2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2022-38931HIGH8.8A Server-Side Request Forgery (SSRF) in fetch_net_file_upload function of baijiacmsV4 v4.1.4 allows remote attackers to ...
CVE-2022-37884HIGH7.5A vulnerability exists in the ClearPass Policy Manager Guest User Interface that can allow an unauthenticated attacker t...
CVE-2022-37883HIGH7.2Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run a...
CVE-2022-37882HIGH7.2Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run a...
CVE-2022-37881HIGH7.2Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run a...
CVE-2022-37880HIGH7.2Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run a...
CVE-2022-37879HIGH7.2Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run a...
CVE-2022-37878HIGH7.2Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run a...
CVE-2022-37877HIGH7.8A vulnerability in the ClearPass OnGuard macOS agent could allow malicious users on a macOS instance to elevate their us...
CVE-2022-37395HIGH7.5A Huawei device has an input verification vulnerability. Successful exploitation of this vulnerability may lead to DoS a...
CVE-2022-37972HIGH7.5Microsoft Endpoint Configuration Manager Spoofing Vulnerability
CVE-2022-30579HIGH8.4The Web Player component of TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketplace and TIBCO Spotfi...
CVE-2022-40262HIGH8.2A potential attacker can execute an arbitrary code at the time of the PEI phase and influence the subsequent boot stages...
CVE-2022-40261HIGH8.2An attacker can exploit this vulnerability to elevate privileges from ring 0 to ring -2, execute arbitrary code in Syste...
CVE-2022-40250HIGH8.8An attacker can exploit this vulnerability to elevate privileges from ring 0 to ring -2, execute arbitrary code in Syste...
CVE-2022-40246HIGH7.2A potential attacker can write one byte by arbitrary address at the time of the PEI phase (only during S3 resume boot mo...
CVE-2022-39974HIGH7.5WASM3 v0.5.0 was discovered to contain a segmentation fault via the component op_Select_i32_srs in wasm3/source/m3_exec....
CVE-2022-38955HIGH7.5An exploitable firmware modification vulnerability was discovered on the Netgear WPN824EXT WiFi Range Extender. An attac...
CVE-2022-38340HIGH7.2Safe Software FME Server v2021.2.5, v2022.0.0.2 and below was discovered to contain a Path Traversal vulnerability via t...
CVE-2022-37259HIGH7.5A Regular Expression Denial of Service (ReDoS) flaw was found in stealjs steal 2.2.4 via the string variable in babel.js...
CVE-2022-37205HIGH8.8JFinal CMS 5.1.0 is affected by: SQL Injection. These interfaces do not use the same component, nor do they have filters...
CVE-2022-26873HIGH8.2A potential attacker can execute an arbitrary code at the time of the PEI phase and influence the subsequent boot stages...
CVE-2022-35196HIGH8.8TestLink v1.9.20 was discovered to contain a Cross-Site Request Forgery (CSRF) via /lib/plan/planView.php.
CVE-2022-40955HIGH8.8In versions of Apache InLong prior to 1.3.0, an attacker with sufficient privileges to specify MySQL JDBC connection URL...
CVE-2022-3079HIGH7.5Festo control block CPX-CEC-C1 and CPX-CMXX in multiple versions allow unauthenticated, remote access to critical webpag...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now