2022 CVE Vulnerabilities
27,525 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-32409 | CRITICAL | 9.8 | 9.5% | Jul 14, 2022 | A local file inclusion (LFI) vulnerability in the component codemirror.php of Portal do Software Publico Brasileiro i3ge... |
| CVE-2022-30113 | CRITICAL | 9.8 | 0.7% | Jul 14, 2022 | Electronic mall system 1.0_build20200203 is affected vulnerable to SQL Injection. |
| CVE-2022-28375 | CRITICAL | 9.8 | 1.8% | Jul 14, 2022 | Verizon 5G Home LVSKIHP OutDoorUnit (ODU) 3.33.101.0 does not property sanitize user-controlled parameters within the cr... |
| CVE-2022-28373 | CRITICAL | 9.8 | 1.8% | Jul 14, 2022 | Verizon 5G Home LVSKIHP InDoorUnit (IDU) 3.4.66.162 does not properly sanitize user-controlled parameters within the crt... |
| CVE-2022-28369 | CRITICAL | 9.8 | 1.3% | Jul 14, 2022 | Verizon 5G Home LVSKIHP InDoorUnit (IDU) 3.4.66.162 does not validate the user-provided URL within the crtcmode function... |
| CVE-2022-25801 | CRITICAL | 9.1 | 0.7% | Jul 14, 2022 | Best Practical RT for Incident Response (RTIR) before 4.0.3 and 5.x before 5.0.3 allows SSRF via Scripted Action tools. |
| CVE-2022-25800 | CRITICAL | 9.1 | 0.7% | Jul 14, 2022 | Best Practical RT for Incident Response (RTIR) before 4.0.3 and 5.x before 5.0.3 allows SSRF via the whois lookup tool. |
| CVE-2022-35857 | CRITICAL | 9.8 | 1.4% | Jul 13, 2022 | kvf-admin through 2022-02-12 allows remote attackers to execute arbitrary code because deserialization is mishandled. Th... |
| CVE-2022-34756 | CRITICAL | 9.8 | 1.3% | Jul 13, 2022 | A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could result in remote code execution or... |
| CVE-2022-20238 | CRITICAL | 9.8 | 0.5% | Jul 13, 2022 | 'remap_pfn_range' here may map out of size kernel memory (for example, may map the kernel area), and because the 'vma->v... |
| CVE-2022-20229 | CRITICAL | 9.8 | 2.1% | Jul 13, 2022 | In bta_hf_client_handle_cind_list_item of bta_hf_client_at.cc, there is a possible out of bounds write due to a missing ... |
| CVE-2022-20222 | CRITICAL | 9.8 | 0.9% | Jul 13, 2022 | In read_attr_value of gatt_db.cc, there is a possible out of bounds write due to a missing bounds check. This could lead... |
| CVE-2022-20216 | CRITICAL | 9.8 | 0.5% | Jul 13, 2022 | android exported is used to set third-party app access permissions, and the default value of intent-filter is true. com.... |
| CVE-2022-28888 | CRITICAL | 9.8 | 3.6% | Jul 13, 2022 | Spryker Commerce OS 1.4.2 allows Remote Command Execution. |
| CVE-2022-32073 | CRITICAL | 9.8 | 1.5% | Jul 13, 2022 | WolfSSH v1.4.7 was discovered to contain an integer overflow via the function wolfSSH_SFTP_RecvRMDIR. |
| CVE-2022-35628 | CRITICAL | 9.8 | 25.8% | Jul 12, 2022 | A SQL injection issue was discovered in the lux extension before 17.6.1, and 18.x through 24.x before 24.0.2, for TYPO3. |
| CVE-2022-31105 | CRITICAL | 9.6 | 0.6% | Jul 12, 2022 | Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Argo CD starting with version 0.4.0 and prior ... |
| CVE-2022-29601 | CRITICAL | 9.8 | 0.9% | Jul 12, 2022 | The seminars (aka Seminar Manager) extension through 4.1.3 for TYPO3 allows SQL Injection. |
| CVE-2022-29600 | CRITICAL | 9.8 | 0.9% | Jul 12, 2022 | The oelib (aka One is Enough Library) extension through 4.1.5 for TYPO3 allows SQL Injection. |
| CVE-2022-22997 | CRITICAL | 9.8 | 1.4% | Jul 12, 2022 | Addressed a remote code execution vulnerability by resolving a command injection vulnerability and closing an AWS S3 buc... |
| CVE-2022-2298 | CRITICAL | 9.8 | 0.8% | Jul 12, 2022 | A vulnerability has been found in SourceCodester Clinics Patient Management System 2.0 and classified as critical. Affec... |
| CVE-2022-34737 | CRITICAL | 9.1 | 0.5% | Jul 12, 2022 | The application security module has a vulnerability in permission assignment. Successful exploitation of this vulnerabil... |
| CVE-2022-34819 | CRITICAL | 10 | 1.5% | Jul 12, 2022 | A vulnerability has been identified in SIMATIC CP 1242-7 V2 (All versions < V3.3.46), SIMATIC CP 1243-1 (All versions < ... |
| CVE-2022-26649 | CRITICAL | 9.6 | 1.2% | Jul 12, 2022 | A vulnerability has been identified in SCALANCE X200-4P IRT (All versions < V5.5.2), SCALANCE X201-3P IRT (All versions ... |
| CVE-2022-31140 | CRITICAL | 9.1 | 1.2% | Jul 11, 2022 | Valinor is a PHP library that helps to map any input into a strongly-typed value object structure. Prior to version 0.12... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now