2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2022-30122HIGH7.5A possible denial of service vulnerability exists in Rack <2.0.9.1, <2.1.4.1 and <2.2.3.1 in the multipart parsing compo...
CVE-2022-2827HIGH7.5AMI MegaRAC User Enumeration Vulnerability
CVE-2022-37783HIGH7.5All Craft CMS versions between 3.0.0 and 3.7.32 disclose password hashes of users who authenticate using their E-Mail ad...
CVE-2022-37325HIGH7.5In Sangoma Asterisk through 16.28.0, 17.x and 18.x through 18.14.0, and 19.x through 19.6.0, an incoming Setup message t...
CVE-2022-45771HIGH8.8An issue in the /api/audits component of Pwndoc v0.5.3 allows attackers to escalate privileges and execute arbitrary cod...
CVE-2022-4292HIGH7.8Use After Free in GitHub repository vim/vim prior to 9.0.0882.
CVE-2022-3907HIGH7.5The Clerk WordPress plugin before 4.0.0 is affected by time-based attacks in the validation function for all API request...
CVE-2022-3858HIGH7.2The Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line, WeChat, Email, SMS, Call Button WordPress plugin befo...
CVE-2022-3856HIGH7.2The Comic Book Management System WordPress plugin before 2.2.0 does not sanitize and escape a parameter before using it ...
CVE-2022-3846HIGH7.5The Workreap WordPress theme before 2.6.3 has a vulnerability with the notifications feature as it's possible to read an...
CVE-2022-3694HIGH7.5The Syncee WordPress plugin before 1.0.10 leaks the administrator token that can be used to take over the administrator'...
CVE-2022-3249HIGH7.2The WP CSV Exporter WordPress plugin before 1.3.7 does not properly sanitise and escape some parameters before using the...
CVE-2022-1540HIGH7.2The PostmagThemes Demo Import WordPress plugin through 1.0.7 does not validate the imported file, allowing high-privileg...
CVE-2022-45313HIGH8.8Mikrotik RouterOs before stable v7.5 was discovered to contain an out-of-bounds read in the hotspot process. This vulner...
CVE-2022-4282HIGH7.2A vulnerability was found in SpringBootCMS and classified as critical. Affected by this issue is some unknown functional...
CVE-2022-4281HIGH8.8A vulnerability has been found in Facepay 1.0 and classified as critical. Affected by this vulnerability is an unknown f...
CVE-2022-43484HIGH7.8TERASOLUNA Global Framework 1.0.0 (Public review version) and TERASOLUNA Server Framework for Java (Rich) 2.0.0.2 to 2.0...
CVE-2022-43470HIGH7.3Cross-site request forgery (CSRF) vulnerability in +F FS040U software versions v2.3.4 and earlier, +F FS020W software ve...
CVE-2022-41777HIGH7.5Improper check or handling of exceptional conditions vulnerability in Nako3edit, editor component of nadesiko3 (PC Versi...
CVE-2022-35507HIGH7.1A response-header CRLF injection vulnerability in the Proxmox Virtual Environment (PVE) and Proxmox Mail Gateway (PMG) w...
CVE-2022-46413HIGH8.8An issue was discovered in Veritas NetBackup Flex Scale through 3.0 and Access Appliance through 8.0.100. Authenticated ...
CVE-2022-46412HIGH8.8An issue was discovered in Veritas NetBackup Flex Scale through 3.0. A non-privileged user may escape a restricted shell...
CVE-2022-46411HIGH8.8An issue was discovered in Veritas NetBackup Flex Scale through 3.0 and Access Appliance through 8.0.100. A default pass...
CVE-2022-46410HIGH8.8An issue was discovered in Veritas NetBackup Flex Scale through 3.0. An attacker with non-root privileges may escalate p...
CVE-2022-46405HIGH7.5Mastodon through 4.0.2 allows attackers to cause a denial of service (large Sidekiq pull queue) by creating bot accounts...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now