2022 CVE Vulnerabilities

27,525 CVEs published in 2022.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2022-1692CRITICAL9.8The CP Image Store with Slideshow WordPress plugin before 1.0.68 does not sanitise and escape the ordering_by query para...
CVE-2022-0788CRITICAL9.8The WP Fundraising Donation and Crowdfunding Platform WordPress plugin before 1.5.0 does not sanitise and escape a param...
CVE-2022-21122CRITICAL9.8The package metacalc before 0.0.2 are vulnerable to Arbitrary Code Execution when it exposes JavaScript's Math class to ...
CVE-2022-24065CRITICAL9.8The package cookiecutter before 2.1.1 are vulnerable to Command Injection via hg argument injection. When calling the co...
CVE-2022-30722CRITICAL9.8Implicit Intent hijacking vulnerability in Samsung Account prior to SMR Jun-2022 Release 1 allows attackers to bypass us...
CVE-2022-30713CRITICAL9.1Improper validation vulnerability in LSOItemData prior to SMR Jun-2022 Release 1 allows attackers to launch certain acti...
CVE-2022-30712CRITICAL9.1Improper validation vulnerability in KfaOptions prior to SMR Jun-2022 Release 1 allows attackers to launch certain activ...
CVE-2022-30711CRITICAL9.1Improper validation vulnerability in FeedsInfo prior to SMR Jun-2022 Release 1 allows attackers to launch certain activi...
CVE-2022-30710CRITICAL9.1Improper validation vulnerability in RemoteViews prior to SMR Jun-2022 Release 1 allows attackers to launch certain acti...
CVE-2022-25361CRITICAL9.1WatchGuard Firebox and XTM appliances allow an unauthenticated remote attacker to delete arbitrary files from a limited ...
CVE-2022-30927CRITICAL9.8A SQL injection vulnerability exists in Simple Task Scheduling System 1.0 when MySQL is being used as the application da...
CVE-2022-32511CRITICAL9.8jmespath.rb (aka JMESPath for Ruby) before 1.6.1 uses JSON.load in a situation where JSON.parse is preferable.
CVE-2022-31768CRITICAL9.8IBM InfoSphere Information Server 11.7 is vulnerable to SQL injection. A remote attacker could send specially crafted SQ...
CVE-2022-31481CRITICAL10An unauthenticated attacker can send a specially crafted update file to the device that can overflow a buffer. This vuln...
CVE-2022-31479CRITICAL9.8An unauthenticated attacker can update the hostname with a specially crafted name that will allow for shell commands to ...
CVE-2022-26134CRITICAL9.8In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un...
CVE-2022-32271CRITICAL9.6In Real Player 20.0.8.310, there is a DCP:// URI Remote Arbitrary Code Execution Vulnerability. This is an internal URL ...
CVE-2022-32270CRITICAL9.8In Real Player 20.0.7.309 and 20.0.8.310, external::Import() allows download of arbitrary file types and Directory Trave...
CVE-2022-32269CRITICAL9.8In Real Player 20.0.8.310, the G2 Control allows injection of unsafe javascript: URIs in local HTTP error pages (display...
CVE-2022-30235CRITICAL9.8A CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists that could allow unauthorized ...
CVE-2022-30234CRITICAL9.8A CWE-798: Use of Hard-coded Credentials vulnerability exists that could allow arbitrary code to be executed when root l...
CVE-2022-29084CRITICAL9.8Dell Unity, Dell UnityVSA, and Dell Unity XT versions before 5.2.0.0.5.173 do not restrict excessive authentication atte...
CVE-2022-26869CRITICAL9.8Dell PowerStore versions 2.0.0.x, 2.0.1.x and 2.1.0.x contains an open port vulnerability. A remote unauthenticated atta...
CVE-2022-32019CRITICAL9.8Car Rental Management System v1.0 is vulnerable to Arbitrary code execution via car-rental-management-system/admin/ajax....
CVE-2022-29704CRITICAL9.8BrowsBox CMS v4.0 was discovered to contain a SQL injection vulnerability.

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now