2022 CVE Vulnerabilities
27,552 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-25872 | MEDIUM | 5.3 | 1.0% | Jun 17, 2022 | All versions of package fast-string-search are vulnerable to Out-of-bounds Read due to incorrect memory freeing and leng... |
| CVE-2022-25871 | HIGH | 7.5 | 1.1% | Jun 17, 2022 | All versions of package querymen are vulnerable to Prototype Pollution if the parameters of exported function handler(ty... |
| CVE-2022-25856 | HIGH | 7.5 | 1.8% | Jun 17, 2022 | The package github.com/argoproj/argo-events/sensors/artifacts before 1.7.1 are vulnerable to Directory Traversal in the ... |
| CVE-2022-25852 | HIGH | 7.5 | 1.2% | Jun 17, 2022 | All versions of package pg-native; all versions of package libpq are vulnerable to Denial of Service (DoS) when the addo... |
| CVE-2022-25345 | HIGH | 7.5 | 1.2% | Jun 17, 2022 | All versions of package @discordjs/opus are vulnerable to Denial of Service (DoS) when trying to encode using an encoder... |
| CVE-2022-22138 | HIGH | 7.5 | 1.2% | Jun 17, 2022 | All versions of package fast-string-search are vulnerable to Denial of Service (DoS) when computations are incorrect for... |
| CVE-2022-21213 | HIGH | 7.5 | 2.0% | Jun 17, 2022 | This affects all versions of package mout. The deepFillIn function can be used to 'fill missing properties recursively',... |
| CVE-2022-31941 | CRITICAL | 9.8 | 1.0% | Jun 17, 2022 | Rescue Dispatch Management System v1.0 is vulnerable to SQL Injection via \rdms\admin?page=user\manage_user&id=. |
| CVE-2022-31083 | HIGH | 7.5 | 0.8% | Jun 17, 2022 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version... |
| CVE-2022-29496 | CRITICAL | 9.8 | 1.9% | Jun 17, 2022 | A stack-based buffer overflow vulnerability exists in the BlynkConsole.h runCommand functionality of Blynk -Library v1.0... |
| CVE-2022-21806 | CRITICAL | 9.8 | 2.2% | Jun 17, 2022 | A use-after-free vulnerability exists in the mips_collector appsrv_server functionality of Anker Eufy Homebase 2 2.1.8.5... |
| CVE-2022-21184 | MEDIUM | 5.9 | 0.4% | Jun 17, 2022 | An information disclosure vulnerability exists in the License registration functionality of Bachmann Visutec GmbH Atvise... |
| CVE-2022-30422 | CRITICAL | 9.8 | 3.8% | Jun 17, 2022 | Proietti Tech srl Planet Time Enterprise 4.2.0.1,4.2.0.0,4.1.0.0,4.0.0.0,3.3.1.0,3.3.0.0 is vulnerable to Remote code ex... |
| CVE-2022-32444 | MEDIUM | 6.1 | 2.2% | Jun 17, 2022 | An issue was discovered in u5cms verion 8.3.5 There is a URL redirection vulnerability that can cause a user's browser t... |
| CVE-2022-32442 | MEDIUM | 6.1 | 0.7% | Jun 17, 2022 | u5cms version 8.3.5 is vulnerable to Cross Site Scripting (XSS). When a user accesses the default home page if the param... |
| CVE-2022-30607 | MEDIUM | 6.5 | 0.7% | Jun 17, 2022 | IBM Robotic Process Automation 20.10.0, 20.12.5, 21.0.0, 21.0.1, and 21.0.2 contains a vulnerability that could allow a ... |
| CVE-2022-22485 | CRITICAL | 9.8 | 1.1% | Jun 17, 2022 | In some cases, an unsuccessful attempt to log into IBM Spectrum Protect Operations Center 8.1.0.000 through 8.1.14.000 d... |
| CVE-2022-31357 | CRITICAL | 9.8 | 1.0% | Jun 17, 2022 | Online Ordering System v2.3.2 was discovered to contain a SQL injection vulnerability via /ordering/admin/inventory/inde... |
| CVE-2022-31356 | CRITICAL | 9.8 | 1.0% | Jun 17, 2022 | Online Ordering System v2.3.2 was discovered to contain a SQL injection vulnerability via /ordering/admin/store/index.ph... |
| CVE-2022-31355 | CRITICAL | 9.8 | 1.0% | Jun 17, 2022 | Online Ordering System v2.3.2 was discovered to contain a SQL injection vulnerability via /ordering/index.php?q=category... |
| CVE-2022-31246 | MEDIUM | 5.5 | 0.7% | Jun 17, 2022 | paymentrequest.py in Electrum before 4.2.2 allows a file:// URL in the r parameter of a payment request (e.g., within QR... |
| CVE-2022-33915 | HIGH | 7 | 0.2% | Jun 17, 2022 | Versions of the Amazon AWS Apache Log4j hotpatch package before log4j-cve-2021-44228-hotpatch-1.3.5 are affected by a ra... |
| CVE-2022-33912 | HIGH | 7.8 | 0.2% | Jun 17, 2022 | A permission issue affects users that deployed the shipped version of the Checkmk Debian package. Packages created by th... |
| CVE-2022-32276 | HIGH | 7.5 | 3.5% | Jun 17, 2022 | Grafana 8.4.3 allows unauthenticated access via (for example) a /dashboard/snapshot/*?orgId=0 URI. NOTE: the vendor cons... |
| CVE-2022-31784 | CRITICAL | 9.8 | 1.5% | Jun 17, 2022 | A vulnerability in the management interface of MiVoice Business through 9.3 PR1 and MiVoice Business Express through 8.0... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now