2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2022-26049HIGH8.8This affects the package com.diffplug.gradle:goomph before 3.37.2. It allows a malicious zip file to potentially break o...
CVE-2022-40320HIGH8.8cfg_tilde_expand in confuse.c in libConfuse 3.3 has a heap-based buffer over-read.
CVE-2022-36110HIGH8.8Netmaker makes networks with WireGuard. Prior to version 0.15.1, Improper Authorization functions lead to non-privileged...
CVE-2022-31006HIGH7.5indy-node is the server portion of Hyperledger Indy, a distributed ledger purpose-built for decentralized identity. In v...
CVE-2022-3133HIGH7.8OS Command Injection in GitHub repository jgraph/drawio prior to 20.3.0.
CVE-2022-38615HIGH8.8SmartVista SVFE2 v2.2.22 was discovered to contain multiple SQL injection vulnerabilities via the UserForm:j_id88, UserF...
CVE-2022-38614HIGH7.5An issue in the IGB Files and OutfileService features of SmartVista Cardgen v3.28.0 allows attackers to list and downloa...
CVE-2022-28742HIGH7.5aEnrich eHRD Learning Management Key Performance Indicator System 5+ has Improper Access Control. The web application do...
CVE-2022-28741HIGH8.1aEnrich a+HRD 5.x Learning Management Key Performance Indicator System has a local file inclusion (LFI) vulnerability th...
CVE-2022-28740HIGH7.5aEnrich eHRD Learning Management Key Performance Indicator System 5+ exposes Sensitive Information to an Unauthorized Ac...
CVE-2022-39846HIGH7.8DLL hijacking vulnerability in Smart Switch PC prior to version 4.3.22083_3 allows attacker to execute arbitrary code.
CVE-2022-39845HIGH7.1Improper validation of integrity check vulnerability in Samsung Kies prior to version 2.6.4.22074 allows local attackers...
CVE-2022-39844HIGH7.1Improper validation of integrity check vulnerability in Smart Switch PC prior to version 4.3.22083 allows local attacker...
CVE-2022-39119HIGH7.8In network service, there is a missing permission check. This could lead to local escalation of privilege with no additi...
CVE-2022-38700HIGH8.8OpenHarmony-v3.1.1 and prior versions have a permission bypass vulnerability. LAN attackers can bypass permission contro...
CVE-2022-38144HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in gVectors Team wpForo Forum plugin <= 2.0.5 at WordPress.
CVE-2022-38093HIGH8.8Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in All in One SEO plugin <= 4.2.3.1 at WordPress.
CVE-2022-38070HIGH8.8Privilege Escalation (subscriber+) vulnerability in Pop-up plugin <= 1.1.5 at WordPress.
CVE-2022-38059HIGH8Cross-Site Request Forgery (CSRF) vulnerability in Alexey Trofimov's Access Code Feeder plugin <= 1.0.3 at WordPress.
CVE-2022-37411HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Vinoj Cardoza's Captcha Code plugin <= 2.7 at WordPress.
CVE-2022-37405HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Mickey Kay's Better Font Awesome plugin <= 2.0.1 at WordPress.
CVE-2022-36864HIGH7.8Improper access control and intent redirection in Samsung Email prior to 6.1.70.20 allows attacker to access specific fo...
CVE-2022-36863HIGH7.8A heap-based overflow vulnerability in GetCorrectDbLanguageTypeEsPKc function in libSDKRecognitionText.spensdk.samsung.s...
CVE-2022-36862HIGH7.8A heap-based overflow vulnerability in HWR::EngineCJK::Impl::Construct() in libSDKRecognitionText.spensdk.samsung.so lib...
CVE-2022-36860HIGH7.8A heap-based overflow vulnerability in LoadEnvironment function in libSDKRecognitionText.spensdk.samsung.so library prio...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now