2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2022-24755CRITICAL9.8Bareos is open source software for backup, archiving, and recovery of data for operating systems. When Bareos Director >...
CVE-2022-24752CRITICAL9.8SyliusGridBundle is a package of generic data grids for Symfony applications. Prior to versions 1.10.1 and 1.11-rc2, val...
CVE-2022-26320CRITICAL9.1The Rambus SafeZone Basic Crypto Module before 10.4.0, as used in certain Fujifilm (formerly Fuji Xerox) devices before ...
CVE-2022-21187CRITICAL9.8The package libvcs before 0.11.1 are vulnerable to Command Injection via argument injection. When calling the update_rep...
CVE-2022-0658CRITICAL9.8The CommonsBooking WordPress plugin before 2.6.8 does not sanitise and escape the location parameter of the calendar_dat...
CVE-2022-0254CRITICAL9.8The WordPress Zero Spam WordPress plugin before 5.2.11 does not properly sanitise and escape the order and orderby param...
CVE-2022-0169CRITICAL9.8The Photo Gallery by 10Web WordPress plugin before 1.6.0 does not validate and escape the bwg_tag_id_bwg_thumbnails_0 pa...
CVE-2022-23943CRITICAL9.8Out-of-bounds Write vulnerability in mod_sed of Apache HTTP Server allows an attacker to overwrite heap memory with poss...
CVE-2022-22721CRITICAL9.1If LimitXMLRequestBody is set to allow request bodies larger than 350MB (defaults to 1M) on 32 bit systems an integer ov...
CVE-2022-22720CRITICAL9.8Apache HTTP Server 2.4.52 and earlier fails to close inbound connection when errors are encountered discarding the reque...
CVE-2022-24760CRITICAL10Parse Server is an open source http web server backend. In versions prior to 4.10.7 there is a Remote Code Execution (RC...
CVE-2022-24754CRITICAL9.8PJSIP is a free and open source multimedia communication library written in C language. In versions prior to and includi...
CVE-2022-25621CRITICAL9.8UUNIVERGE WA 1020 Ver8.2.11 and prior, UNIVERGE WA 1510 Ver8.2.11 and prior, UNIVERGE WA 1511 Ver8.2.11 and prior, UNIVE...
CVE-2022-23730CRITICAL9.8The public API error causes for the attacker to be able to bypass API access control.
CVE-2022-24433CRITICAL9.8The package simple-git before 3.3.0 are vulnerable to Command Injection via argument injection. When calling the .fetch(...
CVE-2022-0860CRITICAL9.1Improper Authorization in GitHub repository cobbler/cobbler prior to 3.3.2.
CVE-2022-0871CRITICAL9.1Missing Authorization in GitHub repository gogs/gogs prior to 0.12.5.
CVE-2022-23402CRITICAL9.8The following Yokogawa Electric products hard-code the password for CAMS server applications: CENTUM VP versions from R5...
CVE-2022-21194CRITICAL9.8The following Yokogawa Electric products do not change the passwords of the internal Windows accounts from the initial c...
CVE-2022-26520CRITICAL9.8In pgjdbc before 42.3.3, an attacker (who controls the jdbc URL or properties) can call java.util.logging.FileHandler to...
CVE-2022-26143CRITICAL9.8The TP-240 (aka tp240dvr) component in Mitel MiCollab before 9.4 SP1 FP1 and MiVoice Business Express through 8.1 allows...
CVE-2022-26131CRITICAL9.8Power Line Communications PLC4TRUCKS J2497 trailer receivers are susceptible to remote RF induced signals.
CVE-2022-26100CRITICAL9.8SAPCAR - version 7.22, does not contain sufficient input validation on the SAPCAR archive. As a result, the SAPCAR proce...
CVE-2022-25922CRITICAL9.1Power Line Communications PLC4TRUCKS J2497 trailer brake controllers implement diagnostic functions which can be invoked...
CVE-2022-25818CRITICAL9.8Improper boundary check in UWB stack prior to SMR Mar-2022 Release 1 allows arbitrary code execution.

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now