2022 CVE Vulnerabilities
27,552 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-31649 | HIGH | 7.5 | 1.2% | Jun 9, 2022 | ownCloud owncloud/core before 10.10.0 Improperly Removes Sensitive Information Before Storage or Transfer. |
| CVE-2022-30075 | HIGH | 8.8 | 37.2% | Jun 9, 2022 | In TP-Link Router AX50 firmware 210730 and older, import of a malicious backup file via web interface can lead to remote... |
| CVE-2022-25807 | MEDIUM | 5.5 | 0.3% | Jun 9, 2022 | An issue was discovered in the IGEL Universal Management Suite (UMS) 6.07.100. A hardcoded DES key in the LDAPDesPWEncry... |
| CVE-2022-25806 | HIGH | 8.8 | 0.9% | Jun 9, 2022 | An issue was discovered in the IGEL Universal Management Suite (UMS) 6.07.100. A hardcoded DES key in the PrefDBCredenti... |
| CVE-2022-25805 | MEDIUM | 6.5 | 0.5% | Jun 9, 2022 | An issue was discovered in the IGEL Universal Management Suite (UMS) 6.07.100. The transmission of cleartext LDAP bind c... |
| CVE-2022-25804 | MEDIUM | 5.5 | 0.3% | Jun 9, 2022 | An issue was discovered in the IGEL Universal Management Suite (UMS) 6.07.100. Insecure permissions for the serverconfig... |
| CVE-2022-24840 | CRITICAL | 9.8 | 1.9% | Jun 9, 2022 | django-s3file is a lightweight file upload input for Django and Amazon S3 . In versions prior to 5.5.1 it was possible t... |
| CVE-2022-31496 | HIGH | 8.8 | 1.9% | Jun 9, 2022 | LibreHealth EHR Base 2.0.0 allows incorrect interface/super/manage_site_files.php access. |
| CVE-2022-29014 | HIGH | 7.5 | 10.6% | Jun 9, 2022 | A local file inclusion vulnerability in Razer Sila Gaming Router v2.0.441_api-2.0.418 allows attackers to read arbitrary... |
| CVE-2022-29013 | CRITICAL | 9.8 | 77.1% | Jun 9, 2022 | A command injection in the command parameter of Razer Sila Gaming Router v2.0.441_api-2.0.418 allows attackers to execut... |
| CVE-2022-31313 | CRITICAL | 9.8 | 1.7% | Jun 8, 2022 | api-res-py package in PyPI 0.1 is vulnerable to a code execution backdoor in the request package. |
| CVE-2022-30882 | CRITICAL | 9.8 | 2.2% | Jun 8, 2022 | pyanxdns package in PyPI version 0.2 is vulnerable to code execution backdoor. The impact is: execute arbitrary code (re... |
| CVE-2022-30877 | CRITICAL | 9.8 | 2.3% | Jun 8, 2022 | The keep for python, as distributed on PyPI, included a code-execution backdoor inserted by a third party. The current v... |
| CVE-2022-30875 | MEDIUM | 6.1 | 0.7% | Jun 8, 2022 | Dolibarr 12.0.5 is vulnerable to Cross Site Scripting (XSS) via Sql Error Page. |
| CVE-2022-28386 | MEDIUM | 4.6 | 0.5% | Jun 8, 2022 | An issue was discovered in certain Verbatim drives through 2022-03-31. The security feature for lockout (e.g., requiring... |
| CVE-2022-32273 | MEDIUM | 4.3 | 0.7% | Jun 8, 2022 | As a result of an observable discrepancy in returned messages, OPSWAT MetaDefender Core (MDCore) before 5.1.2 could allo... |
| CVE-2022-31325 | HIGH | 7.2 | 5.0% | Jun 8, 2022 | There is a SQL Injection vulnerability in ChurchCRM 4.4.5 via the 'PersonID' field in /churchcrm/WhyCameEditor.php. |
| CVE-2022-30899 | MEDIUM | 4.8 | 0.4% | Jun 8, 2022 | A Cross Site Scripting vulnerabilty exists in PartKeepr 1.4.0 via the 'name' field in /api/part_categories. |
| CVE-2022-28387 | MEDIUM | 4.6 | 0.5% | Jun 8, 2022 | An issue was discovered in certain Verbatim drives through 2022-03-31. Due to an insecure design, they can be unlocked b... |
| CVE-2022-28385 | MEDIUM | 4.6 | 0.3% | Jun 8, 2022 | An issue was discovered in certain Verbatim drives through 2022-03-31. Due to missing integrity checks, an attacker can ... |
| CVE-2022-28384 | MEDIUM | 5.5 | 0.4% | Jun 8, 2022 | An issue was discovered in certain Verbatim drives through 2022-03-31. Due to an insecure design, they allow an offline ... |
| CVE-2022-28383 | MEDIUM | 6.8 | 0.6% | Jun 8, 2022 | An issue was discovered in certain Verbatim drives through 2022-03-31. Due to insufficient firmware validation, an attac... |
| CVE-2022-28382 | HIGH | 7.5 | 1.6% | Jun 8, 2022 | An issue was discovered in certain Verbatim drives through 2022-03-31. Due to the use of an insecure encryption AES mode... |
| CVE-2022-24296 | HIGH | 7.5 | 1.1% | Jun 8, 2022 | Use of a Broken or Risky Cryptographic Algorithm vulnerability in Air Conditioning System G-150AD Ver. 3.21 and prior, A... |
| CVE-2022-30926 | CRITICAL | 9.8 | 1.5% | Jun 8, 2022 | H3C Magic R100 R100V100R005 was discovered to contain a stack overflow vulnerability via the EditMacList parameter at /g... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now