2022 CVE Vulnerabilities

27,525 CVEs published in 2022.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2022-29517HIGH8.8A directory traversal vulnerability exists in the HelpdeskActions.aspx edittemplate functionality of Lansweeper lansweep...
CVE-2022-4506HIGH8.8Unrestricted Upload of File with Dangerous Type in GitHub repository openemr/openemr prior to 7.0.0.2.
CVE-2022-4504HIGH7.5Improper Input Validation in GitHub repository openemr/openemr prior to 7.0.0.2.
CVE-2022-4283HIGH7.8A vulnerability was found in X.Org. This security flaw occurs because the XkbCopyNames function left a dangling pointer ...
CVE-2022-47411HIGH7.5An issue was discovered in the fp_newsletter (aka Newsletter subscriber management) extension before 1.1.1, 1.2.0, 2.x b...
CVE-2022-47410HIGH7.5An issue was discovered in the fp_newsletter (aka Newsletter subscriber management) extension before 1.1.1, 1.2.0, 2.x b...
CVE-2022-47409HIGH7.5An issue was discovered in the fp_newsletter (aka Newsletter subscriber management) extension before 1.1.1, 1.2.0, 2.x b...
CVE-2022-46344HIGH8.8A vulnerability was found in X.Org. This security flaw occurs because the handler for the XIChangeProperty request has a...
CVE-2022-46343HIGH8.8A vulnerability was found in X.Org. This security flaw occurs because the handler for the ScreenSaverSetAttributes reque...
CVE-2022-46342HIGH8.8A vulnerability was found in X.Org. This security flaw occurs because the handler for the XvdiSelectVideoNotify request ...
CVE-2022-46341HIGH8.8A vulnerability was found in X.Org. This security flaw occurs because the handler for the XIPassiveUngrab request access...
CVE-2022-46340HIGH8.8A vulnerability was found in X.Org. This security flaw occurs becuase the swap handler for the XTestFakeInput request of...
CVE-2022-2601HIGH8.6A buffer overflow was found in grub_font_construct_glyph(). A malicious crafted pf2 font can lead to an overflow when ca...
CVE-2022-31705HIGH8.2VMware ESXi, Workstation, and Fusion contain a heap out-of-bounds write vulnerability in the USB 2.0 controller (EHCI). ...
CVE-2022-31703HIGH7.5The vRealize Log Insight contains a Directory Traversal Vulnerability. An unauthenticated, malicious actor can inject fi...
CVE-2022-31700HIGH7.2VMware Workspace ONE Access and Identity Manager contain an authenticated remote code execution vulnerability. VMware ha...
CVE-2022-23741HIGH7.2An incorrect authorization vulnerability was identified in GitHub Enterprise Server that allowed a scoped user-to-server...
CVE-2022-46443HIGH8.8mesinkasir Bangresto 1.0 is vulnberable to SQL Injection via the itemqty%5B%5D parameter.
CVE-2022-46256HIGH8.8A path traversal vulnerability was identified in GitHub Enterprise Server that allowed remote code execution when buildi...
CVE-2022-44910HIGH7.8Binbloom 2.0 was discovered to contain a heap buffer overflow via the read_pointer function at /binbloom-master/src/help...
CVE-2022-46127HIGH7.2Helmet Store Showroom Site v1.0 is vulnerable to SQL Injection via /hss/classes/Master.php?f=delete_product.
CVE-2022-46126HIGH7.2Helmet Store Showroom Site v1.0 is vulnerable to SQL Injection via /hss/admin/brands/manage_brand.php?id=.
CVE-2022-46125HIGH7.2Helmet Store Showroom Site v1.0 is vulnerable to SQL Injection via /hss/admin/?page=client/manage_client&id=.
CVE-2022-46124HIGH7.2Helmet Store Showroom Site v1.0 is vulnerable to SQL Injection via /hss/admin/?page=user/manage_user&id=.
CVE-2022-46123HIGH7.2Helmet Store Showroom Site v1.0 is vulnerable to SQL Injection via /hss/admin/categories/manage_category.php?id=.

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now