2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2022-32397HIGH8.8Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/adm...
CVE-2022-32396HIGH8.8Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/adm...
CVE-2022-32395HIGH8.8Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/adm...
CVE-2022-32394HIGH8.8Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/adm...
CVE-2022-32393HIGH8.8Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/adm...
CVE-2022-32392HIGH8.8Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/adm...
CVE-2022-32391HIGH8.8Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/adm...
CVE-2022-2147HIGH7.8Cloudflare Warp for Windows from version 2022.2.95.0 contained an unquoted service path which enables arbitrary code exe...
CVE-2022-2183HIGH7.8Out-of-bounds Read in GitHub repository vim/vim prior to 8.2.
CVE-2022-2182HIGH7.8Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.
CVE-2022-26864HIGH7.8Prior Dell BIOS versions contain an Input Validation vulnerability. A locally authenticated malicious user could potenti...
CVE-2022-26863HIGH7.8Prior Dell BIOS versions contain an Input Validation vulnerability. A locally authenticated malicious user could potenti...
CVE-2022-26862HIGH7.8Prior Dell BIOS versions contain an Input Validation vulnerability. A locally authenticated malicious user could potenti...
CVE-2022-34300HIGH8.8In tinyexr 1.0.1, there is a heap-based buffer over-read in tinyexr::DecodePixelData.
CVE-2022-34299HIGH8.1There is a heap-based buffer over-read in libdwarf 0.4.0. This issue is related to dwarf_global_formref_b.
CVE-2022-34296HIGH7.5In Zalando Skipper before 0.13.218, a query predicate could be bypassed via a prepared request.
CVE-2022-34203HIGH8.8A cross-site request forgery (CSRF) vulnerability in Jenkins EasyQA Plugin 1.0 and earlier allows attackers to connect t...
CVE-2022-34200HIGH8.8A cross-site request forgery (CSRF) vulnerability in Jenkins Convertigo Mobile Platform Plugin 1.1 and earlier allows at...
CVE-2022-34180HIGH7.5Jenkins Embeddable Build Status Plugin 2.0.3 and earlier does not correctly perform the ViewStatus permission check in t...
CVE-2022-34179HIGH7.5Jenkins Embeddable Build Status Plugin 2.0.3 and earlier allows specifying a `style` query parameter that is used to cho...
CVE-2022-34177HIGH7.5Jenkins Pipeline: Input Step Plugin 448.v37cea_9a_10a_70 and earlier archives files uploaded for `file` parameters for P...
CVE-2022-34175HIGH7.5Jenkins 2.335 through 2.355 (both inclusive) allows attackers in some cases to bypass a protection mechanism, thereby di...
CVE-2022-34174HIGH7.5In Jenkins 2.355 and earlier, LTS 2.332.3 and earlier, an observable timing discrepancy on the login form allows disting...
CVE-2022-33114HIGH7.2Jfinal CMS v5.1.0 was discovered to contain a SQL injection vulnerability via the attrVal parameter at /jfinal_cms/syste...
CVE-2022-33105HIGH7.5Redis v7.0 was discovered to contain a memory leak via the component streamGetEdgeID.

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now