2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2022-42916HIGH7.5In curl before 7.86.0, the HSTS check could be bypassed to trick it into staying with HTTP. Using its HSTS support, curl...
CVE-2022-43285HIGH7.5Nginx NJS v0.7.4 was discovered to contain a segmentation violation in njs_promise_reaction_job. NOTE: the vendor disput...
CVE-2022-43284HIGH7.5Nginx NJS v0.7.2 to v0.7.4 was discovered to contain a segmentation violation via njs_scope_valid_value at njs_scope.h. ...
CVE-2022-43282HIGH7.1wasm-interp v1.0.29 was discovered to contain an out-of-bounds read via the component OnReturnCallIndirectExpr->GetRetur...
CVE-2022-43281HIGH7.8wasm-interp v1.0.29 was discovered to contain a heap overflow via the component std::vector<wabt::Type, std::allocator<w...
CVE-2022-43280HIGH7.1wasm-interp v1.0.29 was discovered to contain an out-of-bounds read via the component OnReturnCallExpr->GetReturnCallDro...
CVE-2022-3708HIGH8.1The Web Stories plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including 1.24....
CVE-2022-3401HIGH8.8The Bricks theme for WordPress is vulnerable to remote code execution due to the theme allowing site editors to include ...
CVE-2022-43233HIGH7.2Canteen Management System v1.0 was discovered to contain a SQL injection vulnerability via the userid parameter at /php_...
CVE-2022-43232HIGH7.2Canteen Management System v1.0 was discovered to contain a SQL injection vulnerability via the userid parameter at /php_...
CVE-2022-43231HIGH7.2Canteen Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via /youthappam/manage_w...
CVE-2022-43230HIGH7.2Simple Cold Storage Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter ...
CVE-2022-43229HIGH7.2Simple Cold Storage Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter ...
CVE-2022-43228HIGH7.2Barangay Management System v1.0 was discovered to contain a SQL injection vulnerability via the hidden_id parameter at /...
CVE-2022-41636HIGH7.5Communication traffic involving "Ethernet Q Commands" service of Haas Controller version 100.20.000.1110 is transmitted ...
CVE-2022-2475HIGH8.8Haas Controller version 100.20.000.1110 has insufficient granularity of access control when using the "Ethernet Q Comman...
CVE-2022-2474HIGH8Authentication is currently unsupported in Haas Controller version 100.20.000.1110 when using the “Ethernet Q Commands” ...
CVE-2022-2864HIGH8.8The demon image annotation plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inclu...
CVE-2022-3697HIGH7.5A flaw was found in Ansible in the amazon.aws collection when using the tower_callback parameter from the amazon.aws.ec2...
CVE-2022-37426HIGH7.5Unrestricted Upload of File with Dangerous Type vulnerability in OpenNebula OpenNebula core on Linux allows File Content...
CVE-2022-43276HIGH7.2Canteen Management System v1.0 was discovered to contain a SQL injection vulnerability via the productId parameter at /p...
CVE-2022-43275HIGH7.2Canteen Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via /youthappam/php_acti...
CVE-2022-3512HIGH8.8Using warp-cli command "add-trusted-ssid", a user was able to disconnect WARP client and bypass the "Lock WARP switch" f...
CVE-2022-3337HIGH8.5It was possible for a user to delete a VPN profile from WARP mobile client on iOS platform despite the Lock WARP switch...
CVE-2022-3322HIGH7.5Lock Warp switch is a feature of Zero Trust platform which, when enabled, prevents users of enrolled devices from disab...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now