2022 CVE Vulnerabilities
27,552 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-32974 | MEDIUM | 6.5 | 0.7% | Jun 21, 2022 | An authenticated attacker could read arbitrary files from the underlying operating system of the scanner using a custom ... |
| CVE-2022-32973 | HIGH | 8.8 | 1.2% | Jun 21, 2022 | An authenticated attacker could create an audit file that bypasses PowerShell cmdlet checks and executes commands with a... |
| CVE-2022-31786 | MEDIUM | 6.1 | 0.7% | Jun 21, 2022 | IdeaLMS 2022 allows reflected Cross Site Scripting (XSS) via the IdeaLMS/Class/Assessment/ PATH_INFO. |
| CVE-2022-30874 | MEDIUM | 5.4 | 0.8% | Jun 21, 2022 | There is a Cross Site Scripting Stored (XSS) vulnerability in NukeViet CMS before 4.5.02. |
| CVE-2022-2068 | HIGH | 7.3 | 95.8% | Jun 21, 2022 | In addition to the c_rehash shell command injection identified in CVE-2022-1292, further circumstances where the c_rehas... |
| CVE-2022-27872 | HIGH | 7.8 | 0.7% | Jun 21, 2022 | A maliciously crafted PDF file may be used to dereference a pointer for read or write operation while parsing PDF files ... |
| CVE-2022-27871 | HIGH | 7.8 | 0.7% | Jun 21, 2022 | Autodesk AutoCAD product suite, Revit, Design Review and Navisworks releases using PDFTron prior to 9.1.17 version may b... |
| CVE-2022-27870 | HIGH | 7.8 | 0.7% | Jun 21, 2022 | A maliciously crafted TGA file in Autodesk AutoCAD 2023 may be used to write beyond the allocated buffer while parsing T... |
| CVE-2022-27869 | HIGH | 7.8 | 0.7% | Jun 21, 2022 | A maliciously crafted TIFF file in Autodesk AutoCAD 2023 can be forced to read and write beyond allocated boundaries whe... |
| CVE-2022-27868 | HIGH | 7.8 | 1.0% | Jun 21, 2022 | A maliciously crafted CAT file in Autodesk AutoCAD 2023 can be used to trigger use-after-free vulnerability. Exploitatio... |
| CVE-2022-27867 | HIGH | 7.8 | 0.7% | Jun 21, 2022 | A maliciously crafted JT file in Autodesk AutoCAD 2022, 2021, 2020, 2019 can be used to trigger use-after-free vulnerabi... |
| CVE-2022-26147 | CRITICAL | 9.8 | 2.5% | Jun 21, 2022 | The Quectel RG502Q-EA modem before 2022-02-23 allow OS Command Injection. |
| CVE-2022-23171 | HIGH | 8.8 | 0.6% | Jun 21, 2022 | AtlasVPN - Privilege Escalation Lack of proper security controls on named pipe messages can allow an attacker with low p... |
| CVE-2022-22979 | HIGH | 7.5 | 1.3% | Jun 21, 2022 | In Spring Cloud Function versions prior to 3.2.6, it is possible for a user who directly interacts with framework provid... |
| CVE-2022-1833 | HIGH | 8.8 | 0.8% | Jun 21, 2022 | A flaw was found in AMQ Broker Operator 7.9.4 installed via UI using OperatorHub where a low-privilege user that has acc... |
| CVE-2022-1665 | HIGH | 8.2 | 0.3% | Jun 21, 2022 | A set of pre-production kernel packages of Red Hat Enterprise Linux for IBM Power architecture can be booted by the grub... |
| CVE-2022-1596 | MEDIUM | 6.5 | 0.6% | Jun 21, 2022 | Incorrect Permission Assignment for Critical Resource vulnerability in ABB REX640 PCL1, REX640 PCL2, REX640 PCL3 allows ... |
| CVE-2022-33056 | HIGH | 7.2 | 0.9% | Jun 21, 2022 | Online Railway Reservation System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /... |
| CVE-2022-33055 | HIGH | 7.2 | 0.9% | Jun 21, 2022 | Online Railway Reservation System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /... |
| CVE-2022-33049 | HIGH | 7.2 | 0.9% | Jun 21, 2022 | Online Railway Reservation System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /... |
| CVE-2022-33048 | HIGH | 7.2 | 0.9% | Jun 21, 2022 | Online Railway Reservation System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /... |
| CVE-2022-31478 | MEDIUM | 4.3 | 0.6% | Jun 21, 2022 | The UserTakeOver plugin before 4.0.1 for ILIAS allows an attacker to list all users via the search function. |
| CVE-2022-29775 | CRITICAL | 9.8 | 59.9% | Jun 21, 2022 | iSpyConnect iSpy v7.2.2.0 allows attackers to bypass authentication via a crafted URL. |
| CVE-2022-29774 | CRITICAL | 9.8 | 5.4% | Jun 21, 2022 | iSpy v7.2.2.0 is vulnerable to remote command execution via path traversal. |
| CVE-2022-25585 | MEDIUM | 5.4 | 0.4% | Jun 21, 2022 | Unioncms v1.0.13 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Default settings. |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now