2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2022-34114HIGH8.8Dataease v1.11.1 was discovered to contain a SQL injection vulnerability via the parameter dataSourceId.
CVE-2022-33960HIGH8.8Multiple Authenticated (subscriber or higher user role) SQL Injection (SQLi) vulnerabilities in Social Share Buttons by ...
CVE-2022-33901HIGH7.5Unauthenticated Arbitrary File Read vulnerability in MultiSafepay plugin for WooCommerce plugin <= 4.13.1 at WordPress.
CVE-2022-30998HIGH8.8Multiple Authenticated (subscriber or higher user role) SQL Injection (SQLi) vulnerabilities in WooPlugins.co's Homepage...
CVE-2022-27235HIGH8.8Multiple Broken Access Control vulnerabilities in Social Share Buttons by Supsystic plugin <= 2.2.3 at WordPress.
CVE-2022-0980HIGH8.8Use after free in New Tab Page in Google Chrome prior to 99.0.4844.74 allowed an attacker who convinced a user to instal...
CVE-2022-0979HIGH8.8Use after free in Safe Browsing in Google Chrome on Android prior to 99.0.4844.74 allowed a remote attacker who convince...
CVE-2022-0978HIGH8.8Use after free in ANGLE in Google Chrome prior to 99.0.4844.74 allowed a remote attacker to potentially exploit heap cor...
CVE-2022-28879HIGH7.5A Denial-of-Service (DoS) vulnerability was discovered in F-Secure Atlant and in certain WithSecure products whereby the...
CVE-2022-28878HIGH7.5A Denial-of-Service vulnerability was discovered in the F-Secure Atlant and in certain WithSecure products while scannin...
CVE-2022-34037HIGH7.5An out-of-bounds read in the rewrite function at /modules/caddyhttp/rewrite/rewrite.go in Caddy v2.5.1 allows attackers ...
CVE-2022-2138HIGH7.5The affected product is vulnerable due to missing authentication, which may allow an attacker to read or modify sensitiv...
CVE-2022-2135HIGH7.5The affected product is vulnerable to multiple SQL injections, which may allow an unauthorized attacker to disclose info...
CVE-2022-31168HIGH8.8Zulip is an open source team chat tool. Due to an incorrect authorization check in Zulip Server 5.4 and earlier, a membe...
CVE-2022-2327HIGH7.8io_uring use work_flags to determine which identity need to grab from the calling process to make sure it is consistent ...
CVE-2022-31172HIGH7.5OpenZeppelin Contracts is a library for smart contract development. Versions 4.1.0 until 4.7.1 are vulnerable to the Sig...
CVE-2022-31170HIGH7.5OpenZeppelin Contracts is a library for smart contract development. Versions 4.0.0 until 4.7.1 are vulnerable to ERC165C...
CVE-2022-31169HIGH7.5Wasmtime is a standalone runtime for WebAssembly. There is a bug in Wasmtime's code generator, Cranelift, for AArch64 ta...
CVE-2022-31164HIGH7.5Tovy is a a staff management system for Roblox groups. A vulnerability in versions prior to 0.7.51 allows users to log i...
CVE-2022-31163HIGH8.1TZInfo is a Ruby library that provides access to time zone data and allows times to be converted using time zone rules. ...
CVE-2022-31162HIGH7.5Slack Morphism is an async client library for Rust. Prior to 0.41.0, it was possible for Slack OAuth client information ...
CVE-2022-2493HIGH8.1Data Access from Outside Expected Data Manager Component in GitHub repository openemr/openemr prior to 7.0.0.
CVE-2022-20912HIGH7.2Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W...
CVE-2022-20911HIGH7.2Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W...
CVE-2022-20910HIGH7.2Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now