2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2022-39019HIGH7.5 Broken access controls on PDFtron WebviewerUI in M-Files Hubshare before 3.3.11.3 allows unauthenticated attackers to u...
CVE-2022-39018HIGH7.5 Broken access controls on PDFtron data in M-Files Hubshare before 3.3.11.3 allows unauthenticated attackers to access r...
CVE-2022-39016HIGH8.8 Javascript injection in PDFtron in M-Files Hubshare before 3.3.10.9 allows authenticated attackers to perform an accoun...
CVE-2022-42925HIGH8.8There is a vulnerability on Forma LMS version 3.1.0 and earlier that could allow an authenticated attacker (with the rol...
CVE-2022-42923HIGH8.8Forma LMS on its 3.1.0 version and earlier is vulnerable to a SQL injection vulnerability. The exploitation of this vuln...
CVE-2022-41776HIGH7.5 Delta Electronics InfraSuite Device Master versions 00.00.01a and prior allow unauthenticated users to trigger the Writ...
CVE-2022-41688HIGH7.5 Delta Electronics InfraSuite Device Master versions 00.00.01a and prior lack proper authentication for functions that c...
CVE-2022-41681HIGH8.8There is a vulnerability on Forma LMS version 3.1.0 and earlier that could allow an authenticated attacker (with the rol...
CVE-2022-41644HIGH8.8 Delta Electronics InfraSuite Device Master versions 00.00.01a and prior lacks authentication for a function that chan...
CVE-2022-31690HIGH8.1Spring Security, versions 5.7 prior to 5.7.5, and 5.6 prior to 5.6.9, and older unsupported versions could be susceptibl...
CVE-2022-39294HIGH7.5conduit-hyper integrates a conduit application with the hyper server. Prior to version 0.4.2, `conduit-hyper` did not ch...
CVE-2022-2741HIGH7.5The denial-of-service can be triggered by transmitting a carefully crafted CAN frame on the same CAN network as the vuln...
CVE-2022-3380HIGH7.2The Customizer Export/Import WordPress plugin before 0.9.5 unserializes the content of an imported file, which could lea...
CVE-2022-3374HIGH7.2The Ocean Extra WordPress plugin before 2.0.5 unserialises the content of an imported file, which could lead to PHP obje...
CVE-2022-3366HIGH7.2The PublishPress Capabilities WordPress plugin before 2.5.2, PublishPress Capabilities Pro WordPress plugin before 2.5.2...
CVE-2022-3360HIGH8.1The LearnPress WordPress plugin before 4.1.7.2 unserialises user input in a REST API endpoint available to unauthenticat...
CVE-2022-3357HIGH8.8The Smart Slider 3 WordPress plugin before 3.5.1.11 unserialises the content of an imported file, which could lead to PH...
CVE-2022-3334HIGH7.2The Easy WP SMTP WordPress plugin before 1.5.0 unserialises the content of an imported file, which could lead to PHP obj...
CVE-2022-3770HIGH8.8A vulnerability classified as critical was found in Yunjing CMS. This vulnerability affects unknown code of the file /in...
CVE-2022-37620HIGH7.5A Regular Expression Denial of Service (ReDoS) flaw was found in kangax html-minifier 4.0.0 because of the reCustomIgnor...
CVE-2022-40617HIGH7.5strongSwan before 5.9.8 allows remote attackers to cause a denial of service in the revocation plugin by sending a craft...
CVE-2022-44019HIGH8.8In Total.js 4 before 0e5ace7, /api/common/ping can achieve remote command execution via shell metacharacters in the host...
CVE-2022-42915HIGH8.1curl before 7.86.0 has a double free. If curl is told to use an HTTP proxy for a transfer with a non-HTTP(S) URL, it set...
CVE-2022-41974HIGH7.8multipath-tools 0.7.0 through 0.9.x before 0.9.2 allows local users to obtain root access, as exploited alone or in conj...
CVE-2022-41973HIGH7.8multipath-tools 0.7.7 through 0.9.x before 0.9.2 allows local users to obtain root access, as exploited in conjunction w...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now