2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2022-22464HIGH7.5IBM Security Access Manager Appliance 10.0.0.0, 10.0.1.0, 10.0.2.0, and 10.0.3.0 uses weaker than expected cryptographic...
CVE-2022-33011HIGH8.8Known v1.3.1+2020120201 was discovered to allow attackers to perform an account takeover via a host header injection att...
CVE-2022-32481HIGH7.8Dell PowerProtect Cyber Recovery, versions prior to 19.11, contain a privilege escalation vulnerability on virtual appli...
CVE-2022-2191HIGH7.5In Eclipse Jetty versions 10.0.0 thru 10.0.9, and 11.0.0 thru 11.0.9 versions, SslConnection does not release ByteBuffer...
CVE-2022-2048HIGH7.5In Eclipse Jetty HTTP/2 server implementation, when encountering an invalid HTTP/2 request, the error handling has a bug...
CVE-2022-33680HIGH8.3Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
CVE-2022-32058HIGH7.5An infinite loop in the function httpRpmPass of TP-Link TL-WR741N/TL-WR742N V1/V2/V3_130415 allows attackers to cause a ...
CVE-2022-32055HIGH7.5Inout Homestay v2.2 was discovered to contain a SQL injection vulnerability via the guests parameter at /index.php?page=...
CVE-2022-31135HIGH7.5Akashi is an open source server implementation of the Attorney Online video game based on the Ace Attorney universe. Aff...
CVE-2022-31121HIGH7.5Hyperledger Fabric is a permissioned distributed ledger framework. In affected versions if a consensus client sends a ma...
CVE-2022-31854HIGH7.2Codoforum v5.1 was discovered to contain an arbitrary file upload vulnerability via the logo change option in the admin ...
CVE-2022-33996HIGH8.8Incorrect permission management in Devolutions Server before 2022.2 allows a new user with a preexisting username to inh...
CVE-2022-25048HIGH8.8Command injection vulnerability in CWP v0.9.8.1126 that allows normal users to run commands as the root user.
CVE-2022-2339HIGH7.5With this SSRF vulnerability, an attacker can reach internal addresses to make a request as the server and read it's con...
CVE-2022-20859HIGH8.8A vulnerability in the Disaster Recovery framework of Cisco Unified Communications Manager (Unified CM), Cisco Unified C...
CVE-2022-31129HIGH7.5moment is a JavaScript date library for parsing, validating, manipulating, and formatting dates. Affected versions of mo...
CVE-2022-26078HIGH7.5Gallagher Controller 6000 is vulnerable to a Denial of Service attack via conflicting ARP packets with a duplicate IP ad...
CVE-2022-33738HIGH7.5OpenVPN Access Server before 2.11 uses a weak random generator used to create user session token for the web portal
CVE-2022-33737HIGH7.5The OpenVPN Access Server installer creates a log file readable for everyone, which from version 2.10.0 and before 2.11....
CVE-2022-30929HIGH8.8Mini-Tmall v1.0 is vulnerable to Insecure Permissions via tomcat-embed-jasper.
CVE-2022-30619HIGH8.8Editable SQL Queries behind Base64 encoding sending from the Client-Side to The Server-Side for a particular API used in...
CVE-2022-23714HIGH7.8A local privilege escalation (LPE) issue was discovered in the ransomware canaries features of Elastic Endpoint Security...
CVE-2022-21777HIGH7.8In Autoboot, there is a possible permission bypass due to a missing permission check. This could lead to local escalatio...
CVE-2022-21768HIGH8.8In Bluetooth, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation...
CVE-2022-21767HIGH8.8In Bluetooth, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now