2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2022-23901CRITICAL9.8A stack overflow re2c 2.2 exists due to infinite recursion issues in src/dfa/dead_rules.cc.
CVE-2022-1084CRITICAL9.8A vulnerability classified as critical was found in SourceCodester One Church Management System 1.0. Affected by this vu...
CVE-2022-1083CRITICAL9.8A vulnerability classified as critical has been found in Microfinance Management System. The manipulation of arguments l...
CVE-2022-1082CRITICAL9.8A vulnerability was found in SourceCodester Microfinance Management System 1.0. It has been rated as critical. This issu...
CVE-2022-1080CRITICAL9.8A vulnerability was found in SourceCodester One Church Management System 1.0. It has been declared as critical. This vul...
CVE-2022-1078CRITICAL9.8A vulnerability was found in SourceCodester College Website Management System 1.0. It has been classified as critical. A...
CVE-2022-1073CRITICAL9.8A vulnerability was found in Automatic Question Paper Generator 1.0. It has been declared as critical. An attack leads t...
CVE-2022-25420CRITICAL9.8NTT Resonant Incorporated goo blog App Web Application 1.0 is vulnerable to CLRF injection. This vulnerability allows at...
CVE-2022-25521CRITICAL9.8NUUO v03.11.00 was discovered to contain access control issue.
CVE-2022-26278CRITICAL9.8Tenda AC9 v15.03.2.21_cn was discovered to contain a stack overflow via the time parameter in the PowerSaveSet function.
CVE-2022-0735CRITICAL9.8An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.10 before 14.6.5, all versions star...
CVE-2022-0249CRITICAL9.1A vulnerability was discovered in GitLab starting with version 12. GitLab was vulnerable to a blind SSRF attack since re...
CVE-2022-0846CRITICAL9.8The SpeakOut! Email Petitions WordPress plugin before 2.14.15.1 does not sanitise and escape the id parameter before usi...
CVE-2022-0787CRITICAL9.8The Limit Login Attempts (Spam Protection) WordPress plugin before 5.1 does not sanitise and escape some parameters befo...
CVE-2022-0784CRITICAL9.8The Title Experiments Free WordPress plugin before 9.0.1 does not sanitise and escape the id parameter before using it i...
CVE-2022-0679CRITICAL9.8The Narnoo Distributor WordPress plugin through 2.5.1 fails to validate and sanitize the lib_path parameter before it is...
CVE-2022-0479CRITICAL9.8The Popup Builder WordPress plugin before 4.1.1 does not sanitise and escape the sgpb-subscription-popup-id parameter be...
CVE-2022-23884CRITICAL9.8Mojang Bedrock Dedicated Server 1.18.2 is affected by an integer overflow leading to a bound check bypass caused by Purc...
CVE-2022-0342CRITICAL9.8An authentication bypass vulnerability in the CGI program of Zyxel USG/ZyWALL series firmware versions 4.20 through 4.70...
CVE-2022-23882CRITICAL9.8TuziCMS 2.0.6 is affected by SQL injection in \App\Manage\Controller\BannerController.class.php.
CVE-2022-25757CRITICAL9.8In Apache APISIX before 2.13.0, when decoding JSON with duplicate keys, lua-cjson will choose the last occurred value as...
CVE-2022-26273CRITICAL9.8EyouCMS v1.5.4 was discovered to lack parameter filtering in \user\controller\shop.php, leading to payment logic vulnera...
CVE-2022-24303CRITICAL9.1Pillow before 9.0.1 allows attackers to delete files because spaces in temporary pathnames are mishandled.
CVE-2022-26268CRITICAL9.8Xiaohuanxiong v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /app/controller/Books...
CVE-2022-26258CRITICAL9.8D-Link DIR-820L 1.05B03 was discovered to contain remote command execution (RCE) vulnerability via HTTP POST to get set ...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now