2022 CVE Vulnerabilities

27,525 CVEs published in 2022.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2022-34442CRITICAL9.8 Dell EMC SCG Policy Manager, versions from 5.10 to 5.12, contain(s) a contain a Hard-coded Cryptographic Key vulnerabil...
CVE-2022-46733CRITICAL9.6Sewio’s Real-Time Location System (RTLS) Studio version 2.0.0 up to and including version 2.6.2 is vulnerable to cross-s...
CVE-2022-45444CRITICAL9.8Sewio’s Real-Time Location System (RTLS) Studio version 2.0.0 up to and including version 2.6.2 contains hard-coded pass...
CVE-2022-41989CRITICAL9.8Sewio’s Real-Time Location System (RTLS) Studio version 2.0.0 up to and including version 2.6.2 does not validate the le...
CVE-2022-46732CRITICAL9.8Even if the authentication fails for local service authentication, the requested command could still execute regardless ...
CVE-2022-41903CRITICAL9.8Git is distributed revision control system. `git log` can display commits in an arbitrary format using its `--format` sp...
CVE-2022-23521CRITICAL9.8Git is distributed revision control system. gitattributes are a mechanism to allow defining attributes for paths. These ...
CVE-2022-46475CRITICAL9.8D-Link DIR 645A1 1.06B01_Beta01 was discovered to contain a stack overflow via the service= variable in the genacgi_main...
CVE-2022-43977CRITICAL9.8An issue was discovered on GE Grid Solutions MS3000 devices before 3.7.6.25p0_3.2.2.17p0_4.7p0. The debug port accessibl...
CVE-2022-43976CRITICAL9.8An issue was discovered in FC46-WebBridge on GE Grid Solutions MS3000 devices before 3.7.6.25p0_3.2.2.17p0_4.7p0. Direct...
CVE-2022-36760CRITICAL9Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in mod_proxy_ajp of Apache HTTP Se...
CVE-2022-47853CRITICAL9.8TOTOlink A7100RU V7.4cu.2313_B20191024 is vulnerable to Command Injection Vulnerability in the httpd service. An attacke...
CVE-2022-23739CRITICAL9.8An incorrect authorization vulnerability was identified in GitHub Enterprise Server, allowing for escalation of privileg...
CVE-2022-4447CRITICAL9.8The Fontsy WordPress plugin through 1.8.6 does not properly sanitize and escape a parameter before using it in a SQL sta...
CVE-2022-4101CRITICAL9.1The Images Optimize and Upload CF7 WordPress plugin through 2.1.4 does not validate the file to be deleted via an AJAX a...
CVE-2022-4060CRITICAL9.8The User Post Gallery WordPress plugin through 2.19 does not limit what callback functions can be called by users, makin...
CVE-2022-4890CRITICAL9.8A vulnerability, which was classified as critical, has been found in abhilash1985 PredictApp. This issue affects some un...
CVE-2022-4889CRITICAL9.8A vulnerability classified as critical was found in visegripped Stracker. Affected by this vulnerability is the function...
CVE-2022-1812CRITICAL9.8Integer Overflow or Wraparound in GitHub repository publify/publify prior to 9.2.10.
CVE-2022-45299CRITICAL9.8An issue in the IpFile argument of rust-lang webbrowser-rs v0.8.2 allows attackers to access arbitrary files via supplyi...
CVE-2022-46955CRITICAL9.8Dynamic Transaction Queuing System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at ...
CVE-2022-46954CRITICAL9.8Dynamic Transaction Queuing System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at ...
CVE-2022-3782CRITICAL9.1keycloak: path traversal via double URL encoding. A flaw was found in Keycloak, where it does not properly validate URLs...
CVE-2022-21191CRITICAL9.8Versions of the package global-modules-path before 3.0.0 are vulnerable to Command Injection due to missing input saniti...
CVE-2022-46502CRITICAL9.8Online Student Enrollment System v1.0 was discovered to contain a SQL injection vulnerability via the username parameter...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now