2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2022-2930HIGH7.8Unverified Password Change in GitHub repository octoprint/octoprint prior to 1.8.3.
CVE-2022-30036HIGH8.8MA Lighting grandMA2 Light has a password of root for the root account. NOTE: The vendor's position is that the product ...
CVE-2022-2921HIGH8.8Exposure of Private Personal Information to an Unauthorized Actor in GitHub repository notrinos/notrinoserp prior to v0....
CVE-2022-38493HIGH7.5Rhonabwy 0.9.99 through 1.1.x before 1.1.7 doesn't check the RSA private key length before RSA-OAEP decryption. This all...
CVE-2022-2909HIGH8.8A vulnerability was found in SourceCodester Simple and Nice Shopping Cart Script. It has been declared as critical. Affe...
CVE-2022-2793HIGH7.8Emerson Electric's Proficy Machine Edition Version 9.00 and prior is vulenrable to CWE-353 Missing Support for Integrity...
CVE-2022-2792HIGH7.5Emerson Electric's Proficy Machine Edition Version 9.00 and prior is vulenrable to CWE-284 Improper Access Control, and ...
CVE-2022-36171HIGH8.1MapGIS IGServer 10.5.6.11 is vulnerable to Arbitrary file deletion.
CVE-2022-36157HIGH8.8XXL-JOB all versions as of 11 July 2022 are vulnerable to Insecure Permissions resulting in the ability to execute admin...
CVE-2022-36170HIGH8.8MapGIS 10.5 Pro IGServer has hardcoded credentials in the front-end and can lead to escalation of privileges and arbitra...
CVE-2022-36009HIGH8.8gomatrixserverlib is a Go library for matrix protocol federation. Dendrite is a Matrix homeserver written in Go, an alte...
CVE-2022-2788HIGH7.3Emerson Electric's Proficy Machine Edition Version 9.80 and prior is vulnerable to CWE-29 Path Traversal: '\..\Filename'...
CVE-2022-23460HIGH7.5Jsonxx or Json++ is a JSON parser, writer and reader written in C++. In affected versions of jsonxx json parsing may lea...
CVE-2022-36579HIGH8.8Wellcms 2.2.0 is vulnerable to Cross Site Request Forgery (CSRF).
CVE-2022-36577HIGH8.8An issue was discovered in jizhicms v2.3.1. There is a CSRF vulnerability that can add a admin.
CVE-2022-36225HIGH8.8EyouCMS V1.5.8-UTF8-SP1 is vulnerable to Cross Site Request Forgery (CSRF) via the background, column management functio...
CVE-2022-36224HIGH8.8XunRuiCMS V4.5.6 is vulnerable to Cross Site Request Forgery (CSRF).
CVE-2022-36263HIGH7.3StreamLabs Desktop Application 1.9.0 is vulnerable to Incorrect Access Control via obs64.exe. An attacker can execute ar...
CVE-2022-35909HIGH8.8In Jellyfin before 10.8, the /users endpoint has incorrect access control for admin functionality.
CVE-2022-2889HIGH7.8Use After Free in GitHub repository vim/vim prior to 9.0.0225.
CVE-2022-2886HIGH8.8A vulnerability, which was classified as critical, was found in Laravel 5.1. Affected is an unknown function. The manipu...
CVE-2022-2075HIGH7.5In affected versions of Octopus Deploy it is possible to perform a Regex Denial of Service targeting the build informati...
CVE-2022-2074HIGH7.5In affected versions of Octopus Deploy it is possible to perform a Regex Denial of Service using the Variable Project Te...
CVE-2022-2049HIGH7.5In affected versions of Octopus Deploy it is possible to perform a Regex Denial of Service via the package upload functi...
CVE-2022-35167HIGH8.8Printix Cloud Print Management v1.3.1149.0 for Windows was discovered to contain insecure permissions.

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now