7.5
    High

    CVE-2022-30333

    Last Modified: 3 Nov 2025

    RARLAB UnRAR before 6.12 on Linux and UNIX allows directory traversal to write to files during an extract (aka unpack) operation, as demonstrated by creating a ~/.ssh/authorized_keys file. NOTE: WinRAR and Android RAR are unaffected.

    Published:9 May 2022
    10
    Critical

    CVE-2022-30292

    Last Modified: 21 Nov 2024

    Heap-based buffer overflow in sqbaselib.cpp in SQUIRREL 3.2 due to lack of a certain sq_reservestack call.

    Published:4 May 2022
    7.5
    High

    CVE-2022-30286

    Last Modified: 11 May 2022

    pyscriptjs (aka PyScript Demonstrator) in PyScript through 2022-05-04 allows a remote user to read Python source code.

    Source:Momen Eldawakhly
    Published:9 May 2022
    8.8
    High

    CVE-2022-30216

    Last Modified: 8 Jul 2025

    Windows Server Service Tampering Vulnerability

    Published:12 Jul 2022
    7.8
    High

    CVE-2022-30206

    Last Modified: 25 Feb 2026

    Windows Print Spooler Elevation of Privilege Vulnerability

    Published:12 Jul 2022
    7.4
    High

    CVE-2022-30203

    Last Modified: 8 Jul 2025

    Windows Boot Manager Security Feature Bypass Vulnerability

    Published:12 Jul 2022
    7.8
    High

    CVE-2022-30190

    Last Modified: 5 Aug 2026

    A remote code execution vulnerability exists when MSDT is called using the URL protocol from a calling application such as Word. An attacker who successfully exploits this vulnerability can run arbitrary code with the privileges of the calling application. The attacker can then install programs, view, change, or delete data, or create new accounts in the context allowed by the user’s rights. Please see the MSRC Blog Entry for important information about steps you can take to protect your system from this vulnerability.

    Published:1 Jun 2022
    9.8
    Critical

    CVE-2022-30136

    Last Modified: 2 Jan 2025

    Windows Network File System Remote Code Execution Vulnerability

    Published:15 Jun 2022
    8.8
    High

    CVE-2022-30129

    Last Modified: 2 Jan 2025

    Visual Studio Code Remote Code Execution Vulnerability

    Published:10 May 2022
    7.5
    High

    CVE-2022-30114

    Last Modified: 21 Jan 2025

    A heap-based buffer overflow in a network service in Fastweb FASTGate MediaAccess FGA2130FWB, firmware version 18.3.n.0482_FW_230_FGA2130, and DGA4131FWB, firmware version up to 18.3.n.0462_FW_261_DGA4131, allows a remote attacker to reboot the device through a crafted HTTP request, causing DoS.

    Published:19 May 2023
    5.3
    Medium

    CVE-2022-30076

    Last Modified: 8 Apr 2023

    ENTAB ERP 1.0 allows attackers to discover users' full names via a brute force attack with a series of student usernames such as s10000 through s20000. There is no rate limiting.

    Source:Deb Prasad Banerjee
    Published:16 Apr 2023
    8.8
    High

    CVE-2022-30075

    Last Modified: 14 Jun 2022

    In TP-Link Router AX50 firmware 210730 and older, import of a malicious backup file via web interface can lead to remote code execution due to improper validation.

    Source:Tomas Melicher
    Published:9 Jun 2022
    7.5
    High

    CVE-2022-30040

    Last Modified: 21 Nov 2024

    Tenda AX1803 v1.0.0.1_2890 is vulnerable to Buffer Overflow. The vulnerability lies in rootfs_ In / goform / setsystimecfg of / bin / tdhttpd in ubif file system, attackers can access http://ip/goform/SetSysTimeCfg, and by setting the ntpserve parameter, the stack buffer overflow can be caused to achieve the effect of router denial of service.

