2022 CVE Vulnerabilities
27,525 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-2486 | CRITICAL | 9.8 | 26.1% | Jul 20, 2022 | A vulnerability, which was classified as critical, was found in WAVLINK WN535K2 and WN535K3. This affects an unknown par... |
| CVE-2022-32456 | CRITICAL | 9.8 | 1.3% | Jul 20, 2022 | Digiwin BPM’s function has insufficient validation for user input. An unauthenticated remote attacker can inject arbitra... |
| CVE-2022-21543 | CRITICAL | 9.8 | 1.3% | Jul 19, 2022 | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Mgmt... |
| CVE-2022-34023 | CRITICAL | 9.8 | 0.7% | Jul 19, 2022 | Barangay Management System v1.0 was discovered to contain a SQL injection vulnerability via the hidden_id parameter at /... |
| CVE-2022-35912 | CRITICAL | 9.8 | 1.7% | Jul 19, 2022 | In grails-databinding in Grails before 3.3.15, 4.x before 4.1.1, 5.x before 5.1.9, and 5.2.x before 5.2.1 (at least when... |
| CVE-2022-35405 | CRITICAL | 9.8 | 99.9% | Jul 19, 2022 | Zoho ManageEngine Password Manager Pro before 12101 and PAM360 before 5510 are vulnerable to unauthenticated remote code... |
| CVE-2022-24082 | CRITICAL | 9.8 | 9.5% | Jul 19, 2022 | If an on-premise installation of the Pega Platform is configured with the port for the JMX interface exposed to the Inte... |
| CVE-2022-2467 | CRITICAL | 9.8 | 3.4% | Jul 19, 2022 | A vulnerability has been found in SourceCodester Garage Management System 1.0 and classified as critical. This vulnerabi... |
| CVE-2022-34635 | CRITICAL | 9.8 | 0.8% | Jul 18, 2022 | The mstatus.sd field in CVA6 commit d315ddd0f1be27c1b3f27eb0b8daf471a952299a does not update when the mstatus.fs field i... |
| CVE-2022-34632 | CRITICAL | 9.1 | 0.5% | Jul 18, 2022 | Rocket-Chip commit 4f8114374d8824dfdec03f576a8cd68bebce4e56 was discovered to contain insufficient cryptography via the ... |
| CVE-2022-34029 | CRITICAL | 9.1 | 1.0% | Jul 18, 2022 | Nginx NJS v0.7.4 was discovered to contain an out-of-bounds read via njs_scope_value at njs_scope.h. |
| CVE-2022-2437 | CRITICAL | 9.8 | 1.3% | Jul 18, 2022 | The Feed Them Social – for Twitter feed, Youtube and more plugin for WordPress is vulnerable to deserialization of untru... |
| CVE-2022-35741 | CRITICAL | 9.8 | 6.7% | Jul 18, 2022 | Apache CloudStack version 4.5.0 and later has a SAML 2.0 authentication Service Provider plugin which is found to be vul... |
| CVE-2022-30623 | CRITICAL | 9.8 | 0.3% | Jul 18, 2022 | The server checks the user's cookie in a non-standard way, and a value is entered in the cookie value name of the status... |
| CVE-2022-27434 | CRITICAL | 9.8 | 1.1% | Jul 18, 2022 | UNIT4 TETA Mobile Edition (ME) before 29.5.HF17 was discovered to contain a SQL injection vulnerability via the ProfileN... |
| CVE-2022-32985 | CRITICAL | 9.8 | 1.1% | Jul 17, 2022 | libnx_apl.so on Nexans FTTO GigaSwitch before 6.02N and 7.x before 7.02 implements a Backdoor Account for SSH logins on ... |
| CVE-2022-31211 | CRITICAL | 9.8 | 1.5% | Jul 17, 2022 | An issue was discovered in Infiray IRAY-A8Z3 1.0.957. There is a blank root password for TELNET by default. |
| CVE-2022-31210 | CRITICAL | 9.8 | 1.0% | Jul 17, 2022 | An issue was discovered in Infiray IRAY-A8Z3 1.0.957. The binary file /usr/local/sbin/webproject/set_param.cgi contains ... |
| CVE-2022-31209 | CRITICAL | 9.8 | 1.2% | Jul 17, 2022 | An issue was discovered in Infiray IRAY-A8Z3 1.0.957. The firmware contains a potential buffer overflow by calling strcp... |
| CVE-2022-26479 | CRITICAL | 9.8 | 1.7% | Jul 17, 2022 | An issue was discovered in Poly EagleEye Director II before 2.2.2.1. Existence of a certain file (which can be created v... |
| CVE-2022-26352 | CRITICAL | 9.8 | 91.5% | Jul 17, 2022 | An issue was discovered in the ContentResource API in dotCMS 3.0 through 22.02. Attackers can craft a multipart form req... |
| CVE-2022-35890 | CRITICAL | 9.8 | 1.6% | Jul 15, 2022 | An issue was discovered in Inductive Automation Ignition before 7.9.20 and 8.x before 8.1.17. Designer and Vision Client... |
| CVE-2022-31161 | CRITICAL | 9.8 | 20.1% | Jul 15, 2022 | Roxy-WI is a Web interface for managing HAProxy, Nginx and Keepalived servers. Prior to version 6.1.1.0, the system comm... |
| CVE-2022-35409 | CRITICAL | 9.1 | 1.8% | Jul 15, 2022 | An issue was discovered in Mbed TLS before 2.28.1 and 3.x before 3.2.0. In some configurations, an unauthenticated attac... |
| CVE-2022-32417 | CRITICAL | 9.8 | 32.7% | Jul 14, 2022 | PbootCMS v3.1.2 was discovered to contain a remote code execution (RCE) vulnerability via the function parserIfLabel at ... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now