2022 CVE Vulnerabilities

27,525 CVEs published in 2022.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2022-23556HIGH7.5CodeIgniter is a PHP full-stack web framework. This vulnerability may allow attackers to spoof their IP address when the...
CVE-2022-23540HIGH7.6In versions `<=8.5.1` of `jsonwebtoken` library, lack of algorithm definition in the `jwt.verify()` function can lead to...
CVE-2022-46101HIGH8.8AyaCMS v3.1.2 was found to have a code flaw in the ust_sql.inc.php file, which allows attackers to cause command executi...
CVE-2022-47896HIGH7.8In JetBrains IntelliJ IDEA before 2022.3.1 code Templates were vulnerable to SSTI attacks.
CVE-2022-47895HIGH7.5In JetBrains IntelliJ IDEA before 2022.3.1 the "Validate JSP File" action used the HTTP protocol to download required JA...
CVE-2022-3186HIGH7.5Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where the affected product allows an atta...
CVE-2022-46334HIGH7.8Proofpoint Enterprise Protection (PPS/PoD) contains a vulnerability which allows the pps user to escalate to root privil...
CVE-2022-4633HIGH8.8A vulnerability was found in Auto Upload Images up to 3.3.0 and classified as problematic. Affected by this issue is som...
CVE-2022-36222HIGH8.4Nokia Fastmile 3tg00118abad52 devices shipped by Optus are shipped with a default hardcoded admin account of admin:Nq+L5...
CVE-2022-4287HIGH8.8Authentication bypass in local application lock feature in Devolutions Remote Desktop Manager  2022.3.26 and earlier on ...
CVE-2022-47581HIGH7.5Isode M-Vault 16.0v0 through 17.x before 17.0v24 can crash upon an LDAP v1 bind request.
CVE-2022-38065HIGH8.8A privilege escalation vulnerability exists in the oslo.privsep functionality of OpenStack git master 05194e7618 and pri...
CVE-2022-38060HIGH8.8A privilege escalation vulnerability exists in the sudo functionality of OpenStack Kolla git master 05194e7618. A miscon...
CVE-2022-46330HIGH7.8Squirrel.Windows is both a toolset and a library that provides installation and update functionality for Windows desktop...
CVE-2022-46282HIGH7.8Use after free vulnerability in CX-Drive V3.00 and earlier allows a local attacker to execute arbitrary code by having a...
CVE-2022-25895HIGH7.5All versions of package lite-dev-server are vulnerable to Directory Traversal due to missing input sanitization and sand...
CVE-2022-42949HIGH7.5Silverstripe silverstripe/subsites through 2.6.0 has Insecure Permissions.
CVE-2022-42046HIGH7.8wfshbr64.sys and wfshbr32.sys specially crafted IOCTL allows arbitrary user to perform local privilege escalation
CVE-2022-46328HIGH7.5Some smartphones have the input validation vulnerability. Successful exploitation of this vulnerability may affect data ...
CVE-2022-46322HIGH7.5Some smartphones have the out-of-bounds write vulnerability. Successful exploitation of this vulnerability may cause sys...
CVE-2022-46321HIGH7.5The Wi-Fi module has a vulnerability in permission verification. Successful exploitation of this vulnerability may affec...
CVE-2022-46317HIGH7.5The power consumption module has an out-of-bounds read vulnerability. Successful exploitation of this vulnerability may ...
CVE-2022-46315HIGH7.5The ProfileSDK has defects introduced in the design process. Successful exploitation of this vulnerability may affect sy...
CVE-2022-46314HIGH7.5The IPC module has defects introduced in the design process. Successful exploitation of this vulnerability may affect sy...
CVE-2022-46312HIGH7.5The application management module has a vulnerability in permission verification. Successful exploitation of this vulner...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now