    Published:11 May 2022
    8.8
    High

    CVE-2022-30024

    Last Modified: 21 Nov 2024

    A buffer overflow in the httpd daemon on TP-Link TL-WR841N V12 (firmware version 3.16.9) devices allows an authenticated remote attacker to execute arbitrary code via a GET request to the page for the System Tools of the Wi-Fi network. This affects TL-WR841 V12 TL-WR841N(EU)_V12_160624 and TL-WR841 V11 TL-WR841N(EU)_V11_160325 , TL-WR841N_V11_150616 and TL-WR841 V10 TL-WR841N_V10_150310 are also affected.

    Published:14 Jul 2022
    8.8
    High

    CVE-2022-30023

    Last Modified: 21 Nov 2024

    Tenda ONT GPON AC1200 Dual band WiFi HG9 v1.0.1 is vulnerable to Command Injection via the Ping function.

    Published:16 Jun 2022
    Unknown

    CVE-2022-30006

    https://github.com/ComparedArray/printix-CVE-2022-30006

    7.8
    High

    CVE-2022-29968

    Last Modified: 21 Nov 2024

    An issue was discovered in the Linux kernel through 5.17.5. io_rw_init_file in fs/io_uring.c lacks initialization of kiocb->private.

    Published:2 May 2022
    7.5
    High

    CVE-2022-29932

    Last Modified: 21 Nov 2024

    The HTTP Server in PRIMEUR SPAZIO 2.5.1.954 (File Transfer) allows an unauthenticated attacker to obtain sensitive data (related to the content of transferred files) via a crafted HTTP request.

    Published:11 May 2022
    6.5
    Medium

    CVE-2022-29900

    Last Modified: 21 Nov 2024

    Mis-trained branch predictions for return instructions may allow arbitrary speculative code execution under certain microarchitecture-dependent conditions.

    Published:12 Jul 2022
    7.5
    High

    CVE-2022-29885

    Last Modified: 5 Apr 2023

    The documentation of Apache Tomcat 10.1.0-M1 to 10.1.0-M14, 10.0.0-M1 to 10.0.20, 9.0.13 to 9.0.62 and 8.5.38 to 8.5.78 for the EncryptInterceptor incorrectly stated it enabled Tomcat clustering to run over an untrusted network. This was not correct. While the EncryptInterceptor does provide confidentiality and integrity protection, it does not protect against all risks associated with running over any untrusted network, particularly DoS risks.

    Source:Cristian Giustini
    Published:10 May 2022
    7.5
    High

    CVE-2022-29856

    Last Modified: 21 Nov 2024

    A hardcoded cryptographic key in Automation360 22 allows an attacker to decrypt exported RPA packages.

    Published:29 Apr 2022
    9.8
    Critical

    CVE-2022-29806

    Last Modified: 21 Nov 2024

    ZoneMinder before 1.36.13 allows remote code execution via an invalid language. Ability to create a debug log file at an arbitrary pathname contributes to exploitability.

    Published:26 Apr 2022
    4.7
    Medium

    CVE-2022-29800

    Last Modified: 28 May 2025

    A time-of-check-time-of-use (TOCTOU) race condition vulnerability was found in networkd-dispatcher. This flaw exists because there is a certain time between the scripts being discovered and them being run. An attacker can abuse this vulnerability to replace scripts that networkd-dispatcher believes to be owned by root with ones that are not.

    Published:27 Apr 2022
    5.5
    Medium

    CVE-2022-29799

    Last Modified: 27 May 2025

    A vulnerability was found in networkd-dispatcher. This flaw exists because no functions are sanitized by the OperationalState or the AdministrativeState of networkd-dispatcher. This attack leads to a directory traversal to escape from the “/etc/networkd-dispatcher” base directory.

    Published:27 Apr 2022
    8.8
    High

    CVE-2022-29778

    Last Modified: 21 Nov 2024

    D-Link DIR-890L 1.20b01 allows attackers to execute arbitrary code due to the hardcoded option Wake-On-Lan for the parameter 'descriptor' at SetVirtualServerSettings.php

    Published:3 Jun 2022
    5.4
    Medium

    CVE-2022-29727

    Last Modified: 17 May 2022

    Survey Sparrow Enterprise Survey Software 2022 has a Stored cross-site scripting (XSS) vulnerability in the Signup parameter.

