2022 CVE Vulnerabilities
27,553 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-1681 | HIGH | 7.2 | 1.8% | May 12, 2022 | Authentication Bypass Using an Alternate Path or Channel in GitHub repository requarks/wiki prior to 2.5.281. User can g... |
| CVE-2022-1044 | MEDIUM | 6.5 | 0.8% | May 12, 2022 | Sensitive Data Exposure Due To Insecure Storage Of Profile Image in GitHub repository polonel/trudesk prior to v1.2.1. |
| CVE-2022-30594 | HIGH | 7.8 | 0.8% | May 12, 2022 | The Linux kernel before 5.17.2 mishandles seccomp permissions. The PTRACE_SEIZE code path allows attackers to bypass int... |
| CVE-2022-30592 | CRITICAL | 9.8 | 3.2% | May 11, 2022 | liblsquic/lsquic_qenc_hdl.c in LiteSpeed QUIC (aka LSQUIC) before 3.1.0 mishandles MAX_TABLE_CAPACITY. |
| CVE-2022-30557 | HIGH | 7.5 | 4.1% | May 11, 2022 | Foxit PDF Reader and PDF Editor before 11.2.2 have a Type Confusion issue that causes a crash because of Unsigned32 mish... |
| CVE-2022-29855 | MEDIUM | 6.8 | 0.7% | May 11, 2022 | Mitel 6800 and 6900 Series SIP phone devices through 2022-04-27 have "undocumented functionality." A vulnerability in Mi... |
| CVE-2022-29596 | CRITICAL | 9.8 | 2.0% | May 11, 2022 | MicroStrategy Enterprise Manager 2022 allows authentication bypass by triggering a login failure and then entering the U... |
| CVE-2022-30451 | HIGH | 8.8 | 1.5% | May 11, 2022 | An authenticated user could execute code via a SQLi vulnerability in waimairenCMS before version 9.1. |
| CVE-2022-30450 | CRITICAL | 9.8 | 20.0% | May 11, 2022 | A Remote Code Execution (RCE) vulnerability exists in waimairen 9.1 via wx.php |
| CVE-2022-30449 | CRITICAL | 9.8 | 1.6% | May 11, 2022 | Hospital Management System in PHP with Source Code (HMS) 1.0 was discovered to contain a SQL injection vulnerability via... |
| CVE-2022-30448 | CRITICAL | 9.8 | 1.9% | May 11, 2022 | Hospital Management System in PHP with Source Code (HMS) 1.0 was discovered to contain a File upload vulnerability in tr... |
| CVE-2022-30063 | CRITICAL | 9.8 | 16.6% | May 11, 2022 | ftcms <=2.1 was discovered to be vulnerable to code execution attacks . |
| CVE-2022-30453 | CRITICAL | 9.8 | 14.5% | May 11, 2022 | ShopWind <= 3.4.2 has a RCE vulnerability in Database.php |
| CVE-2022-30452 | HIGH | 7.2 | 0.9% | May 11, 2022 | ShopWind <= v3.4.2 has a Sql injection vulnerability in Database.php |
| CVE-2022-30062 | MEDIUM | 6.5 | 1.0% | May 11, 2022 | ftcms <=2.1 was discovered to be vulnerable to Arbitrary File Read via tp.php |
| CVE-2022-30061 | MEDIUM | 6.5 | 1.2% | May 11, 2022 | ftcms <=2.1 was discovered to be vulnerable to directory traversal attacks via the parameter tp. |
| CVE-2022-30060 | HIGH | 8.8 | 1.1% | May 11, 2022 | ftcms <=2.1 was discovered to be vulnerable to Arbitrary File Write via admin/controllers/tp.php |
| CVE-2022-30059 | MEDIUM | 6.5 | 1.1% | May 11, 2022 | Shopwind <=v3.4.2 was discovered to contain a Arbitrary File Delete vulnerability via the neirong parameter at \backend\... |
| CVE-2022-30058 | MEDIUM | 5.3 | 1.1% | May 11, 2022 | Shopwind <=v3.4.2 was discovered to contain a Arbitrary File Download vulnerability via the neirong parameter at \backen... |
| CVE-2022-30057 | MEDIUM | 5.4 | 0.5% | May 11, 2022 | Shopwind <=v3.4.2 was discovered to contain a stored cross-site scripting (XSS) vulnerability. |
| CVE-2022-30048 | CRITICAL | 9.8 | 1.4% | May 11, 2022 | Mingsoft MCMS 5.2.7 was discovered to contain a SQL injection vulnerability in /mdiy/dict/list URI via orderBy parameter... |
| CVE-2022-30047 | CRITICAL | 9.8 | 1.4% | May 11, 2022 | Mingsoft MCMS v5.2.7 was discovered to contain a SQL injection vulnerability in /mdiy/dict/listExcludeApp URI via orderB... |
| CVE-2022-30040 | HIGH | 7.5 | 1.8% | May 11, 2022 | Tenda AX1803 v1.0.0.1_2890 is vulnerable to Buffer Overflow. The vulnerability lies in rootfs_ In / goform / setsystimec... |
| CVE-2022-29848 | MEDIUM | 6.5 | 3.5% | May 11, 2022 | In Progress Ipswitch WhatsUp Gold 17.0.0 through 21.1.1, and 22.0.0, it is possible for an authenticated user to invoke ... |
| CVE-2022-29847 | HIGH | 7.5 | 55.9% | May 11, 2022 | In Progress Ipswitch WhatsUp Gold 21.0.0 through 21.1.1, and 22.0.0, it is possible for an unauthenticated attacker to i... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now