2022 CVE Vulnerabilities
27,552 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-32311 | CRITICAL | 9.8 | 1.3% | Jul 5, 2022 | Ingredient Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at ... |
| CVE-2022-32310 | CRITICAL | 9.8 | 1.4% | Jul 5, 2022 | An access control issue in Ingredient Stock Management System v1.0 allows attackers to take over user accounts via a cra... |
| CVE-2022-31856 | CRITICAL | 9.8 | 1.3% | Jul 5, 2022 | Newsletter Module v3.x was discovered to contain a SQL injection vulnerability via the zemez_newsletter_email parameter ... |
| CVE-2022-2321 | CRITICAL | 9.8 | 1.3% | Jul 5, 2022 | Improper Restriction of Excessive Authentication Attempts in GitHub repository heroiclabs/nakama prior to 3.13.0. This r... |
| CVE-2022-33075 | MEDIUM | 5.4 | 0.8% | Jul 5, 2022 | A stored cross-site scripting (XSS) vulnerability in the Add Classification function of Zoo Management System v1.0 allow... |
| CVE-2022-31117 | MEDIUM | 5.9 | 1.4% | Jul 5, 2022 | UltraJSON is a fast JSON encoder and decoder written in pure C with bindings for Python 3.7+. In versions prior to 5.4.0... |
| CVE-2022-31116 | HIGH | 7.5 | 1.8% | Jul 5, 2022 | UltraJSON is a fast JSON encoder and decoder written in pure C with bindings for Python 3.7+. Affected versions were fou... |
| CVE-2022-31014 | LOW | 3.5 | 2.4% | Jul 5, 2022 | Nextcloud server is an open source personal cloud server. Affected versions were found to be vulnerable to SMTP command ... |
| CVE-2022-34879 | MEDIUM | 6.1 | 0.4% | Jul 5, 2022 | Reflected Cross Site Scripting (XSS) vulnerabilities in AST Agent Time Sheet interface (/vicidial/AST_agent_time_sheet.p... |
| CVE-2022-34878 | HIGH | 8.8 | 2.7% | Jul 5, 2022 | SQL Injection vulnerability in User Stats interface (/vicidial/user_stats.php) of VICIdial via the file_download paramet... |
| CVE-2022-34877 | HIGH | 8.8 | 2.7% | Jul 5, 2022 | SQL Injection vulnerability in AST Agent Time Sheet interface ((/vicidial/AST_agent_time_sheet.php) of VICIdial via the ... |
| CVE-2022-34876 | HIGH | 8.8 | 2.7% | Jul 5, 2022 | SQL Injection vulnerability in admin interface (/vicidial/admin.php) of VICIdial via modify_email_accounts, access_recor... |
| CVE-2022-31770 | MEDIUM | 4.9 | 0.8% | Jul 5, 2022 | IBM App Connect Enterprise Certified Container 4.2 could allow a user from the administration console to cause a denial ... |
| CVE-2022-31836 | CRITICAL | 9.8 | 1.3% | Jul 5, 2022 | The leafInfo.match() function in Beego v2.0.3 and below uses path.join() to deal with wildcardvalues which can lead to c... |
| CVE-2022-33744 | MEDIUM | 4.7 | 0.3% | Jul 5, 2022 | Arm guests can cause Dom0 DoS via PV devices When mapping pages of guests on Arm, dom0 is using an rbtree to keep track ... |
| CVE-2022-33743 | HIGH | 7.8 | 0.3% | Jul 5, 2022 | network backend may cause Linux netfront to use freed SKBs While adding logic to support XDP (eXpress Data Path), a code... |
| CVE-2022-33742 | HIGH | 7.1 | 0.3% | Jul 5, 2022 | Linux disk/nic frontends data leaks T[his CNA information record relates to multiple CVEs; the text explains which aspec... |
| CVE-2022-33741 | HIGH | 7.1 | 0.3% | Jul 5, 2022 | Linux disk/nic frontends data leaks T[his CNA information record relates to multiple CVEs; the text explains which aspec... |
| CVE-2022-33740 | HIGH | 7.1 | 0.3% | Jul 5, 2022 | Linux disk/nic frontends data leaks T[his CNA information record relates to multiple CVEs; the text explains which aspec... |
| CVE-2022-30290 | HIGH | 7.5 | 0.8% | Jul 5, 2022 | In OpenCTI through 5.2.4, a broken access control vulnerability has been identified in the profile endpoint. An attacker... |
| CVE-2022-2304 | HIGH | 7.8 | 1.2% | Jul 5, 2022 | Stack-based Buffer Overflow in GitHub repository vim/vim prior to 9.0. |
| CVE-2022-26365 | HIGH | 7.1 | 0.3% | Jul 5, 2022 | Linux disk/nic frontends data leaks T[his CNA information record relates to multiple CVEs; the text explains which aspec... |
| CVE-2022-30289 | MEDIUM | 5.4 | 0.4% | Jul 5, 2022 | A stored Cross-site Scripting (XSS) vulnerability was identified in the Data Import functionality of OpenCTI through 5.2... |
| CVE-2022-2097 | MEDIUM | 5.3 | 2.0% | Jul 5, 2022 | AES OCB mode for 32-bit x86 platforms using the AES-NI assembly optimised implementation will not encrypt the entirety o... |
| CVE-2022-2309 | HIGH | 7.5 | 2.0% | Jul 5, 2022 | NULL Pointer Dereference allows attackers to cause a denial of service (or application crash). This only applies when lx... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now