2022 CVE Vulnerabilities
27,552 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-29776 | CRITICAL | 9.8 | 6.9% | Jun 2, 2022 | Onlyoffice Document Server v6.0.0 and below and Core 6.1.0.26 and below were discovered to contain a stack overflow via ... |
| CVE-2022-29735 | HIGH | 8.8 | 0.9% | Jun 2, 2022 | Delta Controls enteliTOUCH 3.40.3935, 3.40.3706, and 3.33.4005 allows attackers to execute arbitrary commands via a craf... |
| CVE-2022-29734 | MEDIUM | 5.4 | 0.4% | Jun 2, 2022 | A cross-site scripting (XSS) vulnerability in ICT Protege GX/WX v2.08 allows authenticated attackers to execute arbitrar... |
| CVE-2022-29733 | MEDIUM | 5.9 | 0.7% | Jun 2, 2022 | Delta Controls enteliTOUCH 3.40.3935, 3.40.3706, and 3.33.4005 was discovered to transmit and store sensitive informatio... |
| CVE-2022-29732 | MEDIUM | 6.1 | 0.7% | Jun 2, 2022 | Delta Controls enteliTOUCH 3.40.3935, 3.40.3706, and 3.33.4005 was discovered to contain a cross-site scripting (XSS) vu... |
| CVE-2022-29731 | MEDIUM | 4.3 | 0.4% | Jun 2, 2022 | An access control issue in ICT Protege GX/WX 2.08 allows attackers to leak SHA1 password hashes of other users. |
| CVE-2022-29730 | CRITICAL | 9.8 | 1.7% | Jun 2, 2022 | USR IOT 4G LTE Industrial Cellular VPN Router v1.0.36 was discovered to contain hard-coded credentials for its highest p... |
| CVE-2022-29729 | HIGH | 7.5 | 1.4% | Jun 2, 2022 | Verizon 4G LTE Network Extender GA4.38 - V0.4.038.2131 utilizes a weak default admin password generation algorithm which... |
| CVE-2022-29725 | HIGH | 8.8 | 1.3% | Jun 2, 2022 | An arbitrary file upload in the image upload component of wityCMS v0.6.2 allows attackers to execute arbitrary code via ... |
| CVE-2022-29712 | CRITICAL | 9.8 | 1.7% | Jun 2, 2022 | LibreNMS v22.3.0 was discovered to contain multiple command injection vulnerabilities via the service_ip, hostname, and ... |
| CVE-2022-29711 | MEDIUM | 6.1 | 0.7% | Jun 2, 2022 | LibreNMS v22.3.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /Table/GraylogCo... |
| CVE-2022-29695 | HIGH | 7.5 | 1.1% | Jun 2, 2022 | Unicorn Engine v2.0.0-rc7 contains memory leaks caused by an incomplete unicorn engine initialization. |
| CVE-2022-29694 | HIGH | 7.5 | 1.8% | Jun 2, 2022 | Unicorn Engine v2.0.0-rc7 and below was discovered to contain a NULL pointer dereference via qemu_ram_free. |
| CVE-2022-29693 | HIGH | 7.5 | 1.2% | Jun 2, 2022 | Unicorn Engine v2.0.0-rc7 and below was discovered to contain a memory leak via the function uc_close at /my/unicorn/uc.... |
| CVE-2022-29692 | HIGH | 7.8 | 0.8% | Jun 2, 2022 | Unicorn Engine v1.0.3 was discovered to contain a use-after-free vulnerability via the hook function. |
| CVE-2022-29659 | CRITICAL | 9.8 | 1.9% | Jun 2, 2022 | Responsive Online Blog v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at single.php. |
| CVE-2022-29653 | MEDIUM | 6.1 | 0.5% | Jun 2, 2022 | OFCMS v1.1.4 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /admin/comn/service/... |
| CVE-2022-29648 | MEDIUM | 5.4 | 0.5% | Jun 2, 2022 | A cross-site scripting (XSS) vulnerability in Jfinal CMS v5.1.0 allows attackers to execute arbitrary web scripts or HTM... |
| CVE-2022-29647 | HIGH | 8.8 | 0.6% | Jun 2, 2022 | An issue was discovered in MCMS 5.2.7. There is a CSRF vulnerability that can add an administrator account via ms/basic/... |
| CVE-2022-29628 | MEDIUM | 5.4 | 0.5% | Jun 2, 2022 | A cross-site scripting (XSS) vulnerability in /omps/seller of Online Market Place Site v1.0 allows attackers to execute ... |
| CVE-2022-29627 | MEDIUM | 4.3 | 0.5% | Jun 2, 2022 | An insecure direct object reference (IDOR) in Online Market Place Site v1.0 allows attackers to modify products that are... |
| CVE-2022-29624 | HIGH | 8.8 | 1.2% | Jun 2, 2022 | An arbitrary file upload vulnerability in the Add File function of TPCMS v3.2 allows attackers to execute arbitrary code... |
| CVE-2022-29598 | MEDIUM | 6.1 | 0.8% | Jun 2, 2022 | Solutions Atlantic Regulatory Reporting System (RRS) v500 is vulnerable to an reflected Cross-Site Scripting (XSS) vulne... |
| CVE-2022-29540 | MEDIUM | 6.1 | 0.7% | Jun 2, 2022 | resi-calltrace in RESI Gemini-Net 4.2 is affected by Multiple XSS issues. Unauthenticated remote attackers can inject ar... |
| CVE-2022-29488 | HIGH | 7.8 | 0.8% | Jun 2, 2022 | The affected product is vulnerable to an out-of-bounds read via uninitialized pointer, which may allow an attacker to ex... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now