2022 CVE Vulnerabilities

27,525 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-50997HIGH7.5Weaver (Fanwei) E-cology 8.0 and 9.0 contains a SQL injection vulnerability in the HrmCareerApplyPerView.jsp endpoint th...
CVE-2022-50974Rejected reason: This CVE ID has been rejected.
CVE-2022-4995CRITICAL9.8Weaver (Fanwei) E-cology 9.0 versions prior to 10.52 contain a file upload vulnerability that allows a remote, unauthent...
CVE-2022-4994In the Linux kernel, the following vulnerability has been resolved: KVM: x86: wean fast IN from emulator_pio_in Use __...
CVE-2022-4990HIGH7.3** UNSUPPORTED WHEN ASSIGNED ** Improper Validation of Specified Quantity in Input in the ASUS AI Suite 3 driver allows ...
CVE-2022-4989HIGH8.5** UNSUPPORTED WHEN ASSIGNED ** Improper Validation of Specified Quantity in Input in the ASUS AI Suite 3 driver allows ...
CVE-2022-50973CRITICAL9.8Yonyou KSOA 9.0 contains an unauthenticated arbitrary file upload vulnerability in the com.sksoft.bill.ImageUpload servl...
CVE-2022-50972CRITICAL9.8WooCommerce 7.1.0 contains a remote code execution vulnerability that allows attackers to execute arbitrary PHP code by ...
CVE-2022-50971HIGH8.5Malwarebytes 4.5 contains an unquoted service path vulnerability in the MBAMService executable that allows local attacke...
CVE-2022-47150MEDIUM4.3Cross-Site request forgery (CSRF) vulnerability in weDevs WooCommerce Conversion Tracking allows Cross Site Request Forg...
CVE-2022-45813MEDIUM5.4Missing Authorization vulnerability in BeRocket Advanced AJAX Product Filters allows Exploiting Incorrectly Configured A...
CVE-2022-44630MEDIUM4.6Cross-Site request forgery (CSRF) vulnerability in YITH YITH WooCommerce Product Slider Carousel allows Cross Site Reque...
CVE-2022-42479MEDIUM5.4Missing Authorization vulnerability in TemplateHouse Soledad allows Accessing Functionality Not Properly Constrained by ...
CVE-2022-48575LOW3.5A person with access to a Mac may be able to bypass Login Window. A consistency issue was addressed with improved state ...
CVE-2022-26758HIGH7.1A malicious application may cause unexpected changes in memory shared between processes. A memory corruption issue was a...
CVE-2022-50953MEDIUM6.9WordPress Plugin admin-word-count-column 2.2 contains a local file read vulnerability that allows unauthenticated attack...
CVE-2022-31114MEDIUM5.1backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages tha...
CVE-2022-49042HIGH7.8An inclusion of functionality from untrusted control sphere vulnerability in MinGW DLL component in Synology Hyper Backu...
CVE-2022-49036HIGH7.8An inclusion of functionality from untrusted control sphere vulnerability in OpenSSL configuration in Synology Active Ba...
CVE-2022-4992HIGH8.8Dräger Infinity Acute Care System and Standalone Infinity M540 patient monitors versions VG4.1.1, VG4.0.3, and lower (wi...
CVE-2022-4991HIGH7.4Tychon includes an OpenSSL component that specifies an OPENSSLDIR variable as a subdirectory that may be controllable by...
CVE-2022-41656MEDIUM4.3Missing Authorization vulnerability in Bizswoop Account Manager for WooCommerce allows Exploiting Incorrectly Configured...
CVE-2022-34363HIGH7.5Dell Unisphere for PowerMax vApp version prior to 10.0.0.2, contains an authorization bypass vulnerability in the  Unisp...
CVE-2022-31231HIGH7.5Dell ECS, versions 3.5 and 3.6, contain an Improper Access Control in the Identity and Access Management (IAM) module. A...
CVE-2022-23826LOW1.8A TOCTOU (Time-Of-Check to Time-Of-Use) in the graphics interface may allow an attacker to load registers repeatedly cre...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now