2022 CVE Vulnerabilities

27,525 CVEs published in 2022.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2022-50901HIGH7.8Wondershare Dr.Fone 11.4.9 contains an unquoted service path vulnerability in the DFWSIDService that allows local users ...
CVE-2022-50900HIGH7.8Wondershare Dr.Fone 12.0.18 contains an unquoted service path vulnerability that allows local users to execute arbitrary...
CVE-2022-50899HIGH8.7Geonetwork 3.10 through 4.2.0 contains an XML external entity vulnerability in PDF rendering that allows attackers to re...
CVE-2022-50898HIGH8.8NanoCMS 0.4 contains an authenticated file upload vulnerability that allows remote code execution through unvalidated pa...
CVE-2022-50897HIGH8.7mPDF 7.0 contains a local file inclusion vulnerability that allows attackers to read arbitrary system files by manipulat...
CVE-2022-50894HIGH7.1VIAVIWEB Wallpaper Admin 1.0 contains an SQL injection vulnerability that allows authenticated attackers to manipulate d...
CVE-2022-50890HIGH8.7Owlfiles File Manager 12.0.1 contains a path traversal vulnerability in its built-in HTTP server that allows attackers t...
CVE-2022-50808HIGH8.5CoolerMaster MasterPlus 1.8.5 contains an unquoted service path vulnerability in the MPService that allows local attacke...
CVE-2022-50806HIGH8.64images 1.9 contains a remote command execution vulnerability that allows authenticated administrators to inject reverse...
CVE-2022-50805HIGH8.8Senayan Library Management System 9.0.0 contains a SQL injection vulnerability in the 'class' parameter that allows atta...
CVE-2022-50693HIGH8.5Splashtop 8.71.12001.0 contains an unquoted service path vulnerability in the Splashtop Software Updater Service that al...
CVE-2022-50804HIGH8.8JM-DATA ONU JF511-TV version 1.0.67 is vulnerable to cross-site request forgery (CSRF) attacks, allowing attackers to pe...
CVE-2022-50800HIGH7.5H3C SSL VPN contains a user enumeration vulnerability that allows attackers to identify valid usernames through the 'txt...
CVE-2022-50799HIGH7.5Fetch FTP Client 5.8.2 contains a denial of service vulnerability that allows attackers to trigger 100% CPU consumption ...
CVE-2022-50795HIGH8.5SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x contains a conditional command injection vulnerability that allows local authenticat...
CVE-2022-50793HIGH8.8SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x contains an authenticated command injection vulnerability in the www-data-handler.ph...
CVE-2022-50792HIGH8.7SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and below contain an unauthenticated file disclosure vulnerability that allow...
CVE-2022-50791HIGH8.5SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x contains a conditional command injection vulnerability that allows local authenticat...
CVE-2022-50790HIGH7.5SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and below contain an unauthenticated vulnerability that allows remote attacke...
CVE-2022-50789HIGH8.5SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x contains a command injection vulnerability that allows local authenticated users to ...
CVE-2022-50788HIGH7.5SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x contains an information disclosure vulnerability that allows unauthenticated attacke...
CVE-2022-50787HIGH7.2SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x contains an unauthenticated stored cross-site scripting vulnerability in the ...
CVE-2022-50695HIGH8.7SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x contains a network vulnerability that allows unauthenticated attackers to sen...
CVE-2022-50692HIGH7.5SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and below contain an insufficient session expiration vulnerability that allow...
CVE-2022-50885HIGH7.5In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Fix NULL-ptr-deref in rxe_qp_do_cleanup()...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now