    Source:Pankaj Kumar Thakur
    Published:11 May 2022
    9.8
    Critical

    CVE-2022-29622

    Last Modified: 21 Nov 2024

    An arbitrary file upload vulnerability in formidable v3.1.4 allows attackers to execute arbitrary code via a crafted filename. NOTE: some third parties dispute this issue because the product has common use cases in which uploading arbitrary files is the desired behavior. Also, there are configuration options in all versions that can change the default behavior of how files are handled. Strapi does not consider this to be a valid vulnerability.

    Published:16 May 2022
    9.8
    Critical

    CVE-2022-29599

    Last Modified: 21 Nov 2024

    In Apache Maven maven-shared-utils prior to version 3.3.3, the Commandline class can emit double-quoted strings without proper escaping, allowing shell injection attacks.

    Published:29 May 2020
    6.1
    Medium

    CVE-2022-29598

    Last Modified: 21 Nov 2024

    Solutions Atlantic Regulatory Reporting System (RRS) v500 is vulnerable to an reflected Cross-Site Scripting (XSS) vulnerability via RRSWeb/maint/ShowDocument/ShowDocument.aspx .

    Published:27 May 2022
    6.5
    Medium

    CVE-2022-29597

    Last Modified: 21 Nov 2024

    Solutions Atlantic Regulatory Reporting System (RRS) v500 is vulnerable to Local File Inclusion (LFI). Any authenticated user has the ability to reference internal system files within requests made to the RRSWeb/maint/ShowDocument/ShowDocument.aspx page. The server will successfully respond with the file contents of the internal system file requested. This ability could allow for adversaries to extract sensitive data and/or files from the underlying file system, gain knowledge about the internal workings of the system, or access source code of the application.

    Published:2 Jun 2022
    5.9
    Medium

    CVE-2022-29593

    Last Modified: 29 Jul 2022

    relay_cgi.cgi on Dingtian DT-R002 2CH relay devices with firmware 3.1.276A allows an attacker to replay HTTP post requests without the need for authentication or a valid signed/authorized request.

    Source:Victor Hanna
    Published:14 Jul 2022
    7
    High

    CVE-2022-29582

    Last Modified: 21 Nov 2024

    In the Linux kernel before 5.17.3, fs/io_uring.c has a use-after-free due to a race condition in io_uring timeouts. This can be triggered by a local user who has no access to any user namespace; however, the race condition perhaps can only be exploited infrequently.

    Published:8 Apr 2022
    7.8
    High

    CVE-2022-29581

    Last Modified: 21 Apr 2025

    Improper Update of Reference Count vulnerability in net/sched of Linux Kernel allows local attacker to cause privilege escalation to root. This issue affects: Linux Kernel versions prior to 5.18; version 4.14 and later versions.

    Published:15 Apr 2022
    6.1
    Medium

    CVE-2022-29577

    Last Modified: 21 Nov 2024

    OWASP AntiSamy before 1.6.7 allows XSS via HTML tag smuggling on STYLE content with crafted input. The output serializer does not properly encode the supposed Cascading Style Sheets (CSS) content. NOTE: this issue exists because of an incomplete fix for CVE-2022-28367.

    Published:21 Apr 2022
    Unknown

    CVE-2022-29554

    https://github.com/ComparedArray/printix-CVE-2022-29554

    Unknown

    CVE-2022-29553

    https://github.com/ComparedArray/printix-CVE-2022-29553

    Unknown

    CVE-2022-29552

    https://github.com/ComparedArray/printix-CVE-2022-29552

    Unknown

    CVE-2022-29551

    https://github.com/ComparedArray/printix-CVE-2022-29551

    4.6
    Medium

    CVE-2022-29548

    Last Modified: 27 Jun 2022

    A reflected XSS issue exists in the Management Console of several WSO2 products. This affects API Manager 2.2.0, 2.5.0, 2.6.0, 3.0.0, 3.1.0, 3.2.0, and 4.0.0; API Manager Analytics 2.2.0, 2.5.0, and 2.6.0; API Microgateway 2.2.0; Data Analytics Server 3.2.0; Enterprise Integrator 6.2.0, 6.3.0, 6.4.0, 6.5.0, and 6.6.0; IS as Key Manager 5.5.0, 5.6.0, 5.7.0, 5.9.0, and 5.10.0; Identity Server 5.5.0, 5.6.0, 5.7.0, 5.9.0, 5.10.0, and 5.11.0; Identity Server Analytics 5.5.0 and 5.6.0; and WSO2 Micro Integrator 1.0.0.

