2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2022-2319HIGH7.8A flaw was found in the Xorg-x11-server. An out-of-bounds access issue can occur in the ProcXkbSetGeometry function due ...
CVE-2022-1902HIGH8.8A flaw was found in the Red Hat Advanced Cluster Security for Kubernetes. Notifier secrets were not properly sanitized i...
CVE-2022-1729HIGH7A race condition was found the Linux kernel in perf_event_open() which can be exploited by an unprivileged user to gain ...
CVE-2022-36773HIGH8.1IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 is vulnerable to an XML External Entity Injection (XXE) attack when proc...
CVE-2022-34380HIGH8.2Dell CloudLink 7.1.3 and all earlier versions contain an Authentication Bypass Using an Alternate Path or Channel Vulner...
CVE-2022-30614HIGH7.5IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 is vulnerable to a denial of service via email flooding caused by sendin...
CVE-2022-2996HIGH7.4A flaw was found in the python-scciclient when making an HTTPS connection to a server where the server's certificate wou...
CVE-2022-36373HIGH8.8Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in Simon Ward MP3 jPlayer plugin <= 2.7.3 at WordPress.
CVE-2022-37435HIGH8.8Apache ShenYu Admin has insecure permissions, which may allow low-privilege administrators to modify high-privilege admi...
CVE-2022-36054HIGH8.8Contiki-NG is an open-source, cross-platform operating system for Next-Generation IoT devices. The 6LoWPAN implementatio...
CVE-2022-36053HIGH8.8Contiki-NG is an open-source, cross-platform operating system for Next-Generation IoT devices. The low-power IPv6 networ...
CVE-2022-36052HIGH8.8Contiki-NG is an open-source, cross-platform operating system for Next-Generation IoT devices. The 6LoWPAN implementatio...
CVE-2022-36676HIGH7.2Simple Task Scheduling System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /cate...
CVE-2022-36675HIGH7.2Simple Task Scheduling System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /sche...
CVE-2022-36674HIGH7.2Simple Task Scheduling System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /sche...
CVE-2022-36671HIGH7.5Novel-Plus v3.6.2 was discovered to contain an arbitrary file download vulnerability via the background file download AP...
CVE-2022-37129HIGH8.8D-Link DIR-816 A2_v1.10CNB04.img is vulnerable to Command Injection via /goform/SystemCommand. After the user passes in ...
CVE-2022-37123HIGH8.8D-link DIR-816 A2_v1.10CNB04.img is vulnerable to Command injection via /goform/form2userconfig.cgi.
CVE-2022-36619HIGH7.5In D-link DIR-816 A2_v1.10CNB04.img,the network can be reset without authentication via /goform/setMAC.
CVE-2022-36051HIGH8.8ZITADEL combines the ease of Auth0 and the versatility of Keycloak.**Actions**, introduced in ZITADEL **1.42.0** on the ...
CVE-2022-36620HIGH7.5D-link DIR-816 A2_v1.10CNB04, DIR-878 DIR_878_FW1.30B08.img is vulnerable to Buffer Overflow via /goform/addRouting.
CVE-2022-2897HIGH7.8Measuresoft ScadaPro Server and Client (All Versions) do not properly resolve links before file access; this could allow...
CVE-2022-2896HIGH7.8Measuresoft ScadaPro Server (All Versions) allows use after free while processing a specific project file.
CVE-2022-2895HIGH7.8Measuresoft ScadaPro Server (All Versions) uses unmaintained ActiveX controls. These controls may allow two stack-based ...
CVE-2022-2894HIGH7.8Measuresoft ScadaPro Server (All Versions) uses unmaintained ActiveX controls. The controls may allow seven untrusted po...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now