2022 CVE Vulnerabilities

27,554 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-23410HIGH7.8AXIS IP Utility before 4.18.0 allows for remote code execution and local privilege escalation by the means of DLL hijack...
CVE-2022-0586HIGH7.5Infinite loop in RTMPT protocol dissector in Wireshark 3.6.0 to 3.6.1 and 3.4.0 to 3.4.11 allows denial of service via p...
CVE-2022-0583HIGH7.5Crash in the PVFS protocol dissector in Wireshark 3.6.0 to 3.6.1 and 3.4.0 to 3.4.11 allows denial of service via packet...
CVE-2022-0582CRITICAL9.8Unaligned access in the CSN.1 protocol dissector in Wireshark 3.6.0 to 3.6.1 and 3.4.0 to 3.4.11 allows denial of servic...
CVE-2022-0581HIGH7.5Crash in the CMS protocol dissector in Wireshark 3.6.0 to 3.6.1 and 3.4.0 to 3.4.11 allows denial of service via packet ...
CVE-2022-24206CRITICAL9.8Tongda2000 v11.10 was discovered to contain a SQL injection vulnerability in /mobile_seal/get_seal.php via the DEVICE_LI...
CVE-2022-23902CRITICAL9.8Tongda2000 v11.10 was discovered to contain a SQL injection vulnerability in export_data.php via the d_name parameter.
CVE-2022-23638MEDIUM6.1svg-sanitizer is a SVG/XML sanitizer written in PHP. A cross-site scripting vulnerability impacts all users of the `svg-...
CVE-2022-23637MEDIUM5.4K-Box is a web-based application to manage documents, images, videos and geodata. Prior to version 0.33.1, a stored Cros...
CVE-2022-23391MEDIUM6.1A cross-site scripting (XSS) vulnerability in Pybbs v6.0 allows attackers to execute arbitrary web scripts or HTML via a...
CVE-2022-23390CRITICAL9.8An issue in the getType function of BBS Forum v5.3 and below allows attackers to upload arbitrary files.
CVE-2022-23389CRITICAL9.8PublicCMS v4.0 was discovered to contain a remote code execution (RCE) vulnerability via the cmdarray parameter.
CVE-2022-23337CRITICAL9.8DedeCMS v5.7.87 was discovered to contain a SQL injection vulnerability in article_coonepage_rule.php via the ids parame...
CVE-2022-23336CRITICAL9.8S-CMS v5.0 was discovered to contain a SQL injection vulnerability in member_pay.php via the O_id parameter.
CVE-2022-23335CRITICAL9.8Metinfo v7.5.0 was discovered to contain a SQL injection vulnerability in language_general.class.php via doModifyParamet...
CVE-2022-22295CRITICAL9.8Metinfo v7.5.0 was discovered to contain a SQL injection vulnerability in parameter_admin.class.php via the table_para p...
CVE-2022-24988CRITICAL9.8In galois_2p8 before 0.1.2, PrimitivePolynomialField::new has an off-by-one buffer overflow for a vector.
CVE-2022-25150HIGH7.8In Malwarebytes Binisoft Windows Firewall Control before 6.8.1.0, programs executed from the Tools tab can be used to es...
CVE-2022-0579MEDIUM6.5Missing Authorization in Packagist snipe/snipe-it prior to 5.3.9.
CVE-2022-23367MEDIUM6.1Fulusso v1.1 was discovered to contain a DOM-based cross-site scripting (XSS) vulnerability in /BindAccount/SuccessTips....
CVE-2022-22854HIGH8.8An access control issue in hprms/admin/?page=user/list of Hospital Patient Record Management System v1.0 allows attacker...
CVE-2022-0512MEDIUM5.3Authorization Bypass Through User-Controlled Key in NPM url-parse prior to 1.5.6.
CVE-2022-24686MEDIUM5.9HashiCorp Nomad and Nomad Enterprise 0.3.0 through 1.0.17, 1.1.11, and 1.2.5 artifact download functionality has a race ...
CVE-2022-24977CRITICAL9.8ImpressCMS before 1.4.2 allows unauthenticated remote code execution via ...../// directory traversal in origName or ima...
CVE-2022-24976CRITICAL9.1Atheme IRC Services before 7.2.12, when used in conjunction with InspIRCd, allows authentication bypass by ending an IRC...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now