2022 CVE Vulnerabilities
27,553 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-29351 | CRITICAL | 9.8 | 2.4% | May 16, 2022 | An arbitrary file upload vulnerability in the file upload module of Tiddlywiki5 v5.2.2 allows attackers to execute arbit... |
| CVE-2022-29017 | MEDIUM | 5.5 | 0.6% | May 16, 2022 | Bento4 v1.6.0.0 was discovered to contain a segmentation fault via the component /x86_64/multiarch/strlen-avx2.S. |
| CVE-2022-30012 | HIGH | 7.5 | 1.7% | May 16, 2022 | In the POST request of the appointment.php page of HMS v.0, there are SQL injection vulnerabilities in multiple paramete... |
| CVE-2022-30011 | CRITICAL | 9.8 | 18.5% | May 16, 2022 | In HMS 1.0 when requesting appointment.php through POST, multiple parameters can lead to a SQL injection vulnerability. |
| CVE-2022-30782 | HIGH | 7.5 | 1.0% | May 16, 2022 | Openmoney API through 2020-06-29 uses the JavaScript Math.random function, which does not provide cryptographically secu... |
| CVE-2022-29588 | HIGH | 7.5 | 1.6% | May 16, 2022 | Konica Minolta bizhub MFP devices before 2022-04-14 use cleartext password storage for the /var/log/nginx/html/ADMINPASS... |
| CVE-2022-29587 | MEDIUM | 4 | 0.4% | May 16, 2022 | Konica Minolta bizhub MFP devices before 2022-04-14 have an internal Chromium browser that executes with root (aka super... |
| CVE-2022-29586 | HIGH | 7.4 | 0.4% | May 16, 2022 | Konica Minolta bizhub MFP devices before 2022-04-14 allow a Sandbox Escape. An attacker must attach a keyboard to a USB ... |
| CVE-2022-30781 | HIGH | 7.5 | 87.7% | May 16, 2022 | Gitea before 1.16.7 does not escape git fetch remote. |
| CVE-2022-30779 | — | — | — | May 16, 2022 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2022-30778 | — | — | — | May 16, 2022 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2022-30775 | MEDIUM | 5.5 | 0.8% | May 16, 2022 | xpdf 4.04 allocates excessive memory when presented with crafted input. This can be triggered by (for example) sending a... |
| CVE-2022-30770 | MEDIUM | 6.1 | 0.9% | May 16, 2022 | Terminalfour versions 8.3.7, 8.3.x versions prior to version 8.3.8 and r 8.2.x versions prior to version 8.2.18.5 or 8.2... |
| CVE-2022-30767 | CRITICAL | 9.8 | 2.4% | May 16, 2022 | nfs_lookup_reply in net/nfs.c in Das U-Boot through 2022.04 (and through 2022.07-rc2) has an unbounded memcpy with a fai... |
| CVE-2022-30763 | HIGH | 7.5 | 1.7% | May 16, 2022 | Janet before 1.22.0 mishandles arrays. |
| CVE-2022-30765 | CRITICAL | 9.8 | 1.1% | May 16, 2022 | Calibre-Web before 0.6.18 allows user table SQL Injection. |
| CVE-2022-30049 | HIGH | 7.5 | 1.0% | May 15, 2022 | A Server-Side Request Forgery (SSRF) in Rebuild v2.8.3 allows attackers to obtain the real IP address and scan Intranet ... |
| CVE-2022-28930 | CRITICAL | 9.8 | 1.0% | May 15, 2022 | ERP-Pro v3.7.5 was discovered to contain a SQL injection vulnerability via the component /base/SysEveMenuAuthPointMapper... |
| CVE-2022-28937 | HIGH | 7.5 | 1.1% | May 15, 2022 | FISCO-BCOS release-3.0.0-rc2 was discovered to contain an issue where a malicious node, via an invalid proposal with an ... |
| CVE-2022-28936 | HIGH | 7.5 | 0.9% | May 15, 2022 | FISCO-BCOS release-3.0.0-rc2 was discovered to contain an issue where a malicious node can trigger an integer overflow a... |
| CVE-2022-28929 | CRITICAL | 9.8 | 1.6% | May 15, 2022 | Hospital Management System v1.0 was discovered to contain a SQL injection vulnerability via the delid parameter at viewt... |
| CVE-2022-30708 | HIGH | 8.8 | 3.3% | May 15, 2022 | Webmin through 1.991, when the Authentic theme is used, allows remote code execution when a user has been manually creat... |
| CVE-2022-1379 | CRITICAL | 9.1 | 1.5% | May 14, 2022 | URL Restriction Bypass in GitHub repository plantuml/plantuml prior to V1.2022.5. An attacker can abuse this to bypass U... |
| CVE-2022-24831 | CRITICAL | 9.8 | 1.0% | May 14, 2022 | OpenClinica is an open source software for Electronic Data Capture (EDC) and Clinical Data Management (CDM). Versions pr... |
| CVE-2022-24830 | CRITICAL | 9.8 | 2.9% | May 14, 2022 | OpenClinica is an open source software for Electronic Data Capture (EDC) and Clinical Data Management (CDM). OpenClinica... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now