2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2022-35291HIGH8.1Due to misconfigured application endpoints, SAP SuccessFactors attachment APIs allow attackers with user privileges to p...
CVE-2022-34549HIGH8.8Sims v1.0 was discovered to contain an arbitrary file upload vulnerability via the component /uploadServlet. This vulner...
CVE-2022-33970HIGH7.2Authenticated WordPress Options Change vulnerability in Biplob018 Shortcode Addons plugin <= 3.1.2 at WordPress.
CVE-2022-2313HIGH7.3A DLL hijacking vulnerability in the MA Smart Installer for Windows prior to 5.7.7, which allows local users to execute ...
CVE-2022-27610HIGH8.1Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in webapi component in Syno...
CVE-2022-34971HIGH8.8An arbitrary file upload vulnerability in the Advertising Management module of Feehi CMS v2.1.1 allows attackers to exec...
CVE-2022-30276HIGH7.5The Motorola MOSCAD and ACE line of RTUs through 2022-05-02 omit an authentication requirement. They feature IP Gateway ...
CVE-2022-30272HIGH7.2The Motorola ACE1000 RTU through 2022-05-02 mishandles firmware integrity. It utilizes either the STS software suite or ...
CVE-2022-30269HIGH8.8Motorola ACE1000 RTUs through 2022-05-02 mishandle application integrity. They allow for custom application installation...
CVE-2022-31205HIGH7.5In Omron CS series, CJ series, and CP series PLCs through 2022-05-18, the password for access to the Web UI is stored in...
CVE-2022-31204HIGH7.5Omron CS series, CJ series, and CP series PLCs through 2022-05-18 use cleartext passwords. They feature a UM Protection ...
CVE-2022-30275HIGH7.5The Motorola MOSCAD Toolbox software through 2022-05-02 relies on a cleartext password. It utilizes an MDLC driver to co...
CVE-2022-29957HIGH7.8The Emerson DeltaV Distributed Control System (DCS) through 2022-04-29 mishandles authentication. It utilizes several pr...
CVE-2022-1641HIGH8.8Use after free in Web UI Diagnostics in Google Chrome on Chrome OS prior to 101.0.4951.64 allowed a remote attacker who ...
CVE-2022-1640HIGH8.8Use after free in Sharing in Google Chrome prior to 101.0.4951.64 allowed a remote attacker who convinced a user to enga...
CVE-2022-1639HIGH8.8Use after free in ANGLE in Google Chrome prior to 101.0.4951.64 allowed a remote attacker to potentially exploit heap co...
CVE-2022-1638HIGH8.8Heap buffer overflow in V8 Internationalization in Google Chrome prior to 101.0.4951.64 allowed a remote attacker to pot...
CVE-2022-1636HIGH8.8Use after free in Performance APIs in Google Chrome prior to 101.0.4951.64 allowed a remote attacker to potentially expl...
CVE-2022-1635HIGH8.8Use after free in Permission Prompts in Google Chrome prior to 101.0.4951.64 allowed a remote attacker who convinced a u...
CVE-2022-1634HIGH8.8Use after free in Browser UI in Google Chrome prior to 101.0.4951.64 allowed a remote attacker who had convinced a user ...
CVE-2022-1633HIGH8.8Use after free in Sharesheet in Google Chrome on Chrome OS prior to 101.0.4951.64 allowed a remote attacker who convince...
CVE-2022-1496HIGH8.8Use after free in File Manager in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to potentially exploit ...
CVE-2022-1493HIGH8.8Use after free in Dev Tools in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to potentially exploit hea...
CVE-2022-1491HIGH8.8Use after free in Bookmarks in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to potentially exploit hea...
CVE-2022-1490HIGH8.8Use after free in Browser Switcher in Google Chrome prior to 101.0.4951.41 allowed a remote attacker who convinced a use...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now