2022 CVE Vulnerabilities

27,554 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-22938MEDIUM6.5VMware Workstation (16.x prior to 16.2.2) and Horizon Client for Windows (5.x prior to 5.5.3) contains a denial-of-servi...
CVE-2022-22791MEDIUM5.4SYNEL - eharmony Authenticated Blind & Stored XSS. Inject JS code into the "comments" field could lead to potential stea...
CVE-2022-22790HIGH7.5SYNEL - eharmony Directory Traversal. Directory Traversal - is an attack against a server or a Web application aimed at ...
CVE-2022-21801HIGH7.5A denial of service vulnerability exists in the netserver recv_command functionality of reolink RLC-410W v3.0.0.136_2012...
CVE-2022-21796HIGH8.2A memory corruption vulnerability exists in the netserver parse_command_list functionality of reolink RLC-410W v3.0.0.13...
CVE-2022-21236HIGH7.5An information disclosure vulnerability exists due to a web server misconfiguration in the Reolink RLC-410W v3.0.0.136_2...
CVE-2022-21217CRITICAL9.8An out-of-bounds write vulnerability exists in the device TestEmail functionality of reolink RLC-410W v3.0.0.136_2012110...
CVE-2022-21199MEDIUM5.9An information disclosure vulnerability exists due to the hardcoded TLS key of reolink RLC-410W v3.0.0.136_20121102. A s...
CVE-2022-21134HIGH7.5A firmware update vulnerability exists in the "update" firmware checks functionality of reolink RLC-410W v3.0....
CVE-2022-22868MEDIUM4.8Gibbon CMS v22.0.01 was discovered to contain a cross-site scripting (XSS) vulnerability, that allows attackers to injec...
CVE-2022-22294CRITICAL9.8A SQL injection vulnerability exists in ZFAKA<=1.43 which an attacker can use to complete SQL injection in the foregroun...
CVE-2022-23863MEDIUM6.5Zoho ManageEngine Desktop Central before 10.1.2137.10 allows an authenticated user to change any user's login password.
CVE-2022-23098HIGH7.5An issue was discovered in the DNS proxy in Connman through 1.40. The TCP server reply implementation has an infinite lo...
CVE-2022-23097CRITICAL9.1An issue was discovered in the DNS proxy in Connman through 1.40. forward_dns_reply mishandles a strnlen call, leading t...
CVE-2022-23096CRITICAL9.1An issue was discovered in the DNS proxy in Connman through 1.40. The TCP server reply implementation lacks a check for ...
CVE-2022-24071MEDIUM4.3A Built-in extension in Whale browser before 3.12.129.46 allows attackers to compromise the rendering process which coul...
CVE-2022-21720MEDIUM4.9GLPI is a free asset and IT management software package. Prior to version 9.5.7, an entity administrator is capable of r...
CVE-2022-0394MEDIUM5.4Cross-site Scripting (XSS) - Stored in Packagist remdex/livehelperchat prior to 3.93v.
CVE-2022-21719MEDIUM6.1GLPI is a free asset and IT management software package. All GLPI versions prior to 9.5.7 are vulnerable to reflected cr...
CVE-2022-0348MEDIUM5.4Cross-site Scripting (XSS) - Stored in Packagist pimcore/pimcore prior to 10.2.
CVE-2022-23181HIGH7The fix for bug CVE-2020-9484 introduced a time of check, time of use vulnerability into Apache Tomcat 10.1.0-M1 to 10.1...
CVE-2022-0372MEDIUM5.4Cross-site Scripting (XSS) - Stored in Packagist bytefury/crater prior to 6.0.2.
CVE-2022-22828HIGH7.5An insecure direct object reference for the file-download URL in Synametrics SynaMan before 5.0 allows a remote attacker...
CVE-2022-0387MEDIUM5.4Cross-site Scripting (XSS) - Stored in Packagist remdex/livehelperchat prior to 3.93v.
CVE-2022-0370MEDIUM5.4Cross-site Scripting (XSS) - Stored in Packagist remdex/livehelperchat prior to 3.93v.

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now