2022 CVE Vulnerabilities
27,553 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-27063 | MEDIUM | 6.1 | 1.4% | Apr 8, 2022 | AeroCMS v0.0.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability via view_all_comments.php. Th... |
| CVE-2022-27062 | MEDIUM | 4.8 | 1.1% | Apr 8, 2022 | AeroCMS v0.0.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability via add_post.php. This vulner... |
| CVE-2022-27061 | HIGH | 7.2 | 2.5% | Apr 8, 2022 | AeroCMS v0.0.1 was discovered to contain an arbitrary file upload vulnerability via the Post Image function under the Ad... |
| CVE-2022-26624 | MEDIUM | 6.1 | 0.9% | Apr 8, 2022 | Bootstrap v3.1.11 and v3.3.7 was discovered to contain a cross-site scripting (XSS) vulnerability via the Title paramete... |
| CVE-2022-1219 | HIGH | 7.5 | 1.4% | Apr 8, 2022 | SQL injection in RecyclebinController.php in GitHub repository pimcore/pimcore prior to 10.3.5. This vulnerability is ca... |
| CVE-2022-28805 | CRITICAL | 9.1 | 2.9% | Apr 8, 2022 | singlevar in lparser.c in Lua from (including) 5.4.0 up to (excluding) 5.4.4 lacks a certain luaK_exp2anyregup call, lea... |
| CVE-2022-28796 | HIGH | 7 | 0.3% | Apr 8, 2022 | jbd2_journal_wait_updates in fs/jbd2/transaction.c in the Linux kernel before 5.17.1 has a use-after-free caused by a tr... |
| CVE-2022-24681 | MEDIUM | 6.1 | 3.6% | Apr 7, 2022 | Zoho ManageEngine ADSelfService Plus before 6121 allows XSS via the welcome name attribute to the Reset Password, Unlock... |
| CVE-2022-26676 | CRITICAL | 9.8 | 1.3% | Apr 7, 2022 | aEnrich a+HRD has inadequate privilege restrictions, an unauthenticated remote attacker can use the API function to uplo... |
| CVE-2022-26675 | HIGH | 7.5 | 2.1% | Apr 7, 2022 | aEnrich a+HRD has inadequate filtering for special characters in URLs. An unauthenticated remote attacker can bypass aut... |
| CVE-2022-26671 | HIGH | 7.3 | 0.9% | Apr 7, 2022 | Taiwan Secom Dr.ID Access Control system’s login page has a hard-coded credential in the source code. An unauthenticated... |
| CVE-2022-26670 | HIGH | 8.8 | 1.5% | Apr 7, 2022 | D-Link DIR-878 has inadequate filtering for special characters in the webpage input field. An unauthenticated LAN attack... |
| CVE-2022-26612 | CRITICAL | 9.8 | 4.3% | Apr 7, 2022 | In Apache Hadoop, The unTar function uses unTarUsingJava function on Windows and the built-in tar utility on Unix and ot... |
| CVE-2022-25597 | HIGH | 8.8 | 0.8% | Apr 7, 2022 | ASUS RT-AC86U’s LPD service has insufficient filtering for special characters in the user request, which allows an unaut... |
| CVE-2022-25596 | HIGH | 8.8 | 0.6% | Apr 7, 2022 | ASUS RT-AC56U’s configuration function has a heap-based buffer overflow vulnerability due to insufficient validation for... |
| CVE-2022-25595 | MEDIUM | 6.5 | 0.4% | Apr 7, 2022 | ASUS RT-AC86U has improper user request handling, which allows an unauthenticated LAN attacker to cause a denial of serv... |
| CVE-2022-25594 | MEDIUM | 5.3 | 1.0% | Apr 7, 2022 | Microprogram’s parking lot management system is vulnerable to sensitive information exposure. An unauthorized remote att... |
| CVE-2022-23973 | HIGH | 8.8 | 0.6% | Apr 7, 2022 | ASUS RT-AX56U’s user profile configuration function is vulnerable to stack-based buffer overflow due to insufficient val... |
| CVE-2022-23972 | HIGH | 8.8 | 0.5% | Apr 7, 2022 | ASUS RT-AX56U’s SQL handling function has an SQL injection vulnerability due to insufficient user input validation. An u... |
| CVE-2022-23971 | HIGH | 8.1 | 0.5% | Apr 7, 2022 | ASUS RT-AX56U’s update_PLC/PORT file has a path traversal vulnerability due to insufficient filtering for special charac... |
| CVE-2022-23970 | HIGH | 8.1 | 0.5% | Apr 7, 2022 | ASUS RT-AX56U’s update_json function has a path traversal vulnerability due to insufficient filtering for special charac... |
| CVE-2022-22519 | HIGH | 7.5 | 1.4% | Apr 7, 2022 | A remote, unauthenticated attacker can send a specific crafted HTTP or HTTPS requests causing a buffer over-read resulti... |
| CVE-2022-22518 | MEDIUM | 6.5 | 0.6% | Apr 7, 2022 | A bug in CmpUserMgr component can lead to only partially applied security policies. This can result in enabled, anonymou... |
| CVE-2022-22517 | HIGH | 7.5 | 1.3% | Apr 7, 2022 | An unauthenticated, remote attacker can disrupt existing communication channels between CODESYS products by guessing a v... |
| CVE-2022-22516 | HIGH | 7.8 | 0.3% | Apr 7, 2022 | The SysDrv3S driver in the CODESYS Control runtime system on Microsoft Windows allows any system user to read and write ... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now