2022 CVE Vulnerabilities

27,525 CVEs published in 2022.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2022-28620CRITICAL9.8A remote authentication bypass vulnerability was discovered in HPE Cray Legacy Shasta System Solutions; HPE Slingshot; a...
CVE-2022-23170CRITICAL9.8SysAid - Okta SSO integration - was found vulnerable to XML External Entity Injection vulnerability. Any SysAid environm...
CVE-2022-21829CRITICAL9.8Concrete CMS Versions 9.0.0 through 9.0.2 and 8.5.7 and below can download zip files over HTTP and execute code from tho...
CVE-2022-1668CRITICAL9.8Weak default root user credentials allow remote attackers to easily obtain OS superuser privileges over the open TCP por...
CVE-2022-1521CRITICAL9.1LRM does not implement authentication or authorization by default. A malicious actor can inject, replay, modify, and/or ...
CVE-2022-1519CRITICAL9.8LRM does not restrict the types of files that can be uploaded to the affected product. A malicious actor can upload any ...
CVE-2022-1518CRITICAL9.8LRM contains a directory traversal vulnerability that can allow a malicious actor to upload outside the intended directo...
CVE-2022-1517CRITICAL9.8LRM utilizes elevated privileges. An unauthenticated malicious actor can upload and execute code remotely at the operati...
CVE-2022-31806CRITICAL9.8In CODESYS V2 PLCWinNT and Runtime Toolkit 32 in versions prior to V2.4.7.57 password protection is not enabled by defau...
CVE-2022-31802CRITICAL9.8In CODESYS Gateway Server V2 for versions prior to V2.3.9.38 only a part of the the specified password is been compared ...
CVE-2022-34181CRITICAL9.1Jenkins xUnit Plugin 3.0.8 and earlier implements an agent-to-controller message that creates a user-specified directory...
CVE-2022-33127CRITICAL9.8The function that calls the diff tool in Diffy 3.4.1 does not properly handle double quotes in a filename when run in a ...
CVE-2022-32554CRITICAL9.8Pure Storage FlashArray products running Purity//FA 6.2.0 - 6.2.3, 6.1.0 - 6.1.12, 6.0.0 - 6.0.8, 5.3.0 - 5.3.17, 5.2.x ...
CVE-2022-32535CRITICAL9.8The Bosch Ethernet switch PRA-ES8P2S with software version 1.01.05 runs its web server with root privilege. In combinati...
CVE-2022-32534CRITICAL9.8The Bosch Ethernet switch PRA-ES8P2S with software version 1.01.05 and earlier was found to be vulnerable to command inj...
CVE-2022-31787CRITICAL9.8IdeaTMS 2022 is vulnerable to SQL Injection via the PATH_INFO
CVE-2022-31361CRITICAL9.8Docebo Community Edition v4.0.5 and below was discovered to contain a SQL injection vulnerability. NOTE: This vulnerabil...
CVE-2022-22980CRITICAL9.8A Spring Data MongoDB application is vulnerable to SpEL Injection when using @Query or @Aggregation-annotated query meth...
CVE-2022-26147CRITICAL9.8The Quectel RG502Q-EA modem before 2022-02-23 allow OS Command Injection.
CVE-2022-29775CRITICAL9.8iSpyConnect iSpy v7.2.2.0 allows attackers to bypass authentication via a crafted URL.
CVE-2022-29774CRITICAL9.8iSpy v7.2.2.0 is vulnerable to remote command execution via path traversal.
CVE-2022-33139CRITICAL9.8A vulnerability has been identified in Cerberus DMS (All versions), Desigo CC (All versions), Desigo CC Compact (All ver...
CVE-2022-31374CRITICAL9.8An arbitrary file upload vulnerability /images/background/1.php in of SolarView Compact 6.0 allows attackers to execute ...
CVE-2022-31801CRITICAL9.8An unauthenticated, remote attacker could upload malicious logic to the devices based on ProConOS/ProConOS eCLR in order...
CVE-2022-31800CRITICAL9.8An unauthenticated, remote attacker could upload malicious logic to devices based on ProConOS/ProConOS eCLR in order to ...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now