2022 CVE Vulnerabilities

27,525 CVEs published in 2022.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2022-23542CRITICAL9.8OpenFGA is an authorization/permission engine built for developers and inspired by Google Zanzibar. During an internal s...
CVE-2022-23537CRITICAL9.8PJSIP is a free and open source multimedia communication library written in C language implementing standard based proto...
CVE-2022-46020CRITICAL9.8WBCE CMS v1.5.4 can implement getshell by modifying the upload file type.
CVE-2022-46538CRITICAL9.8Tenda F1203 V2.0.1.6 was discovered to contain a command injection vulnerability via the mac parameter at /goform/WriteF...
CVE-2022-40624CRITICAL9.8pfSense pfBlockerNG through 2.1.4_27 allows remote attackers to execute arbitrary OS commands as root via the HTTP Host ...
CVE-2022-46421CRITICAL9.8Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Software Fou...
CVE-2022-25904CRITICAL9.8All versions of package safe-eval are vulnerable to Prototype Pollution which allows an attacker to add or modify proper...
CVE-2022-25171CRITICAL9.8The package p4 before 0.0.7 are vulnerable to Command Injection via the run() function due to improper input sanitizatio...
CVE-2022-44109CRITICAL9.8pdftojson commit 94204bb was discovered to contain a stack overflow via the component Stream::makeFilter(char*, Stream*,...
CVE-2022-44108CRITICAL9.8pdftojson commit 94204bb was discovered to contain a stack overflow via the component Object::copy(Object*):Object.cc.
CVE-2022-44940CRITICAL9.1Patchelf v0.9 was discovered to contain an out-of-bounds read via the function modifyRPath at src/patchelf.cc.
CVE-2022-40434CRITICAL9.8Softr v2.0 was discovered to be vulnerable to HTML injection via the Name field of the Account page.
CVE-2022-38708CRITICAL9.1 IBM Cognos Analytics 11.1.7 11.2.0, and 11.2.1 could be vulnerable to a Server-Side Request Forgery Attack (SSRF) attac...
CVE-2022-28173CRITICAL9.8The web server of some Hikvision wireless bridge products have an access control vulnerability which can be used to obta...
CVE-2022-4063CRITICAL9.8The InPost Gallery WordPress plugin before 2.1.4.1 insecurely uses PHP's extract() function when rendering HTML views, a...
CVE-2022-4050CRITICAL9.8The JoomSport WordPress plugin before 5.2.8 does not properly sanitise and escape a parameter before using it in a SQL s...
CVE-2022-4427CRITICAL9.8Improper Input Validation vulnerability in OTRS AG OTRS, OTRS AG ((OTRS)) Community Edition allows SQL Injection via Tic...
CVE-2022-44456CRITICAL9.8CONPROSYS HMI System (CHS) Ver.3.4.4?and earlier allows a remote unauthenticated attacker to execute an arbitrary OS com...
CVE-2022-4607CRITICAL9.8A vulnerability was found in 3D City Database OGC Web Feature Service up to 5.2.0. It has been rated as problematic. Thi...
CVE-2022-4606CRITICAL9.8PHP Remote File Inclusion in GitHub repository flatpressblog/flatpress prior to 1.3.
CVE-2022-4594CRITICAL9.8A vulnerability was found in drogatkin TJWS2. It has been declared as critical. Affected by this vulnerability is the fu...
CVE-2022-4592CRITICAL9.8A vulnerability was found in luckyshot CRMx and classified as critical. This issue affects the function get/save/delete/...
CVE-2022-37832CRITICAL9.8Mutiny 7.2.0-10788 suffers from Hardcoded root password.
CVE-2022-4566CRITICAL9.8A vulnerability, which was classified as critical, has been found in y_project RuoYi 4.7.5. This issue affects some unkn...
CVE-2022-42529CRITICAL9.8Product: AndroidVersions: Android kernelAndroid ID: A-235292841References: N/A

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now