2022 CVE Vulnerabilities
27,552 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-1815 | HIGH | 7.5 | 5.7% | May 25, 2022 | Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository jgraph/drawio prior to 18.1.2. |
| CVE-2022-29405 | MEDIUM | 6.5 | 1.6% | May 25, 2022 | In Apache Archiva, any registered user can reset password for any users. This is fixed in Archiva 2.2.8 |
| CVE-2022-29710 | MEDIUM | 6.1 | 0.7% | May 25, 2022 | A cross-site scripting (XSS) vulnerability in uploadConfirm.php of LimeSurvey v5.3.9 and below allows attackers to execu... |
| CVE-2022-29362 | MEDIUM | 5.4 | 0.5% | May 25, 2022 | A cross-site scripting (XSS) vulnerability in /navigation/create?ParentID=%23 of ZKEACMS v3.5.2 allows attackers to exec... |
| CVE-2022-29361 | CRITICAL | 9.8 | 7.7% | May 25, 2022 | Improper parsing of HTTP requests in Pallets Werkzeug v2.1.0 and below allows attackers to perform HTTP Request Smugglin... |
| CVE-2022-29359 | MEDIUM | 6.1 | 1.1% | May 25, 2022 | A stored cross-site scripting (XSS) vulnerability in /scas/?page=clubs/application_form&id=7 of School Club Application ... |
| CVE-2022-29358 | MEDIUM | 5.5 | 0.6% | May 25, 2022 | epub2txt2 v2.04 was discovered to contain an integer overflow via the function bug in _parse_special_tag at sxmlc.c. Thi... |
| CVE-2022-29349 | MEDIUM | 6.1 | 1.7% | May 25, 2022 | kkFileView v4.0.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the url parameter at /control... |
| CVE-2022-29337 | CRITICAL | 9.8 | 35.3% | May 24, 2022 | C-DATA FD702XW-X-R430 v2.1.13_X001 was discovered to contain a command injection vulnerability via the va_cmd parameter ... |
| CVE-2022-29334 | CRITICAL | 9.8 | 1.2% | May 24, 2022 | An issue in H v1.0 allows attackers to bypass authentication via a session replay attack. |
| CVE-2022-22497 | HIGH | 7.5 | 1.1% | May 24, 2022 | IBM Aspera Faspex 4.4.1 and 5.0.0 could allow unauthorized access due to an incorrectly computed security token. IBM X-F... |
| CVE-2022-29333 | HIGH | 7.8 | 0.9% | May 24, 2022 | A vulnerability in CyberLink Power Director v14 allows attackers to escalate privileges via a crafted .exe file. |
| CVE-2022-23050 | HIGH | 7.2 | 4.6% | May 24, 2022 | ManageEngine AppManager15 (Build No:15510) allows an authenticated admin user to upload a DLL file to perform a DLL hija... |
| CVE-2022-22977 | HIGH | 7.1 | 0.8% | May 24, 2022 | VMware Tools for Windows(12.0.0, 11.x.y and 10.x.y) contains an XML External Entity (XXE) vulnerability. A malicious act... |
| CVE-2022-1669 | HIGH | 8.1 | 0.7% | May 24, 2022 | A buffer overflow vulnerability has been detected in the firewall function of the device management web portal. The devi... |
| CVE-2022-22495 | HIGH | 8.8 | 2.1% | May 24, 2022 | IBM i 7.3, 7.4, and 7.5 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, w... |
| CVE-2022-22309 | MEDIUM | 6.8 | 0.2% | May 24, 2022 | The POWER systems FSP is vulnerable to unauthenticated logins through the serial port/TTY interface. This vulnerability ... |
| CVE-2022-29249 | HIGH | 7.5 | 0.7% | May 24, 2022 | JavaEZ is a library that adds new functions to make Java easier. A weakness in JavaEZ 1.6 allows force decryption of loc... |
| CVE-2022-1849 | MEDIUM | 5.4 | 0.7% | May 24, 2022 | Session Fixation in GitHub repository filegator/filegator prior to 7.8.0. |
| CVE-2022-31261 | HIGH | 7.5 | 1.1% | May 24, 2022 | An XXE issue was discovered in Morpheus through 5.2.16 and 5.4.x through 5.4.4. A successful attack requires a SAML iden... |
| CVE-2022-30843 | HIGH | 8.8 | 0.9% | May 24, 2022 | Room-rent-portal-site v1.0 is vulnerable to SQL Injection via /rrps/classes/Master.php?f=delete_category, id. |
| CVE-2022-30842 | MEDIUM | 5.4 | 0.5% | May 24, 2022 | Covid-19 Travel Pass Management System v1.0 is vulnerable to Cross Site Scripting (XSS) via /ctpms/classes/Users.php?f=s... |
| CVE-2022-30839 | MEDIUM | 6.1 | 0.6% | May 24, 2022 | Room-rent-portal-site v1.0 is vulnerable to Cross Site Scripting (XSS) via /rrps/classes/Master.php?f=save_category, veh... |
| CVE-2022-30838 | CRITICAL | 9.8 | 1.0% | May 24, 2022 | Covid-19 Travel Pass Management System v1.0 is vulnerable to SQL Injection via /ctpms/classes/Master.php?f=update_applic... |
| CVE-2022-30457 | — | — | — | May 24, 2022 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now