    Source:cxosmo
    Published:21 Apr 2022
    Low

    CVE-2022-29469

    Last Modified: 28 May 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

    Published:20 Apr 2022
    9.8
    Critical

    CVE-2022-29465

    Last Modified: 15 Apr 2025

    An out-of-bounds write vulnerability exists in the PSD Header processing memory allocation functionality of Accusoft ImageGear 20.0. A specially-crafted malformed file can lead to memory corruption. An attacker can provide a malicious file to trigger this vulnerability.

    Published:5 Aug 2022
    9.8
    Critical

    CVE-2022-29464

    Last Modified: 7 Nov 2025

    Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /fileupload endpoint with a Content-Disposition directory traversal sequence to reach a directory under the web root, such as a ../../../../repository/deployment/server/webapps directory. This affects WSO2 API Manager 2.2.0 up to 4.0.0, WSO2 Identity Server 5.2.0 up to 5.11.0, WSO2 Identity Server Analytics 5.4.0, 5.4.1, 5.5.0 and 5.6.0, WSO2 Identity Server as Key Manager 5.3.0 up to 5.11.0, WSO2 Enterprise Integrator 6.2.0 up to 6.6.0, WSO2 Open Banking AM 1.4.0 up to 2.0.0 and WSO2 Open Banking KM 1.4.0, up to 2.0.0.

    Published:18 Apr 2022
    8.8
    High

    CVE-2022-29457

    Last Modified: 11 May 2022

    Zoho ManageEngine ADSelfService Plus before 6121, ADAuditPlus 7060, Exchange Reporter Plus 5701, and ADManagerPlus 7131 allow NTLM Hash disclosure during certain storage-path configuration steps.

    Source:Metin Yunus Kandemir
    Published:18 Apr 2022
    4.7
    Medium

    CVE-2022-29455

    Last Modified: 20 Feb 2025

    DOM-based Reflected Cross-Site Scripting (XSS) vulnerability in Elementor's Elementor Website Builder plugin <= 3.5.5 versions.

    Published:13 Jun 2022
    9.8
    Critical

    CVE-2022-29383

    Last Modified: 21 Nov 2024

    NETGEAR ProSafe SSL VPN firmware FVS336Gv2 and FVS336Gv3 was discovered to contain a SQL injection vulnerability via USERDBDomains.Domainname at cgi-bin/platform.cgi.

    Published:13 May 2022
    4.8
    Medium

    CVE-2022-29380

    Last Modified: 21 Nov 2024

    Academy-LMS v4.3 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the SEO panel.

    Published:25 May 2022
    9.8
    Critical

    CVE-2022-29361

    Last Modified: 21 Nov 2024

    Improper parsing of HTTP requests in Pallets Werkzeug v2.1.0 and below allows attackers to perform HTTP Request Smuggling using a crafted HTTP request with multiple requests included inside the body. NOTE: the vendor's position is that this behavior can only occur in unsupported configurations involving development mode and an HTTP server from outside the Werkzeug project

    Published:24 May 2022
    6.1
    Medium

    CVE-2022-29359

    Last Modified: 21 Nov 2024

    A stored cross-site scripting (XSS) vulnerability in /scas/?page=clubs/application_form&id=7 of School Club Application System v0.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the firstname parameter.

    Published:24 May 2022
    9.8
    Critical

    CVE-2022-29337

    Last Modified: 21 Nov 2024

    C-DATA FD702XW-X-R430 v2.1.13_X001 was discovered to contain a command injection vulnerability via the va_cmd parameter in formlanipv6. This vulnerability allows attackers to execute arbitrary commands via a crafted HTTP request.

    Published:24 May 2022
    9.8
    Critical

    CVE-2022-29303

    Last Modified: 17 May 2022

    SolarView Compact ver.6.00 was discovered to contain a command injection vulnerability via conf_mail.php.

    Source:Ahmed Alroky
    Published:12 May 2022