2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2022-24307CRITICAL9.8Mastodon before 3.3.2 and 3.4.x before 3.4.6 has incorrect access control because it does not compact incoming signed JS...
CVE-2022-23357CRITICAL9.1mozilo2.0 was discovered to be vulnerable to directory traversal attacks via the parameter curent_dir.
CVE-2022-21817CRITICAL9.3NVIDIA Omniverse Launcher contains a Cross-Origin Resource Sharing (CORS) vulnerability which can allow an unprivileged ...
CVE-2022-21724CRITICAL9.8pgjdbc is the offical PostgreSQL JDBC Driver. A security hole was found in the jdbc driver for postgresql database while...
CVE-2022-24300CRITICAL9.8Minetest before 5.4.0 allows attackers to add or modify arbitrary meta fields of the same item stack as saved user input...
CVE-2022-24223CRITICAL9.8AtomCMS v2.0 was discovered to contain a SQL injection vulnerability via /admin/login.php.
CVE-2022-24222CRITICAL9.8eliteCMS v1.0 was discovered to contain a SQL injection vulnerability via /admin/edit_user.php.
CVE-2022-24221CRITICAL9.8eliteCMS v1.0 was discovered to contain a SQL injection vulnerability via /admin/functions/functions.php.
CVE-2022-24220CRITICAL9.8eliteCMS v1.0 was discovered to contain a SQL injection vulnerability via /admin/edit_post.php.
CVE-2022-24219CRITICAL9.8eliteCMS v1.0 was discovered to contain a SQL injection vulnerability via /admin/edit_page.php.
CVE-2022-24218CRITICAL9.1An issue in /admin/delete_image.php of eliteCMS v1.0 allows attackers to delete arbitrary files.
CVE-2022-0401CRITICAL9.8Path Traversal in NPM w-zip prior to 1.0.12.
CVE-2022-0320CRITICAL9.8The Essential Addons for Elementor WordPress plugin before 5.0.5 does not validate and sanitise some template data befor...
CVE-2022-24263CRITICAL9.8Hospital Management System v4.0 was discovered to contain a SQL injection vulnerability in /Hospital-Management-System-m...
CVE-2022-0339CRITICAL9.8Server-Side Request Forgery (SSRF) in Pypi calibreweb prior to 0.6.16.
CVE-2022-24123CRITICAL9MarkText through 0.16.3 does not sanitize the input of a mermaid block before rendering. This could lead to Remote Code ...
CVE-2022-22994CRITICAL9.8A remote code execution vulnerability was discovered on Western Digital My Cloud devices where an attacker could trick a...
CVE-2022-22992CRITICAL9.8A command injection remote code execution vulnerability was discovered on Western Digital My Cloud Devices that could al...
CVE-2022-21217CRITICAL9.8An out-of-bounds write vulnerability exists in the device TestEmail functionality of reolink RLC-410W v3.0.0.136_2012110...
CVE-2022-22294CRITICAL9.8A SQL injection vulnerability exists in ZFAKA<=1.43 which an attacker can use to complete SQL injection in the foregroun...
CVE-2022-23097CRITICAL9.1An issue was discovered in the DNS proxy in Connman through 1.40. forward_dns_reply mishandles a strnlen call, leading t...
CVE-2022-23096CRITICAL9.1An issue was discovered in the DNS proxy in Connman through 1.40. The TCP server reply implementation lacks a check for ...
CVE-2022-21723CRITICAL9.1PJSIP is a free and open source multimedia communication library written in C language implementing standard based proto...
CVE-2022-21722CRITICAL9.1PJSIP is a free and open source multimedia communication library written in C language implementing standard based proto...
CVE-2022-21686CRITICAL9.8PrestaShop is an Open Source e-commerce platform. Starting with version 1.7.0.0 and ending with version 1.7.8.3, an atta...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now