2022 CVE Vulnerabilities
27,553 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-27134 | HIGH | 7.5 | 2.0% | May 13, 2022 | EOSIO batdappboomx v327c04cf has an Access-control vulnerability in the `transfer` function of the smart contract which ... |
| CVE-2022-23742 | HIGH | 7.8 | 4.1% | May 12, 2022 | Check Point Endpoint Security Client for Windows versions earlier than E86.40 copy files for forensics reports from a di... |
| CVE-2022-23166 | CRITICAL | 9.8 | 1.0% | May 12, 2022 | Sysaid – Sysaid Local File Inclusion (LFI) – An unauthenticated attacker can access to the system by accessing to "/lib/... |
| CVE-2022-23165 | MEDIUM | 6.1 | 0.4% | May 12, 2022 | Sysaid – Sysaid 14.2.0 Reflected Cross-Site Scripting (XSS) - The parameter "helpPageName" used by the page "/help/treec... |
| CVE-2022-23139 | HIGH | 8.8 | 0.7% | May 12, 2022 | ZTE's ZXMP M721 product has a permission and access control vulnerability. Since the folder permission viewed by sftp is... |
| CVE-2022-22971 | MEDIUM | 6.5 | 2.9% | May 12, 2022 | In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, application with a STOMP over WebS... |
| CVE-2022-22970 | MEDIUM | 5.3 | 1.9% | May 12, 2022 | In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, applications that handle file uplo... |
| CVE-2022-22798 | HIGH | 8.8 | 0.6% | May 12, 2022 | Sysaid – Pro Plus Edition, SysAid Help Desk Broken Access Control v20.4.74 b10, v22.1.20 b62, v22.1.30 b49 - An attacker... |
| CVE-2022-22797 | MEDIUM | 6.1 | 0.5% | May 12, 2022 | Sysaid – sysaid Open Redirect - An Attacker can change the redirect link at the parameter "redirectURL" from"GET" reques... |
| CVE-2022-22796 | CRITICAL | 9.8 | 1.3% | May 12, 2022 | Sysaid – Sysaid System Takeover - An attacker can bypass the authentication process by accessing to: /wmiwizard.jsp, The... |
| CVE-2022-29369 | HIGH | 7.5 | 1.1% | May 12, 2022 | Nginx NJS v0.7.2 was discovered to contain a segmentation violation via njs_lvlhsh_bucket_find at njs_lvlhsh.c. |
| CVE-2022-29368 | HIGH | 7.1 | 0.9% | May 12, 2022 | Moddable commit before 135aa9a4a6a9b49b60aa730ebc3bcc6247d75c45 was discovered to contain an out-of-bounds read via the ... |
| CVE-2022-28819 | HIGH | 7.8 | 2.7% | May 12, 2022 | Adobe Character Animator versions 4.4.2 (and earlier) and 22.3 (and earlier) are affected by an out-of-bounds write vuln... |
| CVE-2022-28818 | MEDIUM | 6.1 | 41.2% | May 12, 2022 | ColdFusion versions CF2021U3 (and earlier) and CF2018U13 are affected by a reflected Cross-Site Scripting (XSS) vulnerab... |
| CVE-2022-29363 | CRITICAL | 9.8 | 1.2% | May 12, 2022 | Phpok v6.1 was discovered to contain a deserialization vulnerability via the update_f() function in login_control.php. T... |
| CVE-2022-27172 | HIGH | 8.8 | 1.0% | May 12, 2022 | A hard-coded password vulnerability exists in the console infactory functionality of InHand Networks InRouter302 V3.5.37... |
| CVE-2022-26782 | HIGH | 8.8 | 3.0% | May 12, 2022 | Multiple improper input validation vulnerabilities exists in the libnvram.so nvram_import functionality of InHand Networ... |
| CVE-2022-26781 | HIGH | 8.8 | 2.6% | May 12, 2022 | Multiple improper input validation vulnerabilities exists in the libnvram.so nvram_import functionality of InHand Networ... |
| CVE-2022-26780 | HIGH | 8.8 | 3.0% | May 12, 2022 | Multiple improper input validation vulnerabilities exists in the libnvram.so nvram_import functionality of InHand Networ... |
| CVE-2022-26518 | HIGH | 8.8 | 4.8% | May 12, 2022 | An OS command injection vulnerability exists in the console infactory_net functionality of InHand Networks InRouter302 V... |
| CVE-2022-26510 | MEDIUM | 6.5 | 1.2% | May 12, 2022 | A firmware update vulnerability exists in the iburn firmware checks functionality of InHand Networks InRouter302 V3.5.37... |
| CVE-2022-26420 | HIGH | 8.8 | 5.8% | May 12, 2022 | An OS command injection vulnerability exists in the console infactory_port functionality of InHand Networks InRouter302 ... |
| CVE-2022-26085 | HIGH | 8.8 | 12.7% | May 12, 2022 | An OS command injection vulnerability exists in the httpd wlscan_ASP functionality of InHand Networks InRouter302 V3.5.4... |
| CVE-2022-26075 | HIGH | 8.8 | 5.8% | May 12, 2022 | An OS command injection vulnerability exists in the console infactory_wlan functionality of InHand Networks InRouter302 ... |
| CVE-2022-26042 | HIGH | 8.8 | 8.6% | May 12, 2022 | An OS command injection vulnerability exists in the daretools binary functionality of InHand Networks InRouter302 V3.5.4... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now