2022 CVE Vulnerabilities

27,554 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-25003CRITICAL9.8Hospital Patient Record Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parame...
CVE-2022-24232HIGH7.8A local file inclusion in Hospital Patient Record Management System v1.0 allows attackers to execute arbitrary code via ...
CVE-2022-23922HIGH7.8WIN-911 2021 R1 and R2 are vulnerable to a permissions misconfiguration that may allow an attacker to locally write file...
CVE-2022-23135MEDIUM6.5There is a directory traversal vulnerability in some home gateway products of ZTE. Due to the lack of verification of us...
CVE-2022-23104HIGH7.8WIN-911 2021 R1 and R2 are vulnerable to a permissions misconfiguration that may allow an attacker to locally write file...
CVE-2022-21824HIGH8.2Due to the formatting logic of the "console.table()" function it was not safe to allow user controlled input to be passe...
CVE-2022-0710MEDIUM6.1The Header Footer Code Manager plugin <= 1.1.16 for WordPress is vulnerable to Reflected Cross-Site Scripting (XSS) via ...
CVE-2022-0683MEDIUM6.1The Essential Addons for Elementor Lite WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escap...
CVE-2022-0653MEDIUM6.1The Profile Builder – User Profile & User Registration Forms WordPress plugin is vulnerable to Cross-Site Scripting due ...
CVE-2022-0651HIGH7.5The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of t...
CVE-2022-0546HIGH7.8A missing bounds check in the image loader used in Blender 3.x and 2.93.8 leads to out-of-bounds heap access, allowing a...
CVE-2022-0545HIGH7.8An integer overflow in the processing of loaded 2D images leads to a write-what-where vulnerability and an out-of-bounds...
CVE-2022-0544MEDIUM5.5An integer underflow in the DDS loader of Blender leads to an out-of-bounds read, possibly allowing an attacker to read ...
CVE-2022-22794CRITICAL9.8Cybonet - PineApp Mail Relay Unauthenticated Sql Injection. Attacker can send a request to: /manage/emailrichment/userli...
CVE-2022-22793HIGH7.5Cybonet - PineApp Mail Relay Local File Inclusion. Attacker can send a request to : /manage/mailpolicymtm/log/eml_viewer...
CVE-2022-22349MEDIUM4.3IBM Sterling External Authentication Server 3.4.3.2, 6.0.2.0, and 6.0.3.0 is vulnerable to path traversals, due to not p...
CVE-2022-24708MEDIUM5.4Anuko Time Tracker is an open source, web-based time tracking application written in PHP. ttUser.class.php in Time Track...
CVE-2022-24707HIGH8.8Anuko Time Tracker is an open source, web-based time tracking application written in PHP. UNION SQL injection and time-b...
CVE-2022-24687MEDIUM6.5HashiCorp Consul and Consul Enterprise 1.9.0 through 1.9.14, 1.10.7, and 1.11.2 clusters with at least one Ingress Gatew...
CVE-2022-0732HIGH7.5The backend infrastructure shared by multiple mobile device monitoring services does not adequately authenticate or auth...
CVE-2022-25838HIGH8.1Laravel Fortify before 1.11.1 allows reuse within a short time window, thus calling into question the "OT" part of the "...
CVE-2022-25809CRITICAL9.8Improper Neutralization of audio output from 3rd and 4th Generation Amazon Echo Dot devices allows arbitrary voice comma...
CVE-2022-25643CRITICAL9.8seatd-launch in seatd 0.6.x before 0.6.4 allows removing files with escalated privileges when installed setuid root. The...
CVE-2022-25640HIGH7.5In wolfSSL before 5.2.0, a TLS 1.3 server cannot properly enforce a requirement for mutual authentication. A client can ...
CVE-2022-25638MEDIUM6.5In wolfSSL before 5.2.0, certificate validation may be bypassed during attempted authentication by a TLS 1.3 client to a...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now