2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2022-1165CRITICAL9.1The Blackhole for Bad Bots WordPress plugin before 3.3.2 uses headers such as CF-CONNECTING-IP, CLIENT-IP etc to determi...
CVE-2022-0939CRITICAL9.9Server-Side Request Forgery (SSRF) in GitHub repository janeczku/calibre-web prior to 0.6.18.
CVE-2022-26530CRITICAL9.1swaylock before 1.6 allows attackers to trigger a crash and achieve unlocked access to a Wayland compositor.
CVE-2022-28381CRITICAL9.8Mediaserver.exe in ALLMediaServer 1.6 has a stack-based buffer overflow that allows remote attackers to execute arbitrar...
CVE-2022-28368CRITICAL9.8Dompdf 1.2.1 allows remote code execution via a .php file in the src:url field of an @font-face Cascading Style Sheets (...
CVE-2022-27534CRITICAL9.8Kaspersky Anti-Virus products for home and Kaspersky Endpoint Security with antivirus databases released before 12 March...
CVE-2022-27177CRITICAL9.8A Python format string issue leading to information disclosure and potentially remote code execution in ConsoleMe for al...
CVE-2022-25158CRITICAL9.1Cleartext Storage of Sensitive Information vulnerability in Mitsubishi Electric MELSEC iQ-F series FX5U(C) CPU all versi...
CVE-2022-25157CRITICAL9.1Use of Password Hash Instead of Password for Authentication vulnerability in Mitsubishi Electric MELSEC iQ-F series FX5U...
CVE-2022-22965CRITICAL9.8A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b...
CVE-2022-22963CRITICAL9.8In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is po...
CVE-2022-22570CRITICAL10A buffer overflow vulnerability found in the UniFi Door Access Reader Lite’s (UA Lite) firmware (Version 3.8.28.24 and e...
CVE-2022-26562CRITICAL9.8An issue in provider/libserver/ECKrbAuth.cpp of Kopano Core <= v11.0.2.51 contains an issue which allows attackers to au...
CVE-2022-24066CRITICAL9.8The package simple-git before 3.5.0 are vulnerable to Command Injection due to an incomplete fix of [CVE-2022-24433](htt...
CVE-2022-24440CRITICAL9.8The package cocoapods-downloader before 1.6.0, from 1.6.2 and before 1.6.3 are vulnerable to Command Injection via git a...
CVE-2022-21223CRITICAL9.8The package cocoapods-downloader before 1.6.2 are vulnerable to Command Injection via hg argument injection. When callin...
CVE-2022-21235CRITICAL9.8The package github.com/masterminds/vcs before 1.13.3 are vulnerable to Command Injection via argument injection. When hg...
CVE-2022-24803CRITICAL9.8Asciidoctor-include-ext is Asciidoctor’s standard include processor reimplemented as an extension. Versions prior to 0.4...
CVE-2022-24802CRITICAL9.8deepmerge-ts is a typescript library providing functionality to deep merging of javascript objects. deepmerge-ts is vuln...
CVE-2022-24797CRITICAL9.1Pomerium is an identity-aware access proxy. In distributed service mode, Pomerium's Authenticate service exposes pprof d...
CVE-2022-24796CRITICAL9.8RaspberryMatic is a free and open-source operating system for running a cloud-free smart-home using the homematicIP / Ho...
CVE-2022-24791CRITICAL9.8Wasmtime is a standalone JIT-style runtime for WebAssembly, using Cranelift. There is a use after free vulnerability in ...
CVE-2022-26546CRITICAL9.1Hospital Management System v1.0 was discovered to lack an authorization component, allowing attackers to access sensitiv...
CVE-2022-24136CRITICAL9.8Hospital Management System v1.0 is affected by an unrestricted upload of dangerous file type vulerability in treatmentre...
CVE-2022-26646CRITICAL9.8Online Banking System Protect v1.0 was discovered to contain a local file inclusion (LFI) vulnerability via the pages pa...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now