2022 CVE Vulnerabilities

27,525 CVEs published in 2022.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2022-30309CRITICAL9.8In Festo Controller CECC-X-M1 product family in multiple versions, the http-endpoint "cecc-x-web-viewer-request-off" POS...
CVE-2022-30308CRITICAL9.8In Festo Controller CECC-X-M1 product family in multiple versions, the http-endpoint "cecc-x-web-viewer-request-on" POST...
CVE-2022-2067CRITICAL9.1SQL Injection in GitHub repository francoisjacquet/rosariosis prior to 9.0.
CVE-2022-0885CRITICAL9.8The Member Hero WordPress plugin through 1.0.9 lacks authorization checks, and does not validate the a request parameter...
CVE-2022-0827CRITICAL9.8The Bestbooks WordPress plugin through 2.6.3 does not sanitise and escape some parameters before using them in a SQL sta...
CVE-2022-0786CRITICAL9.8The KiviCare WordPress plugin before 2.3.9 does not sanitise and escape some parameters before using them in SQL stateme...
CVE-2022-29525CRITICAL9.8Rakuten Casa version AP_F_V1_4_1 or AP_F_V2_0_0 uses a hard-coded credential which may allow a remote unauthenticated at...
CVE-2022-29095CRITICAL9.6Dell SupportAssist Client Consumer versions (3.10.4 and prior) and Dell SupportAssist Client Commercial versions (3.1.1 ...
CVE-2022-25863CRITICAL9.8The package gatsby-plugin-mdx before 2.14.1, from 3.0.0 and before 3.15.2 are vulnerable to Deserialization of Untrusted...
CVE-2022-25845CRITICAL9.8The package com.alibaba:fastjson before 1.2.83 are vulnerable to Deserialization of Untrusted Data by bypassing the defa...
CVE-2022-24376CRITICAL9.8All versions of package git-promise are vulnerable to Command Injection due to an inappropriate fix of a prior [vulnerab...
CVE-2022-24278CRITICAL9.8The package convert-svg-core before 0.6.4 are vulnerable to Directory Traversal due to improper sanitization of SVG tags...
CVE-2022-31788CRITICAL9.8IdeaLMS 2022 allows SQL injection via the IdeaLMS/ChatRoom/ClassAccessControl/6?isBigBlueButton=0&ClassID= pathname.
CVE-2022-32563CRITICAL9.8An issue was discovered in Couchbase Sync Gateway 3.x before 3.0.2. Admin credentials are not verified when using X.509 ...
CVE-2022-31045CRITICAL9.8Istio is an open platform to connect, manage, and secure microservices. In affected versions ill-formed headers sent to ...
CVE-2022-29226CRITICAL9.1Envoy is a cloud-native high-performance proxy. In versions prior to 1.22.1 the OAuth filter implementation does not inc...
CVE-2022-31813CRITICAL9.8Apache HTTP Server 2.4.53 and earlier may not send the X-Forwarded-* headers to the origin server based on client side C...
CVE-2022-28615CRITICAL9.1Apache HTTP Server 2.4.53 and earlier may crash or disclose information due to a read beyond bounds in ap_strcmp_match()...
CVE-2022-1992CRITICAL9.1Path Traversal in GitHub repository gogs/gogs prior to 0.12.9.
CVE-2022-1986CRITICAL9.8OS Command Injection in GitHub repository gogs/gogs prior to 0.12.9.
CVE-2022-31031CRITICAL9.8PJSIP is a free and open source multimedia communication library written in C language implementing standard based proto...
CVE-2022-32272CRITICAL9.8OPSWAT MetaDefender Core before 5.1.2, MetaDefender ICAP before 4.12.1, and MetaDefender Email Gateway Security before 5...
CVE-2022-31830CRITICAL9.1Kity Minder v1.3.5 was discovered to contain a Server-Side Request Forgery (SSRF) via the init function at ImageCapture....
CVE-2022-31827CRITICAL9.1MonstaFTP v2.10.3 was discovered to contain a Server-Side Request Forgery (SSRF) via the function performFetchRequest at...
CVE-2022-31393CRITICAL9.1Jizhicms v2.2.5 was discovered to contain a Server-Side Request Forgery (SSRF) vulnerability via the Index function in a...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now