2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2022-3321HIGH8.2It was possible to bypass Lock WARP switch feature https://developers.cloudflare.com/cloudflare-one/connections/connect...
CVE-2022-3733HIGH8.8A vulnerability was found in SourceCodester Web-Based Student Clearance System. It has been classified as critical. This...
CVE-2022-3616HIGH7.5Attackers can create long chains of CAs that would lead to OctoRPKI exceeding its max iterations parameter. In consequen...
CVE-2022-3379HIGH7.8 Horner Automation's Cscape version 9.90 SP7 and prior does not properly validate user-supplied data. If a user opens a ...
CVE-2022-3378HIGH7.8 Horner Automation's Cscape version 9.90 SP 7 and prior does not properly validate user-supplied data. If a user opens a...
CVE-2022-41773HIGH8.8The affected product DIAEnergie (versions prior to v1.9.01.002) is vulnerable to a SQL injection that exists in CheckDIA...
CVE-2022-41627HIGH7.6 The physical IoT device of the AliveCor's KardiaMobile, a smartphone-based personal electrocardiogram (EKG) has no encr...
CVE-2022-41133HIGH8.8The affected product DIAEnergie (versions prior to v1.9.01.002) is vulnerable to a SQL injection that exists in GetDIAE_...
CVE-2022-40967HIGH8.8The affected product DIAEnergie (versions prior to v1.9.01.002) is vulnerable to a SQL injection that exists in CheckIoT...
CVE-2022-43340HIGH8.8A Cross-Site Request Forgery (CSRF) in dzzoffice 2.02.1_SC_UTF8 allows attackers to arbitrarily create user accounts and...
CVE-2022-39978HIGH7.2Online Pet Shop We App v1.0 was discovered to contain an arbitrary file upload vulnerability via the Editing function in...
CVE-2022-39977HIGH7.2Online Pet Shop We App v1.0 was discovered to contain an arbitrary file upload vulnerability via the Editing function in...
CVE-2022-0074HIGH8.8Untrusted Search Path vulnerability in LiteSpeed Technologies OpenLiteSpeed Web Server and LiteSpeed Web Server Containe...
CVE-2022-0073HIGH8.8Improper Input Validation vulnerability in LiteSpeed Technologies OpenLiteSpeed Web Server and LiteSpeed Web Server dash...
CVE-2022-43366HIGH7.5IP-COM EW9 V15.11.0.14(9732) allows unauthenticated attackers to access sensitive information via the checkLoginUser, at...
CVE-2022-43365HIGH7.5IP-COM EW9 V15.11.0.14(9732) was discovered to contain a buffer overflow in the formSetDebugCfg function. This vulnerabi...
CVE-2022-43364HIGH7.5An access control issue in the password reset page of IP-COM EW9 V15.11.0.14(9732) allows unauthenticated attackers to a...
CVE-2022-40875HIGH7.5Tenda AX1803 v1.0.0.1 was discovered to contain a heap overflow in the function GetParentControlInfo.
CVE-2022-40874HIGH7.5Tenda AX1803 v1.0.0.1 was discovered to contain a heap overflow vulnerability in the GetParentControlInfo function, whic...
CVE-2022-41996HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in ThemeFusion Avada premium theme versions <= 7.8.1 on WordPress leadin...
CVE-2022-3725HIGH7.5Crash in the OPUS protocol dissector in Wireshark 3.6.0 to 3.6.8 allows denial of service via packet injection or crafte...
CVE-2022-38744HIGH7.5 An unauthenticated attacker with network access to a victim's Rockwell Automation FactoryTalk Alarm and Events service...
CVE-2022-3409HIGH7.5A vulnerability in bmcweb of OpenBMC Project allows user to cause denial of service. This vulnerability was identified d...
CVE-2022-2809HIGH7.5A vulnerability in bmcweb of OpenBMC Project allows user to cause denial of service. When fuzzing the multipart_parser c...
CVE-2022-25918HIGH7.5The package shescape from 1.5.10 and before 1.6.1 are vulnerable to Regular Expression Denial of Service (ReDoS) via the...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now