2022 CVE Vulnerabilities

27,525 CVEs published in 2022.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2022-22759CRITICAL9.6If a document created a sandboxed iframe without <code>allow-scripts</code>, and subsequently appended an element to the...
CVE-2022-1887CRITICAL9.8The search term could have been specified externally to trigger SQL injection. This vulnerability affects Firefox for iO...
CVE-2022-46170CRITICAL9.8CodeIgniter is a PHP full-stack web framework. When an application uses (1) multiple session cookies (e.g., one for user...
CVE-2022-47926CRITICAL9.8AyaCMS 3.1.2 is vulnerable to file deletion via /aya/module/admin/fst_del.inc.php
CVE-2022-46102CRITICAL9.8AyaCMS 3.1.2 is vulnerable to Arbitrary file upload via /aya/module/admin/fst_down.inc.php
CVE-2022-45966CRITICAL9.8here is an arbitrary file upload vulnerability in the file management function module of Classcms3.5.
CVE-2022-45347CRITICAL9.8Apache ShardingSphere-Proxy prior to 5.3.0 when using MySQL as database backend didn't cleanup the database session comp...
CVE-2022-3184CRITICAL9.8Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where the device’s existing firmware allo...
CVE-2022-3183CRITICAL9.8Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where a specific function does not saniti...
CVE-2022-4643CRITICAL9.8A vulnerability was found in docconv up to 1.2.0. It has been declared as critical. This vulnerability affects the funct...
CVE-2022-4639CRITICAL9.8A vulnerability, which was classified as critical, has been found in sslh. This issue affects the function hexdump of th...
CVE-2022-40145CRITICAL9.8This vulnerable is about a potential code injection when an attacker has control of the target LDAP server using in the ...
CVE-2022-47635CRITICAL9.8Wildix WMS 6 before 6.02.20221216, WMS 5 before 5.04.20221214, and WMS4 before 4.04.45396.23 allows Server-side request ...
CVE-2022-25893CRITICAL9.8The package vm2 before 3.9.10 are vulnerable to Arbitrary Code Execution due to the usage of prototype lookup for the We...
CVE-2022-24431CRITICAL9.8All versions of package abacus-ext-cmdline are vulnerable to Command Injection via the execute function due to improper ...
CVE-2022-38546CRITICAL9.8A DNS misconfiguration was found in Zyxel NBG7510 firmware versions prior to V1.00(ABZY.3)C0, which could allow an unaut...
CVE-2022-47629CRITICAL9.8Libksba before 1.6.3 is prone to an integer overflow vulnerability in the CRL signature parser.
CVE-2022-46327CRITICAL9.8Some smartphones have configuration issues. Successful exploitation of this vulnerability may cause privilege escalation...
CVE-2022-46326CRITICAL9.8Some smartphones have the out-of-bounds write vulnerability. Successful exploitation of this vulnerability may cause sys...
CVE-2022-46325CRITICAL9.8Some smartphones have the out-of-bounds write vulnerability.Successful exploitation of this vulnerability may cause syst...
CVE-2022-46324CRITICAL9.8Some smartphones have the out-of-bounds write vulnerability. Successful exploitation of this vulnerability may cause sys...
CVE-2022-46323CRITICAL9.8Some smartphones have the out-of-bounds write vulnerability.Successful exploitation of this vulnerability may cause syst...
CVE-2022-46320CRITICAL9.8The kernel module has an out-of-bounds read vulnerability. Successful exploitation of this vulnerability may cause memor...
CVE-2022-46319CRITICAL9.8Fingerprint calibration has a vulnerability of lacking boundary judgment. Successful exploitation of this vulnerability ...
CVE-2022-46316CRITICAL9.8A thread security vulnerability exists in the authentication process. Successful exploitation of this vulnerability may ...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now