2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2022-2068HIGH7.3In addition to the c_rehash shell command injection identified in CVE-2022-1292, further circumstances where the c_rehas...
CVE-2022-27872HIGH7.8A maliciously crafted PDF file may be used to dereference a pointer for read or write operation while parsing PDF files ...
CVE-2022-27871HIGH7.8Autodesk AutoCAD product suite, Revit, Design Review and Navisworks releases using PDFTron prior to 9.1.17 version may b...
CVE-2022-27870HIGH7.8A maliciously crafted TGA file in Autodesk AutoCAD 2023 may be used to write beyond the allocated buffer while parsing T...
CVE-2022-27869HIGH7.8A maliciously crafted TIFF file in Autodesk AutoCAD 2023 can be forced to read and write beyond allocated boundaries whe...
CVE-2022-27868HIGH7.8A maliciously crafted CAT file in Autodesk AutoCAD 2023 can be used to trigger use-after-free vulnerability. Exploitatio...
CVE-2022-27867HIGH7.8A maliciously crafted JT file in Autodesk AutoCAD 2022, 2021, 2020, 2019 can be used to trigger use-after-free vulnerabi...
CVE-2022-23171HIGH8.8AtlasVPN - Privilege Escalation Lack of proper security controls on named pipe messages can allow an attacker with low p...
CVE-2022-22979HIGH7.5In Spring Cloud Function versions prior to 3.2.6, it is possible for a user who directly interacts with framework provid...
CVE-2022-1833HIGH8.8A flaw was found in AMQ Broker Operator 7.9.4 installed via UI using OperatorHub where a low-privilege user that has acc...
CVE-2022-1665HIGH8.2A set of pre-production kernel packages of Red Hat Enterprise Linux for IBM Power architecture can be booted by the grub...
CVE-2022-33056HIGH7.2Online Railway Reservation System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /...
CVE-2022-33055HIGH7.2Online Railway Reservation System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /...
CVE-2022-33049HIGH7.2Online Railway Reservation System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /...
CVE-2022-33048HIGH7.2Online Railway Reservation System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /...
CVE-2022-33913HIGH7.5In Mahara 21.04 before 21.04.6, 21.10 before 21.10.4, and 22.04.2, files can sometimes be downloaded through thumb.php w...
CVE-2022-1720HIGH7.8Buffer Over-read in function grab_file_name in GitHub repository vim/vim prior to 8.2.4956. This vulnerability is capabl...
CVE-2022-1939HIGH7.2The Allow svg files WordPress plugin before 1.1 does not properly validate uploaded files, which could allow high privil...
CVE-2022-1824HIGH8.2An uncontrolled search path vulnerability in McAfee Consumer Product Removal Tool prior to version 10.4.128 could allow ...
CVE-2022-1823HIGH7.8Improper privilege management vulnerability in McAfee Consumer Product Removal Tool prior to version 10.4.128 could allo...
CVE-2022-1801HIGH7.5The Very Simple Contact Form WordPress plugin before 11.6 exposes the solution to the captcha in the rendered contact fo...
CVE-2022-1614HIGH7.5The WP-EMail WordPress plugin before 2.69.0 prioritizes getting a visitor's IP from certain HTTP headers over PHP's REMO...
CVE-2022-1472HIGH7.2The Better Find and Replace WordPress plugin before 1.3.6 does not properly sanitise, validate and escape various parame...
CVE-2022-34006HIGH7.8An issue was discovered in TitanFTP (aka Titan FTP) NextGen before 1.2.1050. When installing, Microsoft SQL Express 2019...
CVE-2022-2129HIGH7.8Out-of-bounds Write in GitHub repository vim/vim prior to 8.2.

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now