2022 CVE Vulnerabilities

27,525 CVEs published in 2022.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2022-1586CRITICAL9.1An out-of-bounds read vulnerability was discovered in the PCRE2 library in the compile_xclass_matchingpath() function of...
CVE-2022-23666CRITICAL9.1A authenticated remote command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10...
CVE-2022-23665CRITICAL9.1A authenticated remote command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10...
CVE-2022-23664CRITICAL9.1A authenticated remote command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10...
CVE-2022-23663CRITICAL9.1A authenticated remote command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10...
CVE-2022-23662CRITICAL9.1A authenticated remote command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10...
CVE-2022-23661CRITICAL9.1A authenticated remote command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10...
CVE-2022-23660CRITICAL10A remote authentication bypass vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and bel...
CVE-2022-23658CRITICAL10A remote authentication bypass vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and bel...
CVE-2022-23657CRITICAL10A remote authentication bypass vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and bel...
CVE-2022-1731CRITICAL9.8Metasonic Doc WebClient 7.0.14.0 / 7.0.12.0 / 7.0.3.0 is vulnerable to a SQL injection attack in the username field. SSO...
CVE-2022-30055CRITICAL9.8Prime95 30.7 build 9 suffers from a Buffer Overflow vulnerability that could lead to Remote Code Execution.
CVE-2022-1386CRITICAL9.8The Fusion Builder WordPress plugin before 3.6.2, used in the Avada theme, does not validate a parameter in its forms wh...
CVE-2022-0867CRITICAL9.8The Pricing Table WordPress plugin before 3.6.1 fails to properly sanitize and escape user supplied POST data before it ...
CVE-2022-29622CRITICAL9.8An arbitrary file upload vulnerability in formidable v3.1.4 allows attackers to execute arbitrary code via a crafted fil...
CVE-2022-29354CRITICAL9.8An arbitrary file upload vulnerability in the file upload module of Keystone v4.2.1 allows attackers to execute arbitrar...
CVE-2022-29353CRITICAL9.8An arbitrary file upload vulnerability in the file upload module of Graphql-upload v13.0.0 allows attackers to execute a...
CVE-2022-29351CRITICAL9.8An arbitrary file upload vulnerability in the file upload module of Tiddlywiki5 v5.2.2 allows attackers to execute arbit...
CVE-2022-30011CRITICAL9.8In HMS 1.0 when requesting appointment.php through POST, multiple parameters can lead to a SQL injection vulnerability.
CVE-2022-30767CRITICAL9.8nfs_lookup_reply in net/nfs.c in Das U-Boot through 2022.04 (and through 2022.07-rc2) has an unbounded memcpy with a fai...
CVE-2022-30765CRITICAL9.8Calibre-Web before 0.6.18 allows user table SQL Injection.
CVE-2022-28930CRITICAL9.8ERP-Pro v3.7.5 was discovered to contain a SQL injection vulnerability via the component /base/SysEveMenuAuthPointMapper...
CVE-2022-28929CRITICAL9.8Hospital Management System v1.0 was discovered to contain a SQL injection vulnerability via the delid parameter at viewt...
CVE-2022-1379CRITICAL9.1URL Restriction Bypass in GitHub repository plantuml/plantuml prior to V1.2022.5. An attacker can abuse this to bypass U...
CVE-2022-24831CRITICAL9.8OpenClinica is an open source software for Electronic Data Capture (EDC) and Clinical Data Management (CDM). Versions pr...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now