2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2022-0362CRITICAL9.8SQL Injection in Packagist showdoc/showdoc prior to 2.10.3.
CVE-2022-23959CRITICAL9.1In Varnish Cache before 6.6.2 and 7.x before 7.0.2, Varnish Cache 6.0 LTS before 6.0.10, and and Varnish Enterprise (Cac...
CVE-2022-0332CRITICAL9.8A flaw was found in Moodle in versions 3.11 to 3.11.4. An SQL injection risk was identified in the h5p activity web serv...
CVE-2022-23944CRITICAL9.1User can access /plugin api without authentication. This issue affected Apache ShenYu 2.4.0 and 2.4.1.
CVE-2022-23126CRITICAL9.8TeslaMate before 1.25.1 (when using the default Docker configuration) allows attackers to open doors of Tesla vehicles, ...
CVE-2022-23855CRITICAL9.8An issue was discovered in Saviynt Enterprise Identity Cloud (EIC) 5.5 SP2.x. An authentication bypass in ECM/maintenanc...
CVE-2022-23852CRITICAL9.8Expat (aka libexpat) before 2.4.4 has a signed integer overflow in XML_GetBuffer, for configurations with a nonzero XML_...
CVE-2022-23366CRITICAL9.8HMS v1.0 was discovered to contain a SQL injection vulnerability via patientlogin.php.
CVE-2022-23365CRITICAL9.8HMS v1.0 was discovered to contain a SQL injection vulnerability via doctorlogin.php.
CVE-2022-23364CRITICAL9.8HMS v1.0 was discovered to contain a SQL injection vulnerability via adminlogin.php.
CVE-2022-23363CRITICAL9.8Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via index.php.
CVE-2022-22553CRITICAL9.8Dell EMC AppSync versions 3.9 to 4.3 contain an Improper Restriction of Excessive Authentication Attempts Vulnerability ...
CVE-2022-23128CRITICAL9.8Incomplete List of Disallowed Inputs vulnerability in Mitsubishi Electric MC Works64 versions 4.00A (10.95.201.23) to 4....
CVE-2022-0318CRITICAL9.8Heap-based Buffer Overflow in vim/vim prior to 8.2.
CVE-2022-23315CRITICAL9.8MCMS v5.2.4 was discovered to contain an arbitrary file upload vulnerability via the component /ms/template/writeFileCon...
CVE-2022-23314CRITICAL9.8MCMS v5.2.4 was discovered to contain a SQL injection vulnerability via /ms/mdiy/model/importJson.do.
CVE-2022-22930CRITICAL9.8A remote code execution (RCE) vulnerability in the Template Management function of MCMS v5.2.4 allows attackers to execu...
CVE-2022-22929CRITICAL9.8MCMS v5.2.4 was discovered to have an arbitrary file upload vulnerability in the New Template module, which allows attac...
CVE-2022-22928CRITICAL9.8MCMS v5.2.4 was discovered to have a hardcoded shiro-key, allowing attackers to exploit the key and execute arbitrary co...
CVE-2022-21679CRITICAL9.8Istio is an open platform to connect, manage, and secure microservices. In Istio 1.12.0 and 1.12.1 The authorization pol...
CVE-2022-22769CRITICAL9The Web server component of TIBCO Software Inc.'s TIBCO EBX, TIBCO EBX, TIBCO EBX, TIBCO EBX Add-ons, TIBCO EBX Add-ons,...
CVE-2022-23221CRITICAL9.8H2 Console before 2.1.210 allows remote attackers to execute arbitrary code via a jdbc:h2:mem JDBC URL containing the IG...
CVE-2022-21391CRITICAL9.9Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications Applications ...
CVE-2022-21390CRITICAL10Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications Applications ...
CVE-2022-21389CRITICAL10Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications Applications ...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now