2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2022-2185HIGH8.8A critical issue has been discovered in GitLab affecting all versions starting from 14.0 prior to 14.10.5, 15.0 prior to...
CVE-2022-33103HIGH7.8Das U-Boot from v2020.10 to v2022.07-rc3 was discovered to contain an out-of-bounds write via the function sqfs_readdir(...
CVE-2022-33099HIGH7.5An issue in the component luaG_runerror of Lua v5.4.4 and below leads to a heap-buffer overflow when a recursive error o...
CVE-2022-2264HIGH7.8Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.
CVE-2022-27904HIGH7Automox Agent for macOS before version 39 was vulnerable to a time-of-check/time-of-use (TOCTOU) race-condition attack d...
CVE-2022-33087HIGH7.5A stack overflow in the function DM_ In fillobjbystr() of TP-Link Archer C50&A5(US)_V5_200407 allows attackers to cause ...
CVE-2022-33085HIGH7.2ESPCMS P8 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the fetch_filename fu...
CVE-2022-33082HIGH7.5An issue in the AST parser (ast/compile.go) of Open Policy Agent v0.10.2 allows attackers to cause a Denial of Service (...
CVE-2022-31115HIGH8.8opensearch-ruby is a community-driven, open source fork of elasticsearch-ruby. In versions prior to 2.0.1 the ruby `YAML...
CVE-2022-2257HIGH7.8Out-of-bounds Read in GitHub repository vim/vim prior to 9.0.
CVE-2022-23720HIGH8.2PingID Windows Login prior to 2.8 does not alert or halt operation if it has been provisioned with the full permissions ...
CVE-2022-23718HIGH8.1PingID Windows Login prior to 2.8 uses known vulnerable components that can lead to remote code execution. An attacker c...
CVE-2022-34793HIGH8.8Jenkins Recipe Plugin 1.2 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
CVE-2022-34792HIGH8A cross-site request forgery (CSRF) vulnerability in Jenkins Recipe Plugin 1.2 and earlier allows attackers to send an H...
CVE-2022-31112HIGH8.2Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. In affected vers...
CVE-2022-22474HIGH7.5IBM Spectrum Protect 8.1.0.0 through 8.1.14.0 dsmcad, dsmc, and dsmcsvc processes incorrectly handle certain read operat...
CVE-2022-22472HIGH8.8IBM Spectrum Protect Plus Container Backup and Restore (10.1.5 through 10.1.10.2 for Kubernetes and 10.1.7 through 10.1....
CVE-2022-33061HIGH7.2Online Railway Reservation System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /...
CVE-2022-33060HIGH7.2Online Railway Reservation System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /...
CVE-2022-33059HIGH7.2Online Railway Reservation System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /...
CVE-2022-33058HIGH7.2Online Railway Reservation System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /...
CVE-2022-33057HIGH7.2Online Railway Reservation System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /...
CVE-2022-2073HIGH7.2Code Injection in GitHub repository getgrav/grav prior to 1.7.34.
CVE-2022-31110HIGH7.5RSSHub is an open source, extensible RSS feed generator. In commits prior to 5c4177441417 passing some special values to...
CVE-2022-31058HIGH7.2Tuleap is a Free & Open Source Suite to improve management of software developments and collaboration. In versions prior...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now