2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2022-36234HIGH7.5SimpleNetwork TCP Server commit 29bc615f0d9910eb2f59aa8dff1f54f0e3af4496 was discovered to contain a double free vulnera...
CVE-2022-34557HIGH8.8Barangay Management System v1.0 was discovered to contain a SQL injection vulnerability via the hidden_id parameter at /...
CVE-2022-34568HIGH7.5SDL v1.2 was discovered to contain a use-after-free via the XFree function at /src/video/x11/SDL_x11yuv.c.
CVE-2022-30287HIGH8Horde Groupware Webmail Edition through 5.2.22 allows a reflection injection attack through which an attacker can instan...
CVE-2022-2399HIGH8.8Use after free in WebGPU in Google Chrome prior to 100.0.4896.88 allowed a remote attacker to potentially exploit heap c...
CVE-2022-29558HIGH8.8Realtek rtl819x-SDK before v3.6.1 allows command injection over the web interface.
CVE-2022-34593HIGH7.5DPTech VPN v8.1.28.0 was discovered to contain an arbitrary file read vulnerability.
CVE-2022-34578HIGH7.2Open Source Point of Sale v3.3.7 was discovered to contain an arbitrary file upload vulnerability via the Update Brandin...
CVE-2022-30319HIGH8.1Saia Burgess Controls (SBC) PCD through 2022-05-06 allows Authentication bypass. According to FSCT-2022-0062, there is a...
CVE-2022-30313HIGH7.5Honeywell Experion PKS Safety Manager through 2022-05-06 has Missing Authentication for a Critical Function. According t...
CVE-2022-1805HIGH8.1When connecting to Amazon Workspaces, the SHA256 presented by AWS connection provisioner is not fully verified by Zero C...
CVE-2022-37009HIGH7.8In JetBrains IntelliJ IDEA before 2022.2 local code execution via a Vagrant executable was possible
CVE-2022-36364HIGH8.8Apache Calcite Avatica JDBC driver creates HTTP client instances based on class names provided via `httpclient_impl` con...
CVE-2022-27611HIGH8.1Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in webapi component in Syno...
CVE-2022-27614HIGH7.5Exposure of sensitive information to an unauthorized actor vulnerability in web server in Synology Media Server before 1...
CVE-2022-27613HIGH8.8Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in webapi component i...
CVE-2022-22685HIGH8.1Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in webapi component in Syno...
CVE-2022-22684HIGH8.8Improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in task managem...
CVE-2022-27615HIGH8.1Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in cgi component in Synolog...
CVE-2022-2481HIGH8.8Use after free in Views in Google Chrome prior to 103.0.5060.134 allowed a remote attacker who convinced a user to engag...
CVE-2022-2480HIGH8.8Use after free in Service Worker API in Google Chrome prior to 103.0.5060.134 allowed a remote attacker to potentially e...
CVE-2022-2478HIGH8.8Use after free in PDF in Google Chrome prior to 103.0.5060.134 allowed a remote attacker to potentially exploit heap cor...
CVE-2022-2477HIGH8.8Use after free in Guest View in Google Chrome prior to 103.0.5060.134 allowed an attacker who convinced a user to instal...
CVE-2022-2296HIGH8.8Use after free in Chrome OS Shell in Google Chrome on Chrome OS prior to 103.0.5060.114 allowed a remote attacker who co...
CVE-2022-2295HIGH8.8Type confusion in V8 in Google Chrome prior to 103.0.5060.114 allowed a remote attacker to potentially exploit heap corr...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now