2022 CVE Vulnerabilities
27,553 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-22368 | HIGH | 7.5 | 0.7% | May 3, 2022 | IBM Spectrum Scale 5.1.0 through 5.1.3.0 uses weaker than expected cryptographic algorithms that could allow an attacker... |
| CVE-2022-1331 | MEDIUM | 5.5 | 0.7% | May 3, 2022 | In four instances DMARS (All versions prior to v2.1.10.24) does not properly restrict references of XML external entitie... |
| CVE-2022-29001 | HIGH | 7.2 | 1.0% | May 3, 2022 | In SpringBootMovie <=1.2, the uploaded file suffix parameter is not filtered, resulting in arbitrary file upload vulnera... |
| CVE-2022-28599 | MEDIUM | 5.4 | 0.5% | May 3, 2022 | A stored cross-site scripting (XSS) vulnerability exists in FUEL-CMS 1.5.1 that allows an authenticated user to upload a... |
| CVE-2022-28588 | MEDIUM | 5.4 | 0.5% | May 3, 2022 | In SpringBootMovie <=1.2 when adding movie names, malicious code can be stored because there are no filtering parameters... |
| CVE-2022-28585 | CRITICAL | 9.8 | 0.9% | May 3, 2022 | EmpireCMS 7.5 has a SQL injection vulnerability in AdClass.php |
| CVE-2022-28505 | HIGH | 7.2 | 0.9% | May 3, 2022 | Jfinal_cms 5.1.0 is vulnerable to SQL Injection via com.jflyfox.system.log.LogController.java. |
| CVE-2022-27962 | CRITICAL | 9.8 | 1.0% | May 3, 2022 | Bluecms 1.6 has a SQL injection vulnerability at cooike. |
| CVE-2022-28561 | CRITICAL | 9.8 | 9.3% | May 3, 2022 | There is a stack overflow vulnerability in the /goform/setMacFilterCfg function in the httpd service of Tenda ax12 22.03... |
| CVE-2022-28560 | CRITICAL | 9.8 | 1.5% | May 3, 2022 | There is a stack overflow vulnerability in the goform/fast_setting_wifi_set function in the httpd service of Tenda ac9 1... |
| CVE-2022-23400 | HIGH | 7.1 | 0.8% | May 3, 2022 | A stack-based buffer overflow vulnerability exists in the IGXMPXMLParser::parseDelimiter functionality of Accusoft Image... |
| CVE-2022-22137 | MEDIUM | 6.5 | 1.1% | May 3, 2022 | A memory corruption vulnerability exists in the ioca_mys_rgb_allocate functionality of Accusoft ImageGear 19.10. A speci... |
| CVE-2022-1473 | HIGH | 7.5 | 2.2% | May 3, 2022 | The OPENSSL_LH_flush() function, which empties a hash table, contains a bug that breaks reuse of the memory occuppied by... |
| CVE-2022-1434 | MEDIUM | 5.9 | 1.0% | May 3, 2022 | The OpenSSL 3.0 implementation of the RC4-MD5 ciphersuite incorrectly uses the AAD data as the MAC key. This makes the M... |
| CVE-2022-1343 | MEDIUM | 5.3 | 1.1% | May 3, 2022 | The function `OCSP_basic_verify` verifies the signer certificate on an OCSP response. In the case where the (non-default... |
| CVE-2022-1292 | HIGH | 7.3 | 83.6% | May 3, 2022 | The c_rehash script does not properly sanitise shell metacharacters to prevent command injection. This script is distrib... |
| CVE-2022-0882 | MEDIUM | 5.5 | 0.1% | May 3, 2022 | A bug exists where an attacker can read the kernel log through exposed Zircon kernel addresses without the required capa... |
| CVE-2022-28590 | HIGH | 7.2 | 22.8% | May 3, 2022 | A Remote Code Execution (RCE) vulnerability exists in Pixelimity 1.0 via admin/admin-ajax.php?action=install_theme. |
| CVE-2022-28589 | MEDIUM | 4.8 | 0.5% | May 3, 2022 | A stored cross-site scripting (XSS) vulnerability in Pixelimity 1.0 allows attackers to execute arbitrary web scripts or... |
| CVE-2022-0916 | HIGH | 8.8 | 0.4% | May 3, 2022 | An issue was discovered in Logitech Options. The OAuth 2.0 state parameter was not properly validated. This leaves appli... |
| CVE-2022-23063 | HIGH | 8.8 | 1.2% | May 3, 2022 | In Shopizer versions 2.3.0 to 3.0.1 are vulnerable to Insufficient Session Expiration. When a password has been changed ... |
| CVE-2022-1554 | HIGH | 7.5 | 1.3% | May 3, 2022 | Path Traversal due to `send_file` call in GitHub repository clinical-genomics/scout prior to 4.52. |
| CVE-2022-21949 | HIGH | 8.8 | 1.7% | May 3, 2022 | A Improper Restriction of XML External Entity Reference vulnerability in SUSE Open Build Service allows remote attackers... |
| CVE-2022-1214 | — | — | — | May 3, 2022 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. Reason: This CVE has been rejected as it was incorrectly assigned. Al... |
| CVE-2022-20767 | HIGH | 7.5 | 1.6% | May 3, 2022 | A vulnerability in the Snort rule evaluation function of Cisco Firepower Threat Defense (FTD) Software could allow an un... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now