2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2022-35505HIGH7.5A segmentation fault in TripleCross v0.1.0 occurs when sending a control command from the client to the server. This occ...
CVE-2022-35158HIGH7.5A vulnerability in the lua parser of TscanCode tsclua v2.15.01 allows attackers to cause a Denial of Service (DoS) via a...
CVE-2022-31197HIGH8PostgreSQL JDBC Driver (PgJDBC for short) allows Java programs to connect to a PostgreSQL database using standard, datab...
CVE-2022-34992HIGH7.8Luadec v0.9.9 was discovered to contain a heap-buffer overflow via the function UnsetPending.
CVE-2022-37396HIGH7.8In JetBrains Rider before 2022.2 Trust and Open Project dialog could be bypassed, leading to local code execution
CVE-2022-34871HIGH7.2This vulnerability allows remote attackers to escalate privileges on affected installations of Centreon. Authentication ...
CVE-2022-28684HIGH8.8This vulnerability allows remote attackers to execute arbitrary code on affected installations of DevExpress. Authentica...
CVE-2022-28668HIGH7.8This vulnerability allows remote attackers to execute arbitrary code on affected installations of Sante DICOM Viewer Pro...
CVE-2022-34973HIGH7.5D-Link DIR820LA1_FW106B02 was discovered to contain a buffer overflow via the nextPage parameter at ping.ccp.
CVE-2022-36359HIGH8.8An issue was discovered in the HTTP FileResponse class in Django 3.2 before 3.2.15 and 4.0 before 4.0.7. An application ...
CVE-2022-32293HIGH8.1In ConnMan through 1.41, a man-in-the-middle attack against a WISPR HTTP query could be used to trigger a use-after-free...
CVE-2022-35737HIGH7.5SQLite 1.0.12 through 3.39.x before 3.39.2 sometimes allows an array-bounds overflow if billions of bytes are used in a ...
CVE-2022-34969HIGH7.5PingCAP TiDB v6.1.0 was discovered to contain a NULL pointer dereference.
CVE-2022-34968HIGH7.5An issue in the fetch_step function in Percona Server for MySQL v8.0.28-19 allows attackers to cause a Denial of Service...
CVE-2022-34967HIGH7.5The assertion `stmt->Dbc->FirstStmt' failed in MonetDB Database Server v11.43.13.
CVE-2022-27616HIGH7.2Improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in webapi compo...
CVE-2022-34937HIGH8.8Yuba u5cms v8.3.5 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component savepage.php. This vul...
CVE-2022-34928HIGH8.8JFinal CMS v5.1.0 was discovered to contain a SQL injection vulnerability via /system/user.
CVE-2022-34927HIGH7.8MilkyTracker v1.03.00 was discovered to contain a stack overflow via the component LoaderXM::load. This vulnerability is...
CVE-2022-37035HIGH8.1An issue was discovered in bgpd in FRRouting (FRR) 8.3. In bgp_notify_send_with_data() and bgp_process_packet() in bgp_p...
CVE-2022-29808HIGH7.5In Quest KACE Systems Management Appliance (SMA) through 12.0, predictable token generation occurs when appliance linkin...
CVE-2022-35923HIGH7.5v8n is a javascript validation library. Versions of v8n prior to 1.5.1 were found to have an inefficient regular express...
CVE-2022-34924HIGH7.5Lanling OA Landray Office Automation (OA) internal patch number #133383/#137780 contains an arbitrary file read vulnerab...
CVE-2022-2631HIGH8.8Improper Access Control in GitHub repository tooljet/tooljet prior to v1.19.0.
CVE-2022-35217HIGH7.8The NHI card’s web service component has a stack-based buffer overflow vulnerability due to insufficient validation for ...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now