2022 CVE Vulnerabilities
27,525 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-1400 | CRITICAL | 9.8 | 0.7% | Aug 17, 2022 | Use of Hard-coded Cryptographic Key vulnerability in the WebReportsApi.dll of Exago Web Reports, as used in the Device42... |
| CVE-2022-1399 | CRITICAL | 9.1 | 0.8% | Aug 17, 2022 | An Argument Injection or Modification vulnerability in the "Change Secret" username field as used in the Discovery compo... |
| CVE-2022-37437 | CRITICAL | 9.8 | 0.4% | Aug 16, 2022 | When using Ingest Actions to configure a destination that resides on Amazon Simple Storage Service (S3) in Splunk Web, T... |
| CVE-2022-34256 | CRITICAL | 9.8 | 1.9% | Aug 16, 2022 | Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by an Improp... |
| CVE-2022-2662 | CRITICAL | 9.8 | 0.8% | Aug 16, 2022 | Sequi PortBloque S has a improper authentication issues which may allow an attacker to bypass the authentication process... |
| CVE-2022-2847 | CRITICAL | 9.8 | 0.7% | Aug 16, 2022 | A vulnerability, which was classified as critical, has been found in SourceCodester Guest Management System. This issue ... |
| CVE-2022-36242 | CRITICAL | 9.8 | 0.8% | Aug 16, 2022 | Clinic's Patient Management System v1.0 is vulnerable to SQL Injection via /pms/update_medicine.php?id=. |
| CVE-2022-38193 | CRITICAL | 9.6 | 0.7% | Aug 16, 2022 | There is a code injection vulnerability in Esri Portal for ArcGIS versions 10.8.1 and below that may allow a remote, una... |
| CVE-2022-36599 | CRITICAL | 9.8 | 0.9% | Aug 16, 2022 | Mingsoft MCMS 5.2.8 was discovered to contain a SQL injection vulnerability in /mdiy/model/delete URI via models Lists. |
| CVE-2022-36273 | CRITICAL | 9.8 | 2.4% | Aug 16, 2022 | Tenda AC9 V15.03.2.21_cn is vulnerable to command injection via goform/SetSysTimeCfg. |
| CVE-2022-36272 | CRITICAL | 9.8 | 0.9% | Aug 16, 2022 | Mingsoft MCMS 5.2.8 was discovered to contain a SQL injection vulnerability in /mdiy/page/verify URI via fieldName param... |
| CVE-2022-30264 | CRITICAL | 9.8 | 0.4% | Aug 16, 2022 | The Emerson ROC and FloBoss RTU product lines through 2022-05-02 perform insecure filesystem operations. They utilize th... |
| CVE-2022-36344 | CRITICAL | 9.8 | 0.7% | Aug 16, 2022 | An unquoted search path vulnerability exists in 'JustSystems JUST Online Update for J-License' bundled with multiple pro... |
| CVE-2022-36308 | CRITICAL | 9.1 | 0.6% | Aug 16, 2022 | Airspan AirVelocity 1500 web management UI displays SNMP credentials in plaintext on software versions older than 15.18.... |
| CVE-2022-36010 | CRITICAL | 9.8 | 1.2% | Aug 15, 2022 | This library allows strings to be parsed as functions and stored as a specialized component, [`JsonFunctionValue`](https... |
| CVE-2022-35978 | CRITICAL | 10 | 2.2% | Aug 15, 2022 | Minetest is a free open-source voxel game engine with easy modding and game creation. In **single player**, a mod can se... |
| CVE-2022-36525 | CRITICAL | 9.8 | 1.4% | Aug 15, 2022 | D-Link Go-RT-AC750 GORTAC750_revA_v101b03 & GO-RT-AC750_revB_FWv200b02 is vulnerable to Buffer Overflow via authenticati... |
| CVE-2022-36523 | CRITICAL | 9.8 | 2.1% | Aug 15, 2022 | D-Link Go-RT-AC750 GORTAC750_revA_v101b03 & GO-RT-AC750_revB_FWv200b02 is vulnerable to command injection via /htdocs/up... |
| CVE-2022-36262 | CRITICAL | 9.8 | 1.5% | Aug 15, 2022 | An issue was discovered in taocms 3.0.2. in the website settings that allows arbitrary php code to be injected by modify... |
| CVE-2022-34294 | CRITICAL | 9.8 | 1.4% | Aug 15, 2022 | totd 1.5.3 uses a fixed UDP source port in upstream queries sent to DNS resolvers. This allows DNS cache poisoning becau... |
| CVE-2022-38221 | CRITICAL | 9.8 | 1.5% | Aug 15, 2022 | A buffer overflow in the FTcpListener thread in The Isle Evrima (the dedicated server on Windows and Linux) 0.9.88.07 be... |
| CVE-2022-2812 | CRITICAL | 9.8 | 0.7% | Aug 15, 2022 | A vulnerability classified as critical was found in SourceCodester Guest Management System. This vulnerability affects u... |
| CVE-2022-2314 | CRITICAL | 9.8 | 12.4% | Aug 15, 2022 | The VR Calendar WordPress plugin through 2.3.2 lets any user execute arbitrary PHP functions on the site. |
| CVE-2022-2180 | CRITICAL | 9.8 | 1.9% | Aug 15, 2022 | The GREYD.SUITE WordPress theme does not properly validate uploaded custom font packages, and does not perform any autho... |
| CVE-2022-35949 | CRITICAL | 9.8 | 1.4% | Aug 12, 2022 | undici is an HTTP/1.1 client, written from scratch for Node.js.`undici` is vulnerable to SSRF (Server-side Request Forge... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now