2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2022-44737HIGH8.8Multiple Cross-Site Request Forgery vulnerabilities in All-In-One Security (AIOS) – Security and Firewall (WordPress plu...
CVE-2022-33012HIGH8.8Microweber v1.2.15 was discovered to allow attackers to perform an account takeover via a host header injection attack.
CVE-2022-42098HIGH8.8KLiK SocialMediaWebsite version v1.0.1 is vulnerable to SQL Injection via the profile.php.
CVE-2022-3910HIGH7.8Use After Free vulnerability in Linux Kernel allows Privilege Escalation. An improper Update of Reference Count in io_ur...
CVE-2022-0222HIGH7.5A CWE-269: Improper Privilege Management vulnerability exists that could cause a denial of service of the Ethernet commu...
CVE-2022-37301HIGH7.5A CWE-191: Integer Underflow (Wrap or Wraparound) vulnerability exists that could cause a denial of service of the contr...
CVE-2022-41131HIGH7.8Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Airfl...
CVE-2022-37931HIGH7.8A vulnerability in NetBatch-Plus software allows unauthorized access to the application.  HPE has provided a workaround...
CVE-2022-35407HIGH7.8An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. A stack buffer overflow leads to arbitrary code...
CVE-2022-43685HIGH8.8CKAN through 2.9.6 account takeovers by unauthenticated users when an existing user id is sent via an HTTP POST request....
CVE-2022-41937HIGH8.1XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. The application...
CVE-2022-41936HIGH7.5XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. The `modificati...
CVE-2022-30529HIGH7.2File upload vulnerability in asith-eranga ISIC tour booking through version published on Feb 13th 2018, allows attackers...
CVE-2022-44786HIGH7.5An issue was discovered in Appalti & Contratti 9.12.2. The target web applications allow Local File Inclusion in any pag...
CVE-2022-44784HIGH8.8An issue was discovered in Appalti & Contratti 9.12.2. The target web applications LFS and DL229 expose a set of service...
CVE-2022-3388HIGH7.8An input validation vulnerability exists in the Monitor Pro interface of MicroSCADA Pro and MicroSCADA X SYS600. An auth...
CVE-2022-44830HIGH7.8Sourcecodester Event Registration App v1.0 was discovered to contain multiple CSV injection vulnerabilities via the Firs...
CVE-2022-45422HIGH7.8When LG SmartShare is installed, local privilege escalation is possible through DLL Hijacking attack. The LG ID is LVE-H...
CVE-2022-45470HIGH7.5missing input validation in Apache Hama may cause information disclosure through path traversal and XSS. Since Apache Ha...
CVE-2022-44163HIGH7.5Tenda AC21 V16.03.08.15 is vulnerable to Buffer Overflow via function formSetMacFilterCfg.
CVE-2022-44158HIGH7.5Tenda AC21 V16.03.08.15 is vulnerable to Buffer Overflow via function via set_device_name.
CVE-2022-44156HIGH7.5Tenda AC15 V15.03.05.19 is vulnerable to Buffer Overflow via function formSetIpMacBind.
CVE-2022-40129HIGH7.8A use-after-free vulnerability exists in the JavaScript engine of Foxit Software's PDF Reader, version 12.0.1.12430. A s...
CVE-2022-38148HIGH8.8Silverstripe silverstripe/framework through 4.11 allows SQL Injection.
CVE-2022-38097HIGH7.8A use-after-free vulnerability exists in the JavaScript engine of Foxit Software's PDF Reader, version 12.0.1.12430. By ...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now