2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2022-32149HIGH7.5An attacker may cause a denial of service by crafting an Accept-Language header which ParseAcceptLanguage will take sign...
CVE-2022-2880HIGH7.5Requests forwarded by ReverseProxy include the raw query parameters from the inbound request, including unparsable param...
CVE-2022-2879HIGH7.5Reader.Read does not set a limit on the maximum size of file headers. A maliciously crafted archive could cause Read to ...
CVE-2022-28762HIGH7.8Zoom Client for Meetings for macOS (Standard and for IT Admin) starting with 5.10.6 and prior to 5.12.0 contains a debug...
CVE-2022-28759HIGH8.6Zoom On-Premise Meeting Connector MMR before version 4.8.20220815.130 contains an improper access control vulnerability....
CVE-2022-3496HIGH8.8A vulnerability was found in SourceCodester Human Resource Management System 1.0 and classified as critical. This issue ...
CVE-2022-3495HIGH7.2A vulnerability has been found in SourceCodester Simple Online Public Access Catalog 1.0 and classified as critical. Thi...
CVE-2022-2780HIGH8.1In affected versions of Octopus Server it is possible to use the Git Connectivity test function on the VCS project to in...
CVE-2022-41536HIGH7.2Open Source SACCO Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at...
CVE-2022-41535HIGH7.2Open Source SACCO Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at...
CVE-2022-41539HIGH8.8Wedding Planner v1.0 was discovered to contain an arbitrary file upload vulnerability in the component /admin/users_add....
CVE-2022-41538HIGH8.8Wedding Planner v1.0 was discovered to contain an arbitrary file upload vulnerability in the component /Wedding-Manageme...
CVE-2022-36803HIGH8.8The MasterUserEdit API in Atlassian Jira Align Server before version 10.109.2 allows An authenticated attacker with the ...
CVE-2022-42720HIGH7.8Various refcounting bugs in the multi-BSS handling in the mac80211 stack in the Linux kernel 5.1 through 5.19.x before 5...
CVE-2022-41674HIGH8.1An issue was discovered in the Linux kernel before 5.19.16. Attackers able to inject WLAN frames could cause a buffer ov...
CVE-2022-42719HIGH8.8A use-after-free in the mac80211 stack when parsing a multi-BSSID element in the Linux kernel 5.2 through 5.19.x before ...
CVE-2022-39278HIGH7.5Istio is an open platform-independent service mesh that provides traffic management, policy enforcement, and telemetry c...
CVE-2022-39201HIGH7.5Grafana is an open source observability and data visualization platform. Starting with version 5.0.0-beta1 and prior to ...
CVE-2022-35135HIGH8.8Boodskap IoT Platform v4.4.9-02 allows attackers to escalate privileges via a crafted request sent to /api/user/upsert/<...
CVE-2022-34022HIGH7.2SQL injection vulnerability in ResIOT IOT Platform + LoRaWAN Network Server through 4.1.1000114 via a crafted POST reque...
CVE-2022-31130HIGH7.5Grafana is an open source observability and data visualization platform. Versions of Grafana for endpoints prior to 9.1....
CVE-2022-39300HIGH8.1node SAML is a SAML 2.0 library based on the SAML implementation of passport-saml. A remote attacker may be able to bypa...
CVE-2022-35944HIGH7.2October is a self-hosted Content Management System (CMS) platform based on the Laravel PHP Framework. This vulnerability...
CVE-2022-31123HIGH7.8Grafana is an open source observability and data visualization platform. Versions prior to 9.1.8 and 8.5.14 are vulnerab...
CVE-2022-41534HIGH7.2Online Diagnostic Lab Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via the co...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now