2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2022-41040HIGH8.8Microsoft Exchange Server Elevation of Privilege Vulnerability
CVE-2022-42004HIGH7.5In FasterXML jackson-databind before 2.13.4, resource exhaustion can occur because of a lack of a check in BeanDeseriali...
CVE-2022-42003HIGH7.5In FasterXML jackson-databind before versions 2.13.4.1 and 2.12.17.1, resource exhaustion can occur because of a lack of...
CVE-2022-39268HIGH8.1### Impact In a CSRF attack, an innocent end user is tricked by an attacker into submitting a web request that they did ...
CVE-2022-34429HIGH7.1Dell Hybrid Client below 1.8 version contains a Zip Slip Vulnerability in UI. A guest privilege attacker could potential...
CVE-2022-40756HIGH8.8If folder security is misconfigured for Actian Zen PSQL BEFORE Patch Update 1 for Zen 15 SP1 (v15.11.005), Patch Update ...
CVE-2022-40341HIGH8.8mojoPortal v2.7 was discovered to contain an arbitrary file upload vulnerability which allows attackers to execute arbit...
CVE-2022-20919HIGH7.5A vulnerability in the processing of malformed Common Industrial Protocol (CIP) packets that are sent to Cisco IOS Softw...
CVE-2022-20856HIGH7.5A vulnerability in the processing of Control and Provisioning of Wireless Access Points (CAPWAP) Mobility messages in Ci...
CVE-2022-20851HIGH7.2A vulnerability in the web UI feature of Cisco IOS XE Software could allow an authenticated, remote attacker to perform ...
CVE-2022-20850HIGH7.1A vulnerability in the CLI of stand-alone Cisco IOS XE SD-WAN Software and Cisco SD-WAN Software could allow an authenti...
CVE-2022-20848HIGH7.5A vulnerability in the UDP processing functionality of Cisco IOS XE Software for Embedded Wireless Controllers on Cataly...
CVE-2022-20847HIGH7.5A vulnerability in the DHCP processing functionality of Cisco IOS XE Wireless Controller Software for the Catalyst 9000 ...
CVE-2022-20818HIGH7.8Multiple vulnerabilities in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to gain elevat...
CVE-2022-20775HIGH7.8A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to gain elevated privil...
CVE-2022-41975HIGH7.8RealVNC VNC Server before 6.11.0 and VNC Viewer before 6.22.826 on Windows allow local privilege escalation via MSI inst...
CVE-2022-41870HIGH7.2AP Manager in Innovaphone before 13r2 Service Release 17 allows command injection via a modified service ID during app u...
CVE-2022-40313HIGH7.1Recursive rendering of Mustache template helpers containing user input could, in some cases, result in an XSS risk or a ...
CVE-2022-40277HIGH7.8Joplin version 2.8.8 allows an external attacker to execute arbitrary commands remotely on any client that opens a link ...
CVE-2022-40274HIGH7.8Gridea version 0.9.3 allows an external attacker to execute arbitrary code remotely on any client attempting to view a m...
CVE-2022-36961HIGH8.8A vulnerable component of Orion Platform was vulnerable to SQL Injection, an authenticated attacker could leverage this ...
CVE-2022-41440HIGH7.2Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /phpinventor...
CVE-2022-41439HIGH7.2Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /phpinventor...
CVE-2022-41437HIGH7.2Billing System Project v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the component /php...
CVE-2022-3371HIGH7.5Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.5.0a3.

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now