2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-4955MEDIUM6.5Inappropriate implementation in DevTools in Google Chrome prior to 108.0.5359.71 allowed an attacker who convinced a use...
CVE-2022-41401MEDIUM6.5OpenRefine <= v3.5.2 contains a Server-Side Request Forgery (SSRF) vulnerability, which permits unauthorized users to ex...
CVE-2022-42986Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2023-39122. Reason: This candidate is a reservation d...
CVE-2022-26838MEDIUM6.5Path traversal vulnerability in Importing Mobile Device Data of Cybozu Remote Service 3.1.2 allows a remote authenticate...
CVE-2022-4046HIGH8.8In CODESYS Control in multiple versions a improper restriction of operations within the bounds of a memory buffer allow ...
CVE-2022-34453HIGH7.1 Dell XtremIO X2 XMS versions prior to 6-4-1.11 contain an improper access control vulnerability. A remote read only use...
CVE-2022-46484HIGH7.5Information disclosure in password protected surveys in Data Illusion Survey Software Solutions NGSurvey v2.4.28 and bel...
CVE-2022-40609CRITICAL9.8IBM SDK, Java Technology Edition 7.1.5.18 and 8.0.8.0 could allow a remote attacker to execute arbitrary code on the sys...
CVE-2022-46485HIGH7.5Data Illusion Survey Software Solutions ngSurvey version 2.4.28 and below is vulnerable to Denial of Service if a survey...
CVE-2022-2416MEDIUM4.3In affected versions of Octopus Deploy it is possible for a low privileged guest user to craft a request that allows enu...
CVE-2022-2346MEDIUM4.3In affected versions of Octopus Deploy it is possible for a low privileged guest user to interact with extension endpoin...
CVE-2022-39987HIGH8.8A Command injection vulnerability in RaspAP 2.8.0 thru 2.9.2 allows an authenticated attacker to execute arbitrary OS co...
CVE-2022-39986CRITICAL9.8A Command injection vulnerability in RaspAP 2.8.0 thru 2.8.7 allows unauthenticated attackers to execute arbitrary comma...
CVE-2022-42183CRITICAL9.1Precisely Spectrum Spatial Analyst 20.01 is vulnerable to Server-Side Request Forgery (SSRF).
CVE-2022-42182MEDIUM5.3Precisely Spectrum Spatial Analyst 20.01 is vulnerable to Directory Traversal.
CVE-2022-4888MEDIUM6.5The Checkout Fields Manager WordPress plugin before 1.0.2, Abandoned Cart Recovery WordPress plugin before 1.2.5, Custom...
CVE-2022-43831HIGH7.8IBM Storage Scale Container Native Storage Access 5.1.2.1 through 5.1.6.1 could allow a local user to obtain escalated p...
CVE-2022-4926MEDIUM6.5Insufficient policy enforcement in Intents in Google Chrome on Android prior to 109.0.5414.119 allowed a remote attacker...
CVE-2022-4925MEDIUM6.5Insufficient validation of untrusted input in QUIC in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to p...
CVE-2022-4924CRITICAL9.6Use after free in WebRTC in Google Chrome prior to 97.0.4692.71 allowed a remote attacker who had compromised the render...
CVE-2022-4923LOW3.1Inappropriate implementation in Omnibox in Google Chrome prior to 99.0.4844.51 allowed an attacker in a privileged netwo...
CVE-2022-4922MEDIUM6.5Inappropriate implementation in Blink in Google Chrome prior to 99.0.4844.51 allowed a remote attacker to perform UI spo...
CVE-2022-4921HIGH8.8Use after free in Accessibility in Google Chrome prior to 99.0.4844.51 allowed a remote attacker who convinced a user to...
CVE-2022-4920CRITICAL9.6Heap buffer overflow in Blink in Google Chrome prior to 101.0.4951.41 allowed a remote attacker who convinced a user to ...
CVE-2022-4919HIGH8.8Use after free in Base Internals in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to perform arbitrary ...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now