2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2022-26471HIGH7.8In telephony, there is a possible escalation of privilege due to a parcel format mismatch. This could lead to local esca...
CVE-2022-42074HIGH7.2Online Diagnostic Lab Management System v1.0 is vulnerable to SQL Injection via /diagnostic/editcategory.php?id=.
CVE-2022-42073HIGH7.2Online Diagnostic Lab Management System v1.0 is vulnerable to SQL Injection via /diagnostic/editclient.php?id=.
CVE-2022-41379HIGH7.2An arbitrary file upload vulnerability in the component /leave_system/classes/Users.php?f=save of Online Leave Managemen...
CVE-2022-41378HIGH7.2Online Pet Shop We App v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /pet_shop/ad...
CVE-2022-41377HIGH7.2Online Pet Shop We App v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /pet_shop/ad...
CVE-2022-37893HIGH7.8An authenticated command injection vulnerability exists in the Aruba InstantOS and ArubaOS 10 command line interface. Su...
CVE-2022-42092HIGH7.2Backdrop CMS 1.22.0 has Unrestricted File Upload vulnerability via 'themes' that allows attackers to Remote Code Executi...
CVE-2022-41515HIGH7.2Open Source SACCO Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at...
CVE-2022-41514HIGH7.2Open Source SACCO Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at...
CVE-2022-41513HIGH7.2Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id paramete...
CVE-2022-41512HIGH7.2An arbitrary file upload vulnerability in the component /php_action/editFile.php of Online Diagnostic Lab Management Sys...
CVE-2022-22493HIGH8.8IBM WebSphere Automation for Cloud Pak for Watson AIOps 1.4.2 is vulnerable to cross-site request forgery, caused by imp...
CVE-2022-22480HIGH7.5IBM QRadar SIEM 7.4 and 7.5 data node rebalancing does not function correctly when using encrypted hosts which could res...
CVE-2022-39871HIGH7.5Improper access control vulnerability cloudNotificationManager.java in SmartThings prior to version 1.7.89.0 allows atta...
CVE-2022-39870HIGH7.5Improper access control vulnerability in cloudNotificationManager.java SmartThings prior to version 1.7.89.0 allows atta...
CVE-2022-39869HIGH7.5Improper access control vulnerability in cloudNotificationManager.java SmartThings prior to version 1.7.89.0 allows atta...
CVE-2022-39868HIGH7.5Improper access control vulnerability in GedSamsungAccount.kt SmartThings prior to version 1.7.89.0 allows attackers to ...
CVE-2022-39867HIGH7.5Improper access control vulnerability in cloudNotificationManager.java SmartThings prior to version 1.7.89.0 allows atta...
CVE-2022-39866HIGH7.5Improper access control vulnerability in RegisteredEventMediator.kt SmartThings prior to version 1.7.89.0 allows attacke...
CVE-2022-39865HIGH7.5Improper access control vulnerability in ContentsSharingActivity.java SmartThings prior to version 1.7.89.0 allows attac...
CVE-2022-39864HIGH7.5Improper access control vulnerability in WifiSetupLaunchHelper in SmartThings prior to version 1.7.89.25 allows attacker...
CVE-2022-39858HIGH7.8Path traversal vulnerability in AtBroadcastReceiver in FactoryCamera prior to version 3.5.51 allows attackers to write a...
CVE-2022-39854HIGH7.8Improper protection in IOMMU prior to SMR Oct-2022 Release 1 allows unauthorized access to secure memory.
CVE-2022-39853HIGH7.8A use after free vulnerability in perf-mgr driver prior to SMR Oct-2022 Release 1 allows attacker to cause memory access...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now