2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2022-24893HIGH8.8ESP-IDF is the official development framework for Espressif SoCs. In Espressif’s Bluetooth Mesh SDK (`ESP-BLE-MESH`), a ...
CVE-2022-33121HIGH8.1A Cross-Site Request Forgery (CSRF) in MiniCMS v1.11 allows attackers to arbitrarily delete local .dat files via clickin...
CVE-2022-22390HIGH7.5IBM Db2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, 11.1, and 11.5 may be vulnerable to an information disclosure cause...
CVE-2022-20829HIGH7.2A vulnerability in the packaging of Cisco Adaptive Security Device Manager (ASDM) images and the validation of those ima...
CVE-2022-20828HIGH7.2A vulnerability in the CLI parser of Cisco FirePOWER Software for Adaptive Security Appliance (ASA) FirePOWER module cou...
CVE-2022-2102HIGH7.5Controls limiting uploads to certain file extensions may be bypassed. This could allow an attacker to intercept the init...
CVE-2022-28619HIGH7.8A potential security vulnerability has been identified in the installer of HPE Version Control Repository Manager. The v...
CVE-2022-1746HIGH7.6The authentication mechanism used by poll workers to administer voting using the tested version of Dominion Voting Syste...
CVE-2022-1667HIGH7.5Client-side JavaScript controls may be bypassed by directly running a JS function to reboot the PLC (e.g., from the brow...
CVE-2022-32530HIGH7.8A CWE-668 Exposure of Resource to Wrong Sphere vulnerability exists that could cause users to be misled, hiding alarms, ...
CVE-2022-32143HIGH8.8In multiple CODESYS products, file download and upload function allows access to internal files in the working directory...
CVE-2022-32142HIGH8.1Multiple CODESYS Products are prone to a out-of bounds read or write access. A low privileged remote attacker may craft ...
CVE-2022-32138HIGH8.8In multiple CODESYS products, a remote attacker may craft a request which may cause an unexpected sign extension, result...
CVE-2022-32137HIGH8.8In multiple CODESYS products, a low privileged remote attacker may craft a request, which may cause a heap-based buffer ...
CVE-2022-31805HIGH7.5In the CODESYS Development System multiple components in multiple versions transmit the passwords for the communication ...
CVE-2022-31804HIGH7.5The CODESYS Gateway Server V2 does not verifiy that the size of a request is within expected limits. An unauthenticated ...
CVE-2022-1965HIGH8.1Multiple products of CODESYS implement a improper error handling. A low privilege remote attacker may craft a request, w...
CVE-2022-32405HIGH8.8Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/adm...
CVE-2022-32404HIGH8.8Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/adm...
CVE-2022-32403HIGH8.8Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/adm...
CVE-2022-32402HIGH8.8Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/adm...
CVE-2022-32401HIGH8.8Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/adm...
CVE-2022-32400HIGH7.2Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/adm...
CVE-2022-32399HIGH8.8Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/adm...
CVE-2022-32398HIGH8.8Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/adm...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now