2022 CVE Vulnerabilities
27,525 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-36952 | CRITICAL | 9.8 | 0.4% | Jul 27, 2022 | In Veritas NetBackup OpsCenter, a hard-coded credential exists that could be used to exploit the underlying VxSS subsyst... |
| CVE-2022-36951 | CRITICAL | 9.8 | 1.0% | Jul 27, 2022 | In Veritas NetBackup OpsCenter, an unauthenticated remote attacker may compromise the host by exploiting an incorrectly ... |
| CVE-2022-36950 | CRITICAL | 9.8 | 1.5% | Jul 27, 2022 | In Veritas NetBackup OpsCenter, an unauthenticated remote attacker may be able to perform remote command execution throu... |
| CVE-2022-24405 | CRITICAL | 9.8 | 3.1% | Jul 27, 2022 | OX App Suite through 7.10.6 allows OS Command Injection via a serialized Java class to the Documentconverter API. |
| CVE-2022-23100 | CRITICAL | 9.8 | 3.0% | Jul 27, 2022 | OX App Suite through 7.10.6 allows OS Command Injection via Documentconverter (e.g., through an email attachment). |
| CVE-2022-2310 | CRITICAL | 9.8 | 1.0% | Jul 27, 2022 | An authentication bypass vulnerability in Skyhigh SWG in main releases 10.x prior to 10.2.12, 9.x prior to 9.2.23, 8.x p... |
| CVE-2022-36129 | CRITICAL | 9.1 | 1.3% | Jul 26, 2022 | HashiCorp Vault Enterprise 1.7.0 through 1.9.7, 1.10.4, and 1.11.0 clusters using Integrated Storage expose an unauthent... |
| CVE-2022-30274 | CRITICAL | 9.8 | 0.5% | Jul 26, 2022 | The Motorola ACE1000 RTU through 2022-05-02 uses ECB encryption unsafely. It can communicate with an XRT LAN-to-radio ga... |
| CVE-2022-30271 | CRITICAL | 9.8 | 0.8% | Jul 26, 2022 | The Motorola ACE1000 RTU through 2022-05-02 ships with a hardcoded SSH private key and initialization scripts (such as /... |
| CVE-2022-30270 | CRITICAL | 9.8 | 0.7% | Jul 26, 2022 | The Motorola ACE1000 RTU through 2022-05-02 has default credentials. It exposes an SSH interface on port 22/TCP. This in... |
| CVE-2022-31207 | CRITICAL | 9.8 | 0.7% | Jul 26, 2022 | The Omron SYSMAC Cx product family PLCs (CS series, CJ series, and CP series) through 2022-05-18 lack cryptographic auth... |
| CVE-2022-31206 | CRITICAL | 9.8 | 0.8% | Jul 26, 2022 | The Omron SYSMAC Nx product family PLCs (NJ series, NY series, NX series, and PMAC series) through 2022-005-18 lack cryp... |
| CVE-2022-30273 | CRITICAL | 9.8 | 0.3% | Jul 26, 2022 | The Motorola MDLC protocol through 2022-05-02 mishandles message integrity. It supports three security modes: Plain, Leg... |
| CVE-2022-29958 | CRITICAL | 9.8 | 0.5% | Jul 26, 2022 | JTEKT TOYOPUC PLCs through 2022-04-29 do not ensure data integrity. They utilize the unauthenticated CMPLink/TCP protoco... |
| CVE-2022-29953 | CRITICAL | 9.8 | 0.8% | Jul 26, 2022 | The Bently Nevada 3700 series of condition monitoring equipment through 2022-04-29 has a maintenance interface on port 4... |
| CVE-2022-29952 | CRITICAL | 9.1 | 0.9% | Jul 26, 2022 | Bently Nevada condition monitoring equipment through 2022-04-29 mishandles authentication. It utilizes the TDI command a... |
| CVE-2022-29951 | CRITICAL | 9.1 | 0.9% | Jul 26, 2022 | JTEKT TOYOPUC PLCs through 2022-04-29 mishandle authentication. They utilize the CMPLink/TCP protocol (configurable on p... |
| CVE-2022-36412 | CRITICAL | 9.8 | 5.7% | Jul 26, 2022 | In Zoho ManageEngine SupportCenter Plus before 11023, V3 API requests are vulnerable to authentication bypass. (An API r... |
| CVE-2022-36161 | CRITICAL | 9.8 | 1.0% | Jul 26, 2022 | Orange Station 1.0 was discovered to contain a SQL injection vulnerability via the username parameter. |
| CVE-2022-34989 | CRITICAL | 9.8 | 0.9% | Jul 26, 2022 | Fruits Bazar v1.0 was discovered to contain a SQL injection vulnerability via the recover_email parameter at user_passwo... |
| CVE-2022-34577 | CRITICAL | 9.8 | 1.7% | Jul 25, 2022 | A vulnerability in adm.cgi of WAVLINK WN535 G3 M35G3R.V5030.180927 allows attackers to execute arbitrary code via a craf... |
| CVE-2022-35131 | CRITICAL | 9 | 2.1% | Jul 25, 2022 | Joplin v2.8.8 allows attackers to execute arbitrary commands via a crafted payload injected into the Node titles. |
| CVE-2022-34907 | CRITICAL | 9.8 | 15.8% | Jul 25, 2022 | An authentication bypass vulnerability exists in FileWave before 14.6.3 and 14.7.x before 14.7.2. Exploitation could all... |
| CVE-2022-35869 | CRITICAL | 9.8 | 60.3% | Jul 25, 2022 | This vulnerability allows remote attackers to bypass authentication on affected installations of Inductive Automation Ig... |
| CVE-2022-24083 | CRITICAL | 9.8 | 0.8% | Jul 25, 2022 | Password authentication bypass vulnerability for local accounts can be used to bypass local authentication checks. |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now