2022 CVE Vulnerabilities
27,552 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-20817 | HIGH | 7.4 | 1.1% | Jun 15, 2022 | A vulnerability in Cisco Unified IP Phones could allow an unauthenticated, remote attacker to impersonate another user's... |
| CVE-2022-20798 | CRITICAL | 9.8 | 1.4% | Jun 15, 2022 | A vulnerability in the external authentication functionality of Cisco Secure Email and Web Manager, formerly known as Ci... |
| CVE-2022-20736 | MEDIUM | 5.3 | 1.0% | Jun 15, 2022 | A vulnerability in the web-based management interface of Cisco AppDynamics Controller Software could allow an unauthenti... |
| CVE-2022-20733 | CRITICAL | 9.8 | 1.0% | Jun 15, 2022 | A vulnerability in the login page of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacke... |
| CVE-2022-20664 | HIGH | 7.7 | 1.0% | Jun 15, 2022 | A vulnerability in the web management interface of Cisco Secure Email and Web Manager, formerly Cisco Security Managemen... |
| CVE-2022-32992 | HIGH | 7.2 | 0.9% | Jun 15, 2022 | Online Tours And Travels Management System v1.0 was discovered to contain a SQL injection vulnerability via the tname pa... |
| CVE-2022-32991 | HIGH | 8.8 | 1.0% | Jun 15, 2022 | Web Based Quiz System v1.0 was discovered to contain a SQL injection vulnerability via the eid parameter at welcome.php. |
| CVE-2022-32302 | HIGH | 8.8 | 0.9% | Jun 15, 2022 | Theme Park Ticketing System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at edit_ti... |
| CVE-2022-32301 | CRITICAL | 9.8 | 1.0% | Jun 15, 2022 | YoudianCMS v9.5.0 was discovered to contain a SQL injection vulnerability via the IdList parameter at /App/Lib/Action/Ho... |
| CVE-2022-32300 | HIGH | 8.8 | 1.3% | Jun 15, 2022 | YoudianCMS v9.5.0 was discovered to contain a SQL injection vulnerability via the MailSendID parameter at /App/Lib/Actio... |
| CVE-2022-32299 | HIGH | 8.8 | 1.0% | Jun 15, 2022 | YoudianCMS v9.5.0 was discovered to contain a SQL injection vulnerability via the id parameter at /App/Lib/Action/Admin/... |
| CVE-2022-32158 | CRITICAL | 10 | 1.4% | Jun 15, 2022 | Splunk Enterprise deployment servers in versions before 8.1.10.1, 8.2.6.1, and 9.0 let clients deploy forwarder bundles ... |
| CVE-2022-32157 | HIGH | 7.5 | 1.2% | Jun 15, 2022 | Splunk Enterprise deployment servers in versions before 9.0 allow unauthenticated downloading of forwarder bundles. Reme... |
| CVE-2022-32156 | HIGH | 8.1 | 0.7% | Jun 15, 2022 | In Splunk Enterprise and Universal Forwarder versions before 9.0, the Splunk command-line interface (CLI) did not valida... |
| CVE-2022-32155 | HIGH | 7.5 | 1.8% | Jun 15, 2022 | In universal forwarder versions before 9.0, management services are available remotely by default. When not required, it... |
| CVE-2022-32154 | HIGH | 8.1 | 1.2% | Jun 15, 2022 | Dashboards in Splunk Enterprise versions before 9.0 might let an attacker inject risky search commands into a form token... |
| CVE-2022-32153 | HIGH | 8.1 | 0.8% | Jun 15, 2022 | Splunk Enterprise peers in Splunk Enterprise versions before 9.0 and Splunk Cloud Platform versions before 8.2.2203 did ... |
| CVE-2022-32152 | HIGH | 7.2 | 0.8% | Jun 15, 2022 | Splunk Enterprise peers in Splunk Enterprise versions before 9.0 and Splunk Cloud Platform versions before 8.2.2203 did ... |
| CVE-2022-32151 | CRITICAL | 9.1 | 0.7% | Jun 15, 2022 | The httplib and urllib Python libraries that Splunk shipped with Splunk Enterprise did not validate certificates using t... |
| CVE-2022-32101 | CRITICAL | 9.8 | 1.0% | Jun 15, 2022 | kkcms v1.3.7 was discovered to contain a SQL injection vulnerability via the cid parameter at /template/wapian/vlist.php... |
| CVE-2022-1342 | MEDIUM | 4.6 | 0.4% | Jun 15, 2022 | A lack of password masking in Devolutions Remote Desktop Manager allows physically proximate attackers to observe sensit... |
| CVE-2022-29453 | MEDIUM | 4.3 | 0.4% | Jun 15, 2022 | Cross-Site Request Forgery (CSRF) vulnerability in API KEY for Google Maps plugin <= 1.2.1 at WordPress leading to Googl... |
| CVE-2022-29442 | MEDIUM | 5.4 | 0.5% | Jun 15, 2022 | Authenticated (subscriber or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in Messages For WordPress... |
| CVE-2022-29441 | MEDIUM | 4.3 | 0.4% | Jun 15, 2022 | Cross-Site Request Forgery (CSRF) vulnerability in Private Messages For WordPress plugin <= 2.1.10 at WordPress allows a... |
| CVE-2022-29440 | MEDIUM | 5.4 | 0.5% | Jun 15, 2022 | Multiple Authenticated (contributor or higher user role) Stored Cross-Site Scripting (XSS) vulnerabilities in Promotion ... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now