2022 CVE Vulnerabilities
27,552 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-34160 | MEDIUM | 5.4 | 0.9% | Jul 8, 2022 | IBM CICS TX Standard and Advanced 11.1 is vulnerable to HTML injection. A remote attacker could inject malicious HTML co... |
| CVE-2022-35406 | MEDIUM | 4.3 | 0.6% | Jul 8, 2022 | A URL disclosure issue was discovered in Burp Suite before 2022.6. If a user views a crafted response in the Repeater or... |
| CVE-2022-28624 | MEDIUM | 4.8 | 0.4% | Jul 8, 2022 | A potential security vulnerability has been identified in certain HPE FlexNetwork and FlexFabric switch products. The vu... |
| CVE-2022-28623 | CRITICAL | 9.8 | 0.8% | Jul 8, 2022 | Security vulnerabilities in HPE IceWall SSO 10.0 certd could be exploited remotely to allow SQL injection or unauthorize... |
| CVE-2022-33011 | HIGH | 8.8 | 1.2% | Jul 8, 2022 | Known v1.3.1+2020120201 was discovered to allow attackers to perform an account takeover via a host header injection att... |
| CVE-2022-32115 | MEDIUM | 6.1 | 1.0% | Jul 8, 2022 | An issue in the isSVG() function of Known v1.2.2+2020061101 allows attackers to execute arbitrary code via a crafted SVG... |
| CVE-2022-31290 | MEDIUM | 5.4 | 0.7% | Jul 8, 2022 | A cross-site scripting (XSS) vulnerability in Known v1.2.2+2020061101 allows authenticated attackers to execute arbitrar... |
| CVE-2022-30852 | MEDIUM | 4.3 | 0.7% | Jul 8, 2022 | Known v1.3.1 was discovered to contain an Insecure Direct Object Reference (IDOR). |
| CVE-2022-1245 | CRITICAL | 9.8 | 1.0% | Jul 8, 2022 | A privilege escalation flaw was found in the token exchange feature of keycloak. Missing authorization allows a client a... |
| CVE-2022-32061 | MEDIUM | 4.8 | 0.5% | Jul 7, 2022 | An arbitrary file upload vulnerability in the Select User function under the People Menu component of Snipe-IT v6.0.2 al... |
| CVE-2022-32060 | MEDIUM | 4.8 | 0.9% | Jul 7, 2022 | An arbitrary file upload vulnerability in the Update Branding Settings component of Snipe-IT v6.0.2 allows attackers to ... |
| CVE-2022-33936 | CRITICAL | 9.8 | 0.9% | Jul 7, 2022 | Cloud Mobility for Dell EMC Storage, 1.3.0.XXX contains a RCE vulnerability. A non-privileged user could potentially exp... |
| CVE-2022-32481 | HIGH | 7.8 | 0.2% | Jul 7, 2022 | Dell PowerProtect Cyber Recovery, versions prior to 19.11, contain a privilege escalation vulnerability on virtual appli... |
| CVE-2022-31029 | MEDIUM | 4.8 | 0.4% | Jul 7, 2022 | AdminLTE is a Pi-hole Dashboard for stats and configuration. In affected versions inserting code like `<script>alert("XS... |
| CVE-2022-2191 | HIGH | 7.5 | 1.7% | Jul 7, 2022 | In Eclipse Jetty versions 10.0.0 thru 10.0.9, and 11.0.0 thru 11.0.9 versions, SslConnection does not release ByteBuffer... |
| CVE-2022-2048 | HIGH | 7.5 | 1.8% | Jul 7, 2022 | In Eclipse Jetty HTTP/2 server implementation, when encountering an invalid HTTP/2 request, the error handling has a bug... |
| CVE-2022-2047 | LOW | 2.7 | 0.9% | Jul 7, 2022 | In Eclipse Jetty versions 9.4.0 thru 9.4.46, and 10.0.0 thru 10.0.9, and 11.0.0 thru 11.0.9 versions, the parsing of the... |
| CVE-2022-33680 | HIGH | 8.3 | 1.4% | Jul 7, 2022 | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability |
| CVE-2022-34592 | CRITICAL | 9.8 | 3.5% | Jul 7, 2022 | Wavlink WL-WN575A3 RPT75A3.V4300.201217 was discovered to contain a command injection vulnerability via the function obt... |
| CVE-2022-33098 | MEDIUM | 6.1 | 52.2% | Jul 7, 2022 | Magnolia CMS v6.2.19 was discovered to contain a cross-site scripting (XSS) vulnerability via the Edit Contact function.... |
| CVE-2022-32449 | CRITICAL | 9.8 | 18.4% | Jul 7, 2022 | TOTOLINK EX300_V2 V4.0.3c.7484 was discovered to contain a command injection vulnerability via the langType parameter in... |
| CVE-2022-32058 | HIGH | 7.5 | 1.1% | Jul 7, 2022 | An infinite loop in the function httpRpmPass of TP-Link TL-WR741N/TL-WR742N V1/V2/V3_130415 allows attackers to cause a ... |
| CVE-2022-32056 | CRITICAL | 9.8 | 1.0% | Jul 7, 2022 | Online Accreditation Management v1.0 was discovered to contain a SQL injection vulnerability via the USERNAME parameter ... |
| CVE-2022-32055 | HIGH | 7.5 | 1.0% | Jul 7, 2022 | Inout Homestay v2.2 was discovered to contain a SQL injection vulnerability via the guests parameter at /index.php?page=... |
| CVE-2022-32054 | CRITICAL | 9.8 | 31.2% | Jul 7, 2022 | Tenda AC10 US_AC10V1.0RTL_V15.03.06.26_multi_TD01 was discovered to contain a remote code execution (RCE) vulnerability ... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now