2022 CVE Vulnerabilities
27,552 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-26026 | HIGH | 7.5 | 1.1% | May 25, 2022 | A denial of service vulnerability exists in the OAS Engine SecureConfigValues functionality of Open Automation Software ... |
| CVE-2022-29402 | MEDIUM | 6.8 | 0.4% | May 25, 2022 | TP-Link TL-WR840N EU v6.20 was discovered to contain insecure protections for its UART console. This vulnerability allow... |
| CVE-2022-29248 | HIGH | 8.1 | 1.2% | May 25, 2022 | Guzzle is a PHP HTTP client. Guzzle prior to versions 6.5.6 and 7.4.3 contains a vulnerability with the cookie middlewar... |
| CVE-2022-30428 | HIGH | 7.5 | 1.1% | May 25, 2022 | In ginadmin through 05-10-2022, the incoming path value is not filtered, resulting in arbitrary file reading. |
| CVE-2022-30427 | HIGH | 7.5 | 1.4% | May 25, 2022 | In ginadmin through 05-10-2022 the incoming path value is not filtered, resulting in directory traversal. |
| CVE-2022-29408 | MEDIUM | 6.1 | 0.7% | May 25, 2022 | Persistent Cross-Site Scripting (XSS) vulnerability in Vsourz Digital's Advanced Contact form 7 DB plugin <= 1.8.7 at Wo... |
| CVE-2022-28875 | MEDIUM | 6.5 | 0.5% | May 25, 2022 | A Denial-of-Service (DoS) vulnerability was discovered in F-Secure Atlant and in certain WithSecure products whereby the... |
| CVE-2022-27305 | HIGH | 8.8 | 1.0% | May 25, 2022 | Gibbon v23 does not generate a new session ID cookie after a user authenticates, making the application vulnerable to se... |
| CVE-2022-23775 | CRITICAL | 9.8 | 1.0% | May 25, 2022 | TrueStack Direct Connect 1.4.7 has Incorrect Access Control. |
| CVE-2022-1348 | MEDIUM | 6.5 | 1.5% | May 25, 2022 | A vulnerability was found in logrotate in how the state file is created. The state file is used to prevent parallel exec... |
| CVE-2022-1678 | HIGH | 7.5 | 2.9% | May 25, 2022 | An issue was discovered in the Linux Kernel from 4.18 to 4.19, an improper update of sock reference in TCP pacing can le... |
| CVE-2022-29380 | MEDIUM | 4.8 | 0.6% | May 25, 2022 | Academy-LMS v4.3 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the SEO panel. |
| CVE-2022-22127 | HIGH | 7.2 | 1.0% | May 25, 2022 | Tableau is aware of a broken access control vulnerability present in Tableau Server affecting Tableau Server customers u... |
| CVE-2022-29651 | HIGH | 7.2 | 1.4% | May 25, 2022 | An arbitrary file upload vulnerability in the Select Image function of Online Food Ordering System v1.0 allows attackers... |
| CVE-2022-29650 | CRITICAL | 9.8 | 1.2% | May 25, 2022 | Online Food Ordering System v1.0 was discovered to contain a SQL injection vulnerability via the Search parameter at /on... |
| CVE-2022-29379 | CRITICAL | 9.8 | 1.7% | May 25, 2022 | Nginx NJS v0.7.3 was discovered to contain a stack overflow in the function njs_default_module_loader at /src/njs/src/nj... |
| CVE-2022-1851 | HIGH | 7.8 | 1.6% | May 25, 2022 | Out-of-bounds Read in GitHub repository vim/vim prior to 8.2. |
| CVE-2022-30595 | CRITICAL | 9.8 | 1.9% | May 25, 2022 | libImaging/TgaRleDecode.c in Pillow 9.1.0 has a heap buffer overflow in the processing of invalid TGA image files. |
| CVE-2022-30323 | HIGH | 8.6 | 1.3% | May 25, 2022 | go-getter up to 1.5.11 and 2.0.2 panicked when processing password-protected ZIP files. Fixed in 1.6.1 and 2.1.0. |
| CVE-2022-30322 | HIGH | 8.6 | 1.3% | May 25, 2022 | go-getter up to 1.5.11 and 2.0.2 allowed asymmetric resource exhaustion when go-getter processed malicious HTTP response... |
| CVE-2022-30321 | HIGH | 8.6 | 3.1% | May 25, 2022 | go-getter up to 1.5.11 and 2.0.2 allowed arbitrary host access via go-getter path traversal, symlink processing, and com... |
| CVE-2022-28862 | CRITICAL | 9.8 | 1.0% | May 25, 2022 | In Archibus Web Central before 26.2, multiple SQL Injection vulnerabilities occur in dwr/call/plaincall/workflow.runWork... |
| CVE-2022-26945 | CRITICAL | 9.8 | 1.5% | May 25, 2022 | go-getter up to 1.5.11 and 2.0.2 allowed protocol switching, endless redirect, and configuration bypass via abuse of cus... |
| CVE-2022-21951 | MEDIUM | 6.8 | 0.4% | May 25, 2022 | A Cleartext Transmission of Sensitive Information vulnerability in SUSE Rancher, Rancher allows attackers on the network... |
| CVE-2022-1883 | HIGH | 8.8 | 6.4% | May 25, 2022 | SQL Injection in GitHub repository camptocamp/terraboard prior to 2.2.0. |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now