2022 CVE Vulnerabilities
27,553 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-0636 | MEDIUM | 5.5 | 0.2% | Apr 22, 2022 | A denial of service vulnerability was reported in Lenovo Thin Installer prior to version 1.3.0039 that could trigger a s... |
| CVE-2022-0354 | HIGH | 7.8 | 0.2% | Apr 22, 2022 | A vulnerability was reported in Lenovo System Update that could allow a local user with interactive system access the ab... |
| CVE-2022-0192 | HIGH | 7.8 | 0.2% | Apr 22, 2022 | A DLL search path vulnerability was reported in Lenovo PCManager prior to version 4.0.40.2175 that could allow privilege... |
| CVE-2022-27342 | CRITICAL | 9.8 | 1.0% | Apr 22, 2022 | Link-Admin v0.0.1 was discovered to contain a SQL injection vulnerability via DictRest.ResponseResult(). |
| CVE-2022-27341 | CRITICAL | 9.8 | 1.2% | Apr 22, 2022 | JFinalCMS v2.0 was discovered to contain a SQL injection vulnerability via the Article Management function. |
| CVE-2022-27340 | HIGH | 8.8 | 0.7% | Apr 22, 2022 | MCMS v5.2.7 contains a Cross-Site Request Forgery (CSRF) via /role/saveOrUpdateRole.do. This vulnerability allows attack... |
| CVE-2022-1440 | CRITICAL | 9.8 | 3.8% | Apr 22, 2022 | Command Injection vulnerability in git-interface@2.1.1 in GitHub repository yarkeev/git-interface prior to 2.1.2. If bot... |
| CVE-2022-29589 | MEDIUM | 6.1 | 0.6% | Apr 22, 2022 | Crypt Server before 3.3.0 allows XSS in the index view. This is related to serial, computername, and username. |
| CVE-2022-1439 | MEDIUM | 6.1 | 3.2% | Apr 22, 2022 | Reflected XSS on demo.microweber.org/demo/module/ in GitHub repository microweber/microweber prior to 1.2.15. Execute Ar... |
| CVE-2022-29583 | HIGH | 7.8 | 0.3% | Apr 22, 2022 | service_windows.go in the kardianos service package for Go omits quoting that is sometimes needed for execution of a Win... |
| CVE-2022-29582 | HIGH | 7 | 0.8% | Apr 22, 2022 | In the Linux kernel before 5.17.3, fs/io_uring.c has a use-after-free due to a race condition in io_uring timeouts. This... |
| CVE-2022-1437 | HIGH | 7.1 | 0.7% | Apr 22, 2022 | Heap-based Buffer Overflow in GitHub repository radareorg/radare2 prior to 5.7.0. The bug causes the program reads data ... |
| CVE-2022-28074 | MEDIUM | 4.8 | 0.4% | Apr 22, 2022 | Halo-1.5.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via \admin\index.html#/system/too... |
| CVE-2022-27406 | HIGH | 7.5 | 3.2% | Apr 22, 2022 | FreeType commit 22a0cccb4d9d002f33c1ba7a4b36812c7d4f46b5 was discovered to contain a segmentation violation via the func... |
| CVE-2022-27405 | HIGH | 7.5 | 2.7% | Apr 22, 2022 | FreeType commit 53dfdcd8198d2b3201a23c4bad9190519ba918db was discovered to contain a segmentation violation via the func... |
| CVE-2022-27404 | CRITICAL | 9.8 | 2.6% | Apr 22, 2022 | FreeType commit 1e2eb65048f75c64b68708efed6ce904c31f3b2f was discovered to contain a heap buffer overflow via the functi... |
| CVE-2022-1429 | HIGH | 7.5 | 64.6% | Apr 22, 2022 | SQL injection in GridHelperService.php in GitHub repository pimcore/pimcore prior to 10.3.6. This vulnerability is capab... |
| CVE-2022-26674 | CRITICAL | 9.8 | 2.5% | Apr 22, 2022 | ASUS RT-AX88U has a Format String vulnerability, which allows an unauthenticated remote attacker to write to arbitrary m... |
| CVE-2022-26673 | MEDIUM | 5.4 | 0.6% | Apr 22, 2022 | ASUS RT-AX88U has insufficient filtering for special characters in the HTTP header parameter. A remote attacker with gen... |
| CVE-2022-26672 | CRITICAL | 9.8 | 1.1% | Apr 22, 2022 | ASUS WebStorage has a hardcoded API Token in the APP source code. An unauthenticated remote attacker can use this token ... |
| CVE-2022-29577 | MEDIUM | 6.1 | 1.2% | Apr 21, 2022 | OWASP AntiSamy before 1.6.7 allows XSS via HTML tag smuggling on STYLE content with crafted input. The output serializer... |
| CVE-2022-28367 | MEDIUM | 6.1 | 1.0% | Apr 21, 2022 | OWASP AntiSamy before 1.6.6 allows XSS via HTML tag smuggling on STYLE content with crafted input. The output serializer... |
| CVE-2022-28366 | HIGH | 7.5 | 2.0% | Apr 21, 2022 | Certain Neko-related HTML parsers allow a denial of service via crafted Processing Instruction (PI) input that causes ex... |
| CVE-2022-29280 | — | — | — | Apr 21, 2022 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2022-28366. Reason: This candidate is a reservation d... |
| CVE-2022-26856 | HIGH | 7.8 | 0.2% | Apr 21, 2022 | Dell EMC Repository Manager version 3.4.0 contains a plain-text password storage vulnerability. A local attacker could p... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now