2022 CVE Vulnerabilities
27,553 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-1771 | MEDIUM | 5.5 | 1.2% | May 18, 2022 | Uncontrolled Recursion in GitHub repository vim/vim prior to 8.2.4975. |
| CVE-2022-30600 | CRITICAL | 9.8 | 4.9% | May 18, 2022 | A flaw was found in moodle where logic used to count failed login attempts could result in the account lockout threshold... |
| CVE-2022-30599 | CRITICAL | 9.8 | 1.3% | May 18, 2022 | A flaw was found in moodle where an SQL injection risk was identified in Badges code relating to configuring criteria. |
| CVE-2022-30598 | MEDIUM | 4.3 | 1.0% | May 18, 2022 | A flaw was found in moodle where global search results could include author information on some activities where a user ... |
| CVE-2022-30597 | MEDIUM | 5.3 | 1.2% | May 18, 2022 | A flaw was found in moodle where the description user field was not hidden when being set as a hidden user field. |
| CVE-2022-30111 | MEDIUM | 6.8 | 0.3% | May 18, 2022 | Due to the use of an insecure algorithm for rolling codes in MCK Smartlock 1.0, allows attackers to unlock the mechanism... |
| CVE-2022-28921 | MEDIUM | 6.5 | 0.7% | May 18, 2022 | A Cross-Site Request Forgery (CSRF) vulnerability discovered in BlogEngine.Net v3.3.8.0 allows unauthenticated attackers... |
| CVE-2022-25617 | MEDIUM | 6.1 | 0.8% | May 18, 2022 | Reflected Cross-Site Scripting (XSS) vulnerability in Code Snippets plugin <= 2.14.3 at WordPress via &orderby vulnerabl... |
| CVE-2022-30596 | MEDIUM | 5.4 | 0.8% | May 18, 2022 | A flaw was found in moodle where ID numbers displayed when bulk allocating markers to assignments required additional sa... |
| CVE-2022-29445 | HIGH | 7.2 | 1.0% | May 18, 2022 | Authenticated (administrator or higher role) Local File Inclusion (LFI) vulnerability in Wow-Company's Popup Box plugin ... |
| CVE-2022-28924 | MEDIUM | 6.5 | 0.9% | May 18, 2022 | An information disclosure vulnerability in UniverSIS-Students before v1.5.0 allows attackers to obtain sensitive informa... |
| CVE-2022-25162 | MEDIUM | 5.3 | 2.4% | May 18, 2022 | Improper Input Validation vulnerability in Mitsubishi Electric MELSEC iQ-F series FX5U-xMy/z(x=32,64,80, y=T,R, z=ES,DS,... |
| CVE-2022-25161 | HIGH | 8.6 | 3.7% | May 18, 2022 | Improper Input Validation vulnerability in Mitsubishi Electric MELSEC iQ-F series FX5U-xMy/z(x=32,64,80, y=T,R, z=ES,DS,... |
| CVE-2022-22787 | HIGH | 7.5 | 3.8% | May 18, 2022 | The Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.10.0 fails to properly valid... |
| CVE-2022-22778 | HIGH | 8.8 | 0.4% | May 18, 2022 | The Web Server component of TIBCO Software Inc.'s TIBCO BusinessConnect Trading Community Management contains an easily ... |
| CVE-2022-22777 | MEDIUM | 6.1 | 0.6% | May 18, 2022 | The Web Server component of TIBCO Software Inc.'s TIBCO BusinessConnect Trading Community Management contains easily exp... |
| CVE-2022-22776 | MEDIUM | 5.4 | 0.5% | May 18, 2022 | The Web Server component of TIBCO Software Inc.'s TIBCO BusinessConnect Trading Community Management contains easily exp... |
| CVE-2022-1734 | HIGH | 7 | 0.5% | May 18, 2022 | A flaw in Linux Kernel found in nfcmrvl_nci_unregister_dev() in drivers/nfc/nfcmrvl/main.c can lead to use after free bo... |
| CVE-2022-0883 | HIGH | 7.8 | 0.2% | May 18, 2022 | SLM has an issue with Windows Unquoted/Trusted Service Paths Security Issue. All installations version 9.x.x prior to 9.... |
| CVE-2022-30105 | CRITICAL | 9.8 | 2.8% | May 18, 2022 | In Belkin N300 Firmware 1.00.08, the script located at /setting_hidden.asp, which is accessible before and after configu... |
| CVE-2022-28917 | HIGH | 7.5 | 8.8% | May 18, 2022 | Tenda AX12 v22.03.01.21_cn was discovered to contain a stack overflow via the lanIp parameter in /goform/AdvSetLanIp. |
| CVE-2022-22786 | HIGH | 8.8 | 1.5% | May 18, 2022 | The Zoom Client for Meetings for Windows before version 5.10.0 and Zoom Rooms for Conference Room for Windows before ver... |
| CVE-2022-22785 | CRITICAL | 9.1 | 3.5% | May 18, 2022 | The Zoom Client for Meetings (for Android, iOS, Linux, MacOS, and Windows) before version 5.10.0 failed to properly cons... |
| CVE-2022-22784 | HIGH | 8.1 | 4.0% | May 18, 2022 | The Zoom Client for Meetings (for Android, iOS, Linux, MacOS, and Windows) before version 5.10.0 failed to properly pars... |
| CVE-2022-1767 | HIGH | 7.5 | 1.7% | May 18, 2022 | Server-Side Request Forgery (SSRF) in GitHub repository jgraph/drawio prior to 18.0.7. |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now