2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2022-38413HIGH7.8Adobe InDesign versions 16.4.2 (and earlier) and 17.3 (and earlier) are affected by a Heap-based Buffer Overflow vulnera...
CVE-2022-38405HIGH7.8Adobe InCopy version 17.3 (and earlier) and 16.4.2 (and earlier) are affected by a Heap-based Buffer Overflow vulnerabil...
CVE-2022-38404HIGH7.8Adobe InCopy version 17.3 (and earlier) and 16.4.2 (and earlier) are affected by a Heap-based Buffer Overflow vulnerabil...
CVE-2022-38403HIGH7.8Adobe InCopy version 17.3 (and earlier) and 16.4.2 (and earlier) are affected by a Heap-based Buffer Overflow vulnerabil...
CVE-2022-38402HIGH7.8Adobe InCopy version 17.3 (and earlier) and 16.4.2 (and earlier) are affected by a Heap-based Buffer Overflow vulnerabil...
CVE-2022-38401HIGH7.8Adobe InCopy version 17.3 (and earlier) and 16.4.2 (and earlier) are affected by a Heap-based Buffer Overflow vulnerabil...
CVE-2022-35713HIGH7.8Adobe Photoshop versions 22.5.8 (and earlier) and 23.4.2 (and earlier) are affected by an out-of-bounds write vulnerabil...
CVE-2022-28853HIGH7.8Adobe InDesign versions 16.4.2 (and earlier) and 17.3 (and earlier) are affected by an out-of-bounds write vulnerability...
CVE-2022-28852HIGH7.8Adobe InDesign versions 16.4.2 (and earlier) and 17.3 (and earlier) are affected by by an out-of-bounds write vulnerabil...
CVE-2022-38412HIGH7.8Adobe Animate version 21.0.11 (and earlier) and 22.0.7 (and earlier) are affected by an out-of-bounds read vulnerability...
CVE-2022-38411HIGH7.8Adobe Animate version 21.0.11 (and earlier) and 22.0.7 (and earlier) are affected by a Heap-based Buffer Overflow vulner...
CVE-2022-38408HIGH7.8Adobe Illustrator versions 26.4 (and earlier) and 25.4.7 (and earlier) are affected by an Improper Input Validation vuln...
CVE-2022-40337HIGH8.8OASES (aka Open Aviation Strategic Engineering System) 8.8.0.2 allows attackers to execute arbitrary code via the Open P...
CVE-2022-38878HIGH7.2School Activity Updates with SMS Notification v1.0 is vulnerable to SQL Injection via /activity/admin/modules/event/inde...
CVE-2022-38877HIGH7.2Garage Management System v1.0 is vulnerable to Arbitrary code execution via ip/garage/php_action/editProductImage.php?id...
CVE-2022-35195HIGH7.2TestLink 1.9.20 Raijin was discovered to contain a broken access control vulnerability at /lib/attachments/attachmentdow...
CVE-2022-35193HIGH7.2TestLink v1.9.20 was discovered to contain a SQL injection vulnerability via /lib/execute/execNavigator.php.
CVE-2022-38833HIGH7.2School Activity Updates with SMS Notification v1.0 is vulnerable to SQL Injection via /activity/admin/modules/modstudent...
CVE-2022-38832HIGH7.2School Activity Updates with SMS Notification v1.0 is vulnerable to SQL Injection via /activity/admin/modules/department...
CVE-2022-3176HIGH7.8There exists a use-after-free in io_uring in the Linux kernel. Signalfd_poll() and binder_poll() use a waitqueue whose l...
CVE-2022-38844HIGH8CSV Injection in Create Contacts in EspoCRM 7.1.8 allows remote authenticated users to run system commands via creating ...
CVE-2022-38843HIGH8.8EspoCRM version 7.1.8 is vulnerable to Unrestricted File Upload allowing attackers to upload malicious file with any ext...
CVE-2022-38808HIGH8.8ywoa v6.1 is vulnerable to SQL Injection via backend/oa/visual/exportExcel.do interface.
CVE-2022-40152HIGH7.5Those using Woodstox to parse XML data may be vulnerable to Denial of Service attacks (DOS) if DTD support is enabled. I...
CVE-2022-40151HIGH7.5Those using Xstream to seralize XML data may be vulnerable to Denial of Service attacks (DOS). If the parser is running ...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now