2022 CVE Vulnerabilities
27,552 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-31486 | HIGH | 8.8 | 1.2% | Jun 6, 2022 | An authenticated attacker can send a specially crafted route to the “edit_route.cgi” binary and have it execute shell co... |
| CVE-2022-31485 | MEDIUM | 5.3 | 0.8% | Jun 6, 2022 | An unauthenticated attacker can send a specially crafted packets to update the “notes” section of the home page of the w... |
| CVE-2022-31484 | HIGH | 7.5 | 1.0% | Jun 6, 2022 | An unauthenticated attacker can send a specially crafted network packet to delete a user from the web interface. This vu... |
| CVE-2022-31483 | HIGH | 8.8 | 1.6% | Jun 6, 2022 | An authenticated attacker can upload a file with a filename including “..” and “/” to achieve the ability to upload the ... |
| CVE-2022-31482 | HIGH | 7.5 | 1.0% | Jun 6, 2022 | An unauthenticated attacker can send a specially crafted unauthenticated HTTP request to the device that can overflow a ... |
| CVE-2022-31481 | CRITICAL | 10 | 1.5% | Jun 6, 2022 | An unauthenticated attacker can send a specially crafted update file to the device that can overflow a buffer. This vuln... |
| CVE-2022-31480 | HIGH | 7.5 | 0.9% | Jun 6, 2022 | An unauthenticated attacker could arbitrarily upload firmware files to the target device, ultimately causing a Denial-of... |
| CVE-2022-31479 | CRITICAL | 9.8 | 2.3% | Jun 6, 2022 | An unauthenticated attacker can update the hostname with a specially crafted name that will allow for shell commands to ... |
| CVE-2022-1944 | HIGH | 7.1 | 0.5% | Jun 6, 2022 | When the feature is configured, improper authorization in the Interactive Web Terminal in GitLab CE/EE affecting all ver... |
| CVE-2022-1940 | MEDIUM | 5.4 | 6.3% | Jun 6, 2022 | A Stored Cross-Site Scripting vulnerability in Jira integration in GitLab EE affecting all versions from 13.11 prior to ... |
| CVE-2022-1936 | MEDIUM | 6.5 | 0.7% | Jun 6, 2022 | Incorrect authorization in GitLab EE affecting all versions from 12.0 before 14.9.5, all versions starting from 14.10 be... |
| CVE-2022-1935 | MEDIUM | 6.5 | 0.7% | Jun 6, 2022 | Incorrect authorization in GitLab EE affecting all versions from 12.0 before 14.9.5, all versions starting from 14.10 be... |
| CVE-2022-1821 | MEDIUM | 4.3 | 0.8% | Jun 6, 2022 | An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.8 before 14.9.5, all versions start... |
| CVE-2022-1783 | LOW | 2.7 | 0.9% | Jun 6, 2022 | An issue has been discovered in GitLab CE/EE affecting all versions starting from 14.3 before 14.9.5, all versions start... |
| CVE-2022-30863 | MEDIUM | 4.8 | 0.5% | Jun 6, 2022 | FUDForum 3.1.2 is vulnerable to Cross Site Scripting (XSS) via page_title param in Page Manager in the Admin Control Pan... |
| CVE-2022-30861 | MEDIUM | 4.8 | 0.5% | Jun 6, 2022 | FUDforum 3.1.2 is vulnerable to Stored XSS via Forum Name field in Forum Manager Feature. |
| CVE-2022-30860 | HIGH | 7.2 | 23.0% | Jun 6, 2022 | FUDforum 3.1.2 is vulnerable to Remote Code Execution through Upload File feature of File Administration System in Admin... |
| CVE-2022-32296 | LOW | 3.3 | 0.4% | Jun 5, 2022 | The Linux kernel before 5.17.9 allows TCP servers to identify clients by observing what source ports are used. This occu... |
| CVE-2022-32291 | HIGH | 8.8 | 1.5% | Jun 5, 2022 | In Real Player through 20.1.0.312, attackers can execute arbitrary code by placing a UNC share pathname (for a DLL file)... |
| CVE-2022-26134 | CRITICAL | 9.8 | 100.0% | Jun 3, 2022 | In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un... |
| CVE-2022-29784 | MEDIUM | 5.3 | 1.1% | Jun 3, 2022 | PublicCMS V4.0.202204.a and below contains an information leak via the component /views/directive/sys/SysConfigDataDirec... |
| CVE-2022-29778 | HIGH | 8.8 | 2.5% | Jun 3, 2022 | D-Link DIR-890L 1.20b01 allows attackers to execute arbitrary code due to the hardcoded option Wake-On-Lan for the param... |
| CVE-2022-29773 | MEDIUM | 6.5 | 0.7% | Jun 3, 2022 | An access control issue in aleksis/core/util/auth_helpers.py: ClientProtectedResourceMixin of AlekSIS-Core v2.8.1 and be... |
| CVE-2022-29770 | MEDIUM | 5.4 | 0.5% | Jun 3, 2022 | XXL-Job v2.3.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via /xxl-job-admin/jobinfo. |
| CVE-2022-26493 | HIGH | 8.8 | 0.5% | Jun 3, 2022 | Xecurify's miniOrange Premium, Standard, and Enterprise Drupal SAML SP modules possess an authentication and authorizati... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now