Known Exploited Vulnerabilities (KEV)

ID Title Severity CVSS EPSS Source Updated
cve-2022-36804 Atlassian Bitbucket Server and Data Center Command Injection Vulnerability HIGH N/A 99.17% cvelistv5 2022-09-30
cve-2022-36642 A local file disclosure vulnerability in /appConfig/userDB.json of Telos Alliance Omnia MPX Node through 1.0.0-1.4.9 allows attackers to access users credentials which makes him able to gain initial access to the control panel with high privilege because the cleartext storage of sensitive information which can be unlatched by exploiting the LFD vulnerability. CRITICAL 9.8 12.88% cvelistv5 2026-06-17
cve-2022-36559 Seiko SkyBridge MB-A200 v01.00.04 and below was discovered to contain a command injection vulnerability via the Ping parameter at ping_exec.cgi. CRITICAL 9.8 1.76% cvelistv5 2026-06-17
cve-2022-36553 CVE-2022-36553 HIGH N/A 90.90% cvelistv5
cve-2022-36537 ZK Framework AuUploader Unspecified Vulnerability CRITICAL N/A 95.40% cvelistv5 2023-02-27
cve-2022-36509 CVE-2022-36509 HIGH 7.8 11.18% cvelistv5
cve-2022-36267 CVE-2022-36267 HIGH N/A 54.55% cvelistv5
cve-2022-35914 Teclib GLPI Remote Code Execution Vulnerability HIGH N/A 99.88% cvelistv5 2023-03-07
cve-2022-35653 moodle: LTI module reflected XSS risk - affecting unauthenticated users only MEDIUM 5.4 4.75% cvelistv5 2026-03-27
cve-2022-35413 WAPPLES through 6.0 has a hardcoded systemi account. A threat actor could use this account to access the system configuration and confidential information (such as SSL keys) via an HTTPS request to the /webapi/ URI on port 443 or 5001. CRITICAL 9.8 17.98% cvelistv5 2026-06-17
cve-2022-35405 Zoho ManageEngine Multiple Products Remote Code Execution Vulnerability CRITICAL 9.8 99.93% cvelistv5 2022-09-22
cve-2022-3481 CVE-2022-3481 HIGH N/A 3.95% cvelistv5
cve-2022-34753 CVE-2022-34753 HIGH 8.8 71.28% cvelistv5
cve-2022-34713 Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability HIGH N/A 67.76% cvelistv5 2022-08-09
cve-2022-34538 Digital Watchdog DW MEGApix IP cameras A7.2.2_20211029 was discovered to contain a command injection vulnerability in the component /admin/vca/bia/addacph.cgi. This vulnerability is exploitable via a crafted POST request. HIGH 8.8 2.73% cvelistv5 2026-06-17
cve-2022-34121 Cuppa CMS v1.0 was discovered to contain a local file inclusion (LFI) vulnerability via the component /templates/default/html/windows/right.php. HIGH 7.5 3.70% cvelistv5 2026-06-17
cve-2022-33891 SUSE CVE CVE-2022-33891 HIGH 8.8 93.08% cvelistv5 2025-07-02
cve-2022-32917 Apple iOS, iPadOS, and macOS Remote Code Execution Vulnerability HIGH 7.8 5.60% cvelistv5 2022-09-14
cve-2022-32894 Apple iOS and macOS Out-of-Bounds Write Vulnerability HIGH 7.8 3.29% cvelistv5 2022-08-18
cve-2022-32893 SUSE CVE CVE-2022-32893 HIGH 8.8 9.93% cvelistv5 2026-08-31
cve-2022-32409 CVE-2022-32409 HIGH N/A 13.40% cvelistv5
cve-2022-3236 Sophos Firewall Code Injection Vulnerability CRITICAL 9.8 98.91% cvelistv5 2022-09-23
cve-2022-31847 CVE-2022-31847 HIGH N/A 6.55% cvelistv5
cve-2022-31814 CVE-2022-31814 CRITICAL 9.8 91.88% cvelistv5
cve-2022-3180 CVE-2022-3180 CRITICAL 9.8 9.21% cvelistv5
cve-2022-31793 CVE-2022-31793 HIGH N/A 15.85% cvelistv5
cve-2022-31656 CVE-2022-31656 HIGH N/A 22.94% cvelistv5
cve-2022-31474 CVE-2022-31474 HIGH 7.5 63.76% cvelistv5
cve-2022-31208 An issue was discovered in Infiray IRAY-A8Z3 1.0.957. The webserver contains an endpoint that can execute arbitrary commands by manipulating the cmd_string URL parameter. HIGH 8.8 1.46% cvelistv5 2026-06-17
cve-2022-31199 Netwrix Auditor Insecure Object Deserialization Vulnerability CRITICAL 9.8 36.01% cvelistv5 2023-07-11