2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2022-41568HIGH7.5LINE client for iOS before 12.17.0 might be crashed by sharing an invalid shared key of e2ee in group chat.
CVE-2022-40799HIGH8.8Data Integrity Failure in 'Backup Config' in D-Link DNR-322L <= 2.60B15 allows an authenticated attacker to execute OS l...
CVE-2022-45202HIGH7.8GPAC v2.1-DEV-rev428-gcb8ae46c8-master was discovered to contain a stack overflow via the function dimC_box_read at isom...
CVE-2022-44037HIGH8.8An access control issue in APsystems ENERGY COMMUNICATION UNIT (ECU-C) Power Control Software V4.1NA, V3.11.4, W2.1NA, V...
CVE-2022-41675HIGH8A remote attacker with general user privilege can inject malicious code in the form content of Raiden MAILD Mail Server ...
CVE-2022-3088HIGH7.8UC-8100A-ME-T System Image: Versions v1.0 to v1.6, UC-2100 System Image: Versions v1.0 to v1.12, UC-2100-W System Image:...
CVE-2022-24190HIGH7.5The /device/acceptBind end-point for Ourphoto App version 1.4.1 does not require authentication or authorization. The us...
CVE-2022-24188HIGH7.5The /device/signin end-point for the Ourphoto App version 1.4.1 discloses clear-text password information for functional...
CVE-2022-24187HIGH7.5The user_id and device_id on the Ourphoto App version 1.4.1 /device/* end-points both suffer from insecure direct object...
CVE-2022-45921HIGH7.5FusionAuth before 1.41.3 allows a file outside of the application root to be viewed or retrieved using an HTTP request. ...
CVE-2022-45442HIGH8.8Sinatra is a domain-specific language for creating web applications in Ruby. An issue was discovered in Sinatra 2.0 befo...
CVE-2022-38140HIGH8.8Auth. (contributor+) Arbitrary File Upload in SEO Plugin by Squirrly SEO plugin <= 12.1.10 on WordPress.
CVE-2022-34654HIGH8.8Cross-Site Request Forgery (CSRF) in Virgial Berveling's Manage Notification E-mails plugin <= 1.8.2 on WordPress.
CVE-2022-41957HIGH7.5Muhammara is a node module with c/cpp bindings to modify PDF with JavaScript for node or electron. The package muhammara...
CVE-2022-31877HIGH8.8An issue in the component MSI.TerminalServer.exe of MSI Center v1.0.41.0 allows attackers to escalate privileges via a c...
CVE-2022-3865HIGH8.8The WP User Merger WordPress plugin before 1.5.3 does not properly sanitise and escape a parameter before using it in a ...
CVE-2022-3849HIGH8.8The WP User Merger WordPress plugin before 1.5.3 does not properly sanitise and escape a parameter before using it in a ...
CVE-2022-3848HIGH8.8The WP User Merger WordPress plugin before 1.5.3 does not properly sanitise and escape a parameter before using it in a ...
CVE-2022-3769HIGH8.8The OWM Weather WordPress plugin before 5.6.9 does not properly sanitise and escape a parameter before using it in a SQL...
CVE-2022-3768HIGH8.8The WPSmartContracts WordPress plugin before 1.3.12 does not properly sanitise and escape a parameter before using it in...
CVE-2022-3689HIGH7.2The HTML Forms WordPress plugin before 1.3.25 does not properly properly escape a parameter before using it in a SQL sta...
CVE-2022-3490HIGH7.2The Checkout Field Editor (Checkout Manager) for WooCommerce WordPress plugin before 1.8.0 unserializes user input provi...
CVE-2022-4020HIGH8.2Vulnerability in the HQSwSmiDxe DXE driver on some consumer Acer Notebook devices may allow an attacker with elevated pr...
CVE-2022-38900HIGH7.5decode-uri-component 0.2.0 is vulnerable to Improper Input Validation resulting in DoS.
CVE-2022-45939HIGH7.8GNU Emacs through 28.2 allows attackers to execute commands via shell metacharacters in the name of a source-code file, ...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now