2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-45148Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2022-42273HIGH8.8NVIDIA BMC contains a vulnerability in libwebsocket, where an authorized attacker can cause a buffer overflow and cause ...
CVE-2022-42272HIGH8.8NVIDIA BMC contains a vulnerability in IPMI handler, where an authorized attacker can cause a buffer overflow, which may...
CVE-2022-25027HIGH7.5The Forgotten Password functionality of Rocket TRUfusion Portal v7.9.2.1 allows remote attackers to bypass authenticatio...
CVE-2022-25026HIGH7.5A Server-Side Request Forgery (SSRF) in Rocket TRUfusion Portal v7.9.2.1 allows remote attackers to gain access to sensi...
CVE-2022-47102MEDIUM5.4A cross-site scripting (XSS) vulnerability in Student Study Center Management System V 1.0 allows attackers to execute a...
CVE-2022-46623HIGH7.8Judging Management System v1.0.0 was discovered to contain a SQL injection vulnerability via the username parameter.
CVE-2022-46622MEDIUM6.1A cross-site scripting (XSS) vulnerability in Judging Management System v1.0 allows attackers to execute arbitrary web s...
CVE-2022-45729MEDIUM6.1A cross-site scripting (XSS) vulnerability in Doctor Appointment Management System v1.0.0 allows attackers to execute ar...
CVE-2022-45728MEDIUM6.1Doctor Appointment Management System v1.0.0 was discovered to contain a cross-site scripting (XSS) vulnerability.
CVE-2022-46472HIGH7.2Helmet Store Showroom Site v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /hss/cla...
CVE-2022-4842MEDIUM5.5A flaw NULL Pointer Dereference in the Linux kernel NTFS3 driver function attr_punch_hole() was found. A local user coul...
CVE-2022-4743HIGH7.5A potential memory leak issue was discovered in SDL2 in GLES_CreateTexture() function in SDL_render_gles.c. The vulnerab...
CVE-2022-3977HIGH7.8A use-after-free flaw was found in the Linux kernel MCTP (Management Component Transport Protocol) functionality. This i...
CVE-2022-3628MEDIUM6.6A buffer overflow flaw was found in the Linux kernel Broadcom Full MAC Wi-Fi driver. This issue occurs when a user conne...
CVE-2022-3145MEDIUM4.7An open redirect vulnerability exists in Okta OIDC Middleware prior to version 5.0.0 allowing an attacker to redirect a ...
CVE-2022-43591HIGH8.8A buffer overflow vulnerability exists in the QML QtScript Reflect API of Qt Project Qt 6.3.2. A specially-crafted javas...
CVE-2022-40983HIGH8.8An integer overflow vulnerability exists in the QML QtScript Reflect API of Qt Project Qt 6.3.2. A specially-crafted jav...
CVE-2022-46372HIGH8.8Alotcer - AR7088H-A firmware version 16.10.3 Command execution Improper validation of unspecified input field may allow ...
CVE-2022-46371MEDIUM5.3Alotcer - AR7088H-A firmware version 16.10.3 Information disclosure. Unspecified error message contains the default admi...
CVE-2022-46370HIGH7.5Rumpus - FTP server version 9.0.7.1 Improper Token Verification– vulnerability may allow bypassing identity verification...
CVE-2022-46369MEDIUM5.4Rumpus - FTP server version 9.0.7.1 Persistent cross-site scripting (PXSS) – vulnerability may allow inserting scripts i...
CVE-2022-46368HIGH8.8Rumpus - FTP server version 9.0.7.1 Cross-site request forgery (CSRF) – vulnerability may allow unauthorized action on b...
CVE-2022-46367HIGH8.8Rumpus - FTP server Cross-site request forgery (CSRF) – Privilege escalation vulnerability that may allow privilege esca...
CVE-2022-39187MEDIUM6.1Rumpus - FTP server version 9.0.7.1 has a Reflected cross-site scripting (RXSS) vulnerability through unspecified vector...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now