2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2022-42751HIGH8.8CandidATS version 3.0.0 allows an external attacker to elevate privileges in the application. This is possible because t...
CVE-2022-42750HIGH8.8CandidATS version 3.0.0 allows an external attacker to steal the cookie of arbitrary users. This is possible because the...
CVE-2022-3776HIGH8.8The Restaurant Menu – Food Ordering System – Table Reservation plugin for WordPress is vulnerable to Cross-Site Request ...
CVE-2022-44624HIGH7.5In JetBrains TeamCity version before 2022.10, Password parameters could be exposed in the build log if they contained sp...
CVE-2022-44623HIGH7.5In JetBrains TeamCity version before 2022.10, Project Viewer could see scrambled secure values in the MetaRunner setting...
CVE-2022-39234HIGH8.8GLPI stands for Gestionnaire Libre de Parc Informatique. GLPI is a Free Asset and IT Management Software package that pr...
CVE-2022-32287HIGH7.5A relative path traversal vulnerability in a FileUtil class used by the PEAR management component of Apache UIMA allows ...
CVE-2022-44638HIGH8.8In libpixman in Pixman before 0.42.2, there is an out-of-bounds write (aka heap-based buffer overflow) in rasterize_edge...
CVE-2022-3181HIGH7.5An Improper Input Validation vulnerability exists in Trihedral VTScada version 12.0.38 and prior. A specifically malform...
CVE-2022-43068HIGH7.2Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id paramete...
CVE-2022-43066HIGH7.2Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id paramete...
CVE-2022-43227HIGH7.2Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id paramete...
CVE-2022-43226HIGH8.8Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id paramete...
CVE-2022-39356HIGH8.8Discourse is a platform for community discussion. Users who receive an invitation link that is not scoped to a single em...
CVE-2022-41716HIGH7.5Due to unsanitized NUL values, attackers may be able to maliciously set environment variables on Windows. In syscall.Sta...
CVE-2022-41551HIGH7.2Garage Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /garage/ed...
CVE-2022-43995HIGH7.1Sudo 1.8.0 through 1.9.12, with the crypt() password backend, contains a plugins/sudoers/auth/passwd.c array-out-of-boun...
CVE-2022-35842HIGH7.5An exposure of sensitive information to an unauthorized actor vulnerabiltiy [CWE-200] in FortiOS SSL-VPN versions 7.2.0,...
CVE-2022-33870HIGH7.8An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in the command line interpre...
CVE-2022-30307HIGH8.1A key management error vulnerability [CWE-320] affecting the RSA SSH host key in FortiOS 7.2.0 and below, 7.0.6 and belo...
CVE-2022-26122HIGH8.6An insufficient verification of data authenticity vulnerability [CWE-345] in FortiClient, FortiMail and FortiOS AV engin...
CVE-2022-26119HIGH7.8A improper authentication vulnerability in Fortinet FortiSIEM before 6.5.0 allows a local attacker with CLI access to pe...
CVE-2022-3723HIGH8.8Type confusion in V8 in Google Chrome prior to 107.0.5304.87 allowed a remote attacker to potentially exploit heap corru...
CVE-2022-3659HIGH8.8Use after free in Accessibility in Google Chrome on Chrome OS prior to 107.0.5304.62 allowed a remote attacker who convi...
CVE-2022-3658HIGH8.8Use after free in Feedback service on Chrome OS in Google Chrome on Chrome OS prior to 107.0.5304.62 allowed an attacker...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now