2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-47172HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in HasThemes ShopLentor plugin <= 2.6.2 versions.
CVE-2022-4023MEDIUM5.3The 3DPrint WordPress plugin before 3.5.6.9 does not protect against CSRF attacks in the modified version of Tiny File M...
CVE-2022-4952HIGH7.5A vulnerability has been found in OmniSharp csharp-language-server-protocol up to 0.19.6 and classified as problematic. ...
CVE-2022-42045MEDIUM6.7Certain Zemana products are vulnerable to Arbitrary code injection. This affects Watchdog Anti-Malware 4.1.422 and Zeman...
CVE-2022-24834HIGH8.8Redis is an in-memory database that persists on disk. A specially crafted Lua script executing in Redis can trigger a he...
CVE-2022-46651MEDIUM6.5Apache Airflow, versions before 2.6.3, is affected by a vulnerability that allows an unauthorized actor to gain access t...
CVE-2022-45855HIGH8.8SpringEL injection in the metrics source in Apache Ambari version 2.7.0 to 2.7.6 allows a malicious authenticated user t...
CVE-2022-42009HIGH8.8SpringEL injection in the server agent in Apache Ambari version 2.7.0 to 2.7.6 allows a malicious authenticated user to ...
CVE-2022-48451MEDIUM4.1In bluetooth service, there is a possible out of bounds write due to race condition. This could lead to local denial of...
CVE-2022-48450MEDIUM4.4In bluetooth service, there is a possible missing params check. This could lead to local denial of service with System ...
CVE-2022-48521MEDIUM5.3An issue was discovered in OpenDKIM through 2.10.3, and 2.11.x through 2.11.0-Beta2. It fails to keep track of ordinal n...
CVE-2022-23447HIGH7.5An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-22] in FortiExtende...
CVE-2022-31810HIGH7.5A vulnerability has been identified in SiPass integrated (All versions < V2.90.3.8). Affected server applications improp...
CVE-2022-29562MEDIUM5.3A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.16.0), RUGGEDCOM ROX MX5000RE (All versio...
CVE-2022-29561HIGH8.8A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.16.0), RUGGEDCOM ROX MX5000RE (All versio...
CVE-2022-22302LOW3.3A clear text storage of sensitive information (CWE-312) vulnerability in both FortiGate version 6.4.0 through 6.4.1, 6.2...
CVE-2022-45823HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in GalleryPlugins Video Contest WordPress plugin <= 3.2 versions.
CVE-2022-4361MEDIUM6.1Keycloak, an open-source identity and access management solution, has a cross-site scripting (XSS) vulnerability in the ...
CVE-2022-48520HIGH7.5Unauthorized access vulnerability in the SystemUI module. Successful exploitation of this vulnerability may affect confi...
CVE-2022-48519HIGH7.5Unauthorized access vulnerability in the SystemUI module. Successful exploitation of this vulnerability may affect confi...
CVE-2022-48518MEDIUM5.5Vulnerability of signature verification in the iaware system being initialized later than the time when the system broad...
CVE-2022-48517HIGH7.5Unauthorized service access vulnerability in the DSoftBus module. Successful exploitation of this vulnerability will aff...
CVE-2022-48516HIGH7.5Vulnerability that a unique value can be obtained by a third-party app in the DSoftBus module. Successful exploitation o...
CVE-2022-48515HIGH7.5Vulnerability of inappropriate permission control in Nearby. Successful exploitation of this vulnerability may affect se...
CVE-2022-48514HIGH7.5The Sepolicy module has inappropriate permission control on the use of Netlink.Successful exploitation of this vulnerabi...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now