2022 CVE Vulnerabilities

27,525 CVEs published in 2022.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2022-36231CRITICAL9.8pdf_info 0.5.3 is vulnerable to Command Execution because the Ruby code uses backticks instead of Open3.
CVE-2022-48342CRITICAL9.8In JetBrains TeamCity before 2022.10.2 jVMTI was enabled by default on agents.
CVE-2022-2504CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SDD Computer Softw...
CVE-2022-48149CRITICAL9.8Online Student Admission System in PHP Free Source Code 1.0 was discovered to contain a SQL injection vulnerability via ...
CVE-2022-45599CRITICAL9.8Aztech WMB250AC Mesh Routers Firmware Version 016 2020 is vulnerable to PHP Type Juggling in file /var/www/login.php, al...
CVE-2022-39983CRITICAL9.8File upload vulnerability in Pro Gamma Instant Developer RD3 22.5 r23, r30, and possibly earlier versions, allows attack...
CVE-2022-41217CRITICAL9.8Cloudflow contains a unauthenticated file upload vulnerability, which makes it possible for an attacker to upload malici...
CVE-2022-46637CRITICAL9.8Prolink router PRS1841 was discovered to contain hardcoded credentials for its Telnet and FTP services.
CVE-2022-45677CRITICAL9.8SQL Injection Vulnerability in tanujpatra228 Tution Management System (TMS) via the email parameter to processes/student...
CVE-2022-45564CRITICAL9.8SQL Injection vulnerability in znfit Home improvement ERP management system V50_20220207,v42 allows attackers to execute...
CVE-2022-48337CRITICAL9.8GNU Emacs through 28.2 allows attackers to execute commands via shell metacharacters in the name of a source-code file, ...
CVE-2022-48317CRITICAL9.8Expired sessions were not securely terminated in the RestAPI for Tribe29's Checkmk <= 2.1.0p10 and Checkmk <= 2.0.0p28 a...
CVE-2022-48329CRITICAL9.8MISP before 2.4.166 unsafely allows users to use the order parameter, related to app/Model/Attribute.php, app/Model/Gala...
CVE-2022-48328CRITICAL9.8app/Controller/Component/IndexFilterComponent.php in MISP before 2.4.167 mishandles ordered_url_params and additional_de...
CVE-2022-40021CRITICAL9.8QVidium Technologies Amino A140 (prior to firmware version 1.0.0-283) was discovered to contain a command injection vuln...
CVE-2022-47986CRITICAL9.8IBM Aspera Faspex 4.4.2 Patch Level 1 and earlier could allow a remote attacker to execute arbitrary code on the system,...
CVE-2022-40032CRITICAL9.8SQL Injection vulnerability in Simple Task Managing System version 1.0 in login.php in 'username' and 'password' paramet...
CVE-2022-40347CRITICAL9.8SQL Injection vulnerability in Intern Record System version 1.0 in /intern/controller.php in 'phone', 'email', 'deptType...
CVE-2022-33964CRITICAL9.8Improper input validation in the Intel(R) SUR software before version 2.4.8902 may allow an unauthenticated user to pote...
CVE-2022-29514CRITICAL9.8Improper access control in the Intel(R) SUR software before version 2.4.8902 may allow an unauthenticated user to potent...
CVE-2022-26843CRITICAL9.8Insufficient visual distinction of homoglyphs presented to user in the Intel(R) oneAPI DPC++/C++ Compiler before version...
CVE-2022-25987CRITICAL9.8Improper handling of Unicode encoding in source code to be compiled by the Intel(R) C++ Compiler Classic before version ...
CVE-2022-39954CRITICAL9.1An improper restriction of xml external entity reference in Fortinet FortiNAC version 9.4.0 through 9.4.1, FortiNAC vers...
CVE-2022-39952CRITICAL9.8A external control of file name or path in Fortinet FortiNAC versions 9.4.0, 9.2.0 through 9.2.5, 9.1.0 through 9.1.7, 8...
CVE-2022-38375CRITICAL9.8An improper authorization vulnerability [CWE-285]  in Fortinet FortiNAC version 9.4.0 through 9.4.1 and before 9.2.6 all...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now