2022 CVE Vulnerabilities

27,553 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-29351CRITICAL9.8An arbitrary file upload vulnerability in the file upload module of Tiddlywiki5 v5.2.2 allows attackers to execute arbit...
CVE-2022-29017MEDIUM5.5Bento4 v1.6.0.0 was discovered to contain a segmentation fault via the component /x86_64/multiarch/strlen-avx2.S.
CVE-2022-30012HIGH7.5In the POST request of the appointment.php page of HMS v.0, there are SQL injection vulnerabilities in multiple paramete...
CVE-2022-30011CRITICAL9.8In HMS 1.0 when requesting appointment.php through POST, multiple parameters can lead to a SQL injection vulnerability.
CVE-2022-30782HIGH7.5Openmoney API through 2020-06-29 uses the JavaScript Math.random function, which does not provide cryptographically secu...
CVE-2022-29588HIGH7.5Konica Minolta bizhub MFP devices before 2022-04-14 use cleartext password storage for the /var/log/nginx/html/ADMINPASS...
CVE-2022-29587MEDIUM4Konica Minolta bizhub MFP devices before 2022-04-14 have an internal Chromium browser that executes with root (aka super...
CVE-2022-29586HIGH7.4Konica Minolta bizhub MFP devices before 2022-04-14 allow a Sandbox Escape. An attacker must attach a keyboard to a USB ...
CVE-2022-30781HIGH7.5Gitea before 1.16.7 does not escape git fetch remote.
CVE-2022-30779Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2022-30778Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2022-30775MEDIUM5.5xpdf 4.04 allocates excessive memory when presented with crafted input. This can be triggered by (for example) sending a...
CVE-2022-30770MEDIUM6.1Terminalfour versions 8.3.7, 8.3.x versions prior to version 8.3.8 and r 8.2.x versions prior to version 8.2.18.5 or 8.2...
CVE-2022-30767CRITICAL9.8nfs_lookup_reply in net/nfs.c in Das U-Boot through 2022.04 (and through 2022.07-rc2) has an unbounded memcpy with a fai...
CVE-2022-30763HIGH7.5Janet before 1.22.0 mishandles arrays.
CVE-2022-30765CRITICAL9.8Calibre-Web before 0.6.18 allows user table SQL Injection.
CVE-2022-30049HIGH7.5A Server-Side Request Forgery (SSRF) in Rebuild v2.8.3 allows attackers to obtain the real IP address and scan Intranet ...
CVE-2022-28930CRITICAL9.8ERP-Pro v3.7.5 was discovered to contain a SQL injection vulnerability via the component /base/SysEveMenuAuthPointMapper...
CVE-2022-28937HIGH7.5FISCO-BCOS release-3.0.0-rc2 was discovered to contain an issue where a malicious node, via an invalid proposal with an ...
CVE-2022-28936HIGH7.5FISCO-BCOS release-3.0.0-rc2 was discovered to contain an issue where a malicious node can trigger an integer overflow a...
CVE-2022-28929CRITICAL9.8Hospital Management System v1.0 was discovered to contain a SQL injection vulnerability via the delid parameter at viewt...
CVE-2022-30708HIGH8.8Webmin through 1.991, when the Authentic theme is used, allows remote code execution when a user has been manually creat...
CVE-2022-1379CRITICAL9.1URL Restriction Bypass in GitHub repository plantuml/plantuml prior to V1.2022.5. An attacker can abuse this to bypass U...
CVE-2022-24831CRITICAL9.8OpenClinica is an open source software for Electronic Data Capture (EDC) and Clinical Data Management (CDM). Versions pr...
CVE-2022-24830CRITICAL9.8OpenClinica is an open source software for Electronic Data Capture (EDC) and Clinical Data Management (CDM). OpenClinica...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now