2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2022-44402HIGH7.2Automotive Shop Management System v1.0 is vulnerable to SQL Injection via /asms/classes/Master.php?f=delete_transaction.
CVE-2022-41920HIGH8.8Lancet is a general utility library for the go programming language. Affected versions are subject to a ZipSlip issue wh...
CVE-2022-4052HIGH7.2A vulnerability was found in Student Attendance Management System and classified as critical. This issue affects some un...
CVE-2022-44384HIGH8.8An arbitrary file upload vulnerability in rconfig v3.9.6 allows attackers to execute arbitrary code via a crafted PHP fi...
CVE-2022-43140HIGH7.5kkFileView v4.1.0 was discovered to contain a Server-Side Request Forgery (SSRF) via the component cn.keking.web.control...
CVE-2022-42894HIGH7.5A vulnerability has been identified in syngo Dynamics (All versions < VA40G HF01). An unauthenticated Server-Side Reques...
CVE-2022-42893HIGH7.5A vulnerability has been identified in syngo Dynamics (All versions < VA40G HF01). syngo Dynamics application server hos...
CVE-2022-42891HIGH7.5A vulnerability has been identified in syngo Dynamics (All versions < VA40G HF01). syngo Dynamics application server hos...
CVE-2022-42734HIGH7.5A vulnerability has been identified in syngo Dynamics (All versions < VA40G HF01). syngo Dynamics application server hos...
CVE-2022-42733HIGH7.5A vulnerability has been identified in syngo Dynamics (All versions < VA40G HF01). syngo Dynamics application server hos...
CVE-2022-42732HIGH7.5A vulnerability has been identified in syngo Dynamics (All versions < VA40G HF01). syngo Dynamics application server hos...
CVE-2022-45461HIGH8.8The Java Admin Console in Veritas NetBackup through 10.1 and related Veritas products on Linux and UNIX allows authentic...
CVE-2022-42982HIGH7.5BKG Professional NtripCaster 2.0.39 allows querying information over the UDP protocol without authentication. The NTRIP ...
CVE-2022-42246HIGH8.8Doufox 0.0.4 contains a CSRF vulnerability that can add system administrator account.
CVE-2022-44007HIGH8.8An issue was discovered in BACKCLICK Professional 5.9.63. Due to an unsafe implementation of session tracking, it is pos...
CVE-2022-43264HIGH7.5Arobas Music Guitar Pro for iPad and iPhone before v1.10.2 allows attackers to perform directory traversal and download ...
CVE-2022-24036HIGH8.6Karmasis Informatics Infraskope SIEM+ has an unauthenticated access vulnerability which could allow an unauthenticated a...
CVE-2022-4013HIGH8.8A vulnerability classified as problematic was found in Hospital Management Center. Affected by this vulnerability is an ...
CVE-2022-3920HIGH7.5HashiCorp Consul and Consul Enterprise 1.13.0 up to 1.13.3 do not filter cluster filtering's imported nodes and services...
CVE-2022-41916HIGH7.5Heimdal is an implementation of ASN.1/DER, PKIX, and Kerberos. Versions prior to 7.7.1 are vulnerable to a denial of ser...
CVE-2022-4006HIGH7.5A vulnerability, which was classified as problematic, has been found in WBCE CMS. Affected by this issue is the function...
CVE-2022-29279HIGH8.2Use of a untrusted pointer allows tampering with SMRAM and OS memory in SdHostDriver and SdMmcDevice Use of a untrusted ...
CVE-2022-29278HIGH8.2Incorrect pointer checks within the NvmExpressDxe driver can allow tampering with SMRAM and OS memory Incorrect pointer ...
CVE-2022-29277HIGH8.8Incorrect pointer checks within the the FwBlockServiceSmm driver can allow arbitrary RAM modifications During review of ...
CVE-2022-29276HIGH8.2SMI functions in AhciBusDxe use untrusted inputs leading to corruption of SMRAM. SMI functions in AhciBusDxe use untrust...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now