2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-47191HIGH8.8Generex UPS CS141 below 2.06 version, could allow a remote attacker to upload a firmware file containing a file with mod...
CVE-2022-47190CRITICAL9.8Generex UPS CS141 below 2.06 version, could allow a remote attacker to upload a firmware file containing a webshell that...
CVE-2022-47189CRITICAL9.1Generex UPS CS141 below 2.06 version, allows an attacker toupload a firmware file containing an incorrect configuration,...
CVE-2022-47188HIGH7.5There is an arbitrary file reading vulnerability in Generex UPS CS141 below 2.06 version. An attacker, making use of the...
CVE-2022-46021HIGH7.5X-Man 1.0 has a SQL injection vulnerability, which can cause data leakage.
CVE-2022-4899HIGH7.5A vulnerability was found in zstd v1.4.10, where an attacker can supply empty string as an argument to the command line ...
CVE-2022-3192MEDIUM5.3Improper Input Validation vulnerability in ABB AC500 V2 PM5xx allows Client-Server Protocol Manipulation.This issue affe...
CVE-2022-4744HIGH7.8A double-free flaw was found in the Linux kernel’s TUN/TAP device driver functionality in how a user registers the devic...
CVE-2022-47542HIGH8.8Red Gate SQL Monitor 11.0.14 through 12.1.46 has Incorrect Access Control, exploitable remotely for Escalation of Privil...
CVE-2022-23522HIGH8.8MindsDB is an open source machine learning platform. An unsafe extraction is being performed using `shutil.unpack_archiv...
CVE-2022-43473MEDIUM5.4A blind XML External Entity (XXE) vulnerability exists in the Add UCS Device functionality of ManageEngine OpManager 12....
CVE-2022-30351HIGH7.5PDFZorro PDFZorro Online r20220428 using TCPDF 6.2.5, despite having workflows claiming to correctly remove redacted inf...
CVE-2022-30350HIGH7.5Avanquest Software RAD PDF (PDFEscape Online) 3.19.2.2 is vulnerable to Information Leak / Disclosure. The PDFEscape Onl...
CVE-2022-3787HIGH7.8A vulnerability was found in the device-mapper-multipath. The device-mapper-multipath allows local users to obtain root ...
CVE-2022-1274MEDIUM5.4A flaw was found in Keycloak in the execute-actions-email endpoint. This issue allows arbitrary HTML to be injected into...
CVE-2022-47602MEDIUM5.4Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in JoomUnited WP Table Manager plugin <= 3.5.2 vers...
CVE-2022-44370HIGH7.8NASM v2.16 was discovered to contain a heap buffer overflow in the component quote_for_pmake() asm/nasm.c:856
CVE-2022-44369MEDIUM5.5NASM 2.16 (development) is vulnerable to 476: Null Pointer Dereference via output/outaout.c.
CVE-2022-44368MEDIUM5.5NASM v2.16 was discovered to contain a null pointer deference in the NASM component
CVE-2022-47613MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in QuantumCloud AI ChatBot plugin <= 4.3.0 versions.
CVE-2022-47610MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Mr Digital Simple Image Popup plugin <= 1.3.6 versions...
CVE-2022-47607MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Usersnap plugin <= 4.16 versions.
CVE-2022-47603MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in wpdevart Gallery – Image and Video Gallery with Thumbnails...
CVE-2022-45355HIGH7.2Auth. (admin+) SQL Injection (SQLi) vulnerability in ThimPress WP Pipes plugin <= 1.33 versions.
CVE-2022-43650HIGH7.1This vulnerability allows remote attackers to disclose sensitive information on affected installations of RARLAB WinRAR ...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now