2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2022-32992HIGH7.2Online Tours And Travels Management System v1.0 was discovered to contain a SQL injection vulnerability via the tname pa...
CVE-2022-32991HIGH8.8Web Based Quiz System v1.0 was discovered to contain a SQL injection vulnerability via the eid parameter at welcome.php.
CVE-2022-32302HIGH8.8Theme Park Ticketing System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at edit_ti...
CVE-2022-32300HIGH8.8YoudianCMS v9.5.0 was discovered to contain a SQL injection vulnerability via the MailSendID parameter at /App/Lib/Actio...
CVE-2022-32299HIGH8.8YoudianCMS v9.5.0 was discovered to contain a SQL injection vulnerability via the id parameter at /App/Lib/Action/Admin/...
CVE-2022-32157HIGH7.5Splunk Enterprise deployment servers in versions before 9.0 allow unauthenticated downloading of forwarder bundles. Reme...
CVE-2022-32156HIGH8.1In Splunk Enterprise and Universal Forwarder versions before 9.0, the Splunk command-line interface (CLI) did not valida...
CVE-2022-32155HIGH7.5In universal forwarder versions before 9.0, management services are available remotely by default. When not required, it...
CVE-2022-32154HIGH8.1Dashboards in Splunk Enterprise versions before 9.0 might let an attacker inject risky search commands into a form token...
CVE-2022-32153HIGH8.1Splunk Enterprise peers in Splunk Enterprise versions before 9.0 and Splunk Cloud Platform versions before 8.2.2203 did ...
CVE-2022-32152HIGH7.2Splunk Enterprise peers in Splunk Enterprise versions before 9.0 and Splunk Cloud Platform versions before 8.2.2203 did ...
CVE-2022-29437HIGH8.8Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in Image Slider by NextCode plugin <= 1.1.2 at WordPress.
CVE-2022-33140HIGH8.8The optional ShellUserGroupProvider in Apache NiFi 1.10.0 to 1.16.2 and Apache NiFi Registry 0.6.0 to 1.16.2 does not ne...
CVE-2022-20209HIGH7.5In hme_add_new_node_to_a_sorted_array of hme_utils.c, there is a possible out of bounds read due to a heap buffer overfl...
CVE-2022-20207HIGH7.8In static definitions of GattServiceConfig.java, there is a possible permission bypass due to an insecure default value....
CVE-2022-20204HIGH7.8In registerRemoteBugreportReceivers of DevicePolicyManagerService.java, there is a possible reporting of falsified bug r...
CVE-2022-20197HIGH7.8In recycle of Parcel.java, there is a possible way to start foreground activity from background due to a permissions byp...
CVE-2022-20194HIGH7.8In onCreate of ChooseLockGeneric.java, there is a possible permission bypass. This could lead to local escalation of pri...
CVE-2022-20193HIGH7.3In getUniqueUsagesWithLabels of PermissionUsageHelper.java, there is a possible incorrect permission attribution due to ...
CVE-2022-20192HIGH7.8In grantEmbeddedWindowFocus of WindowManagerService.java, there is a possible way to change an input channel for embedde...
CVE-2022-20190HIGH7.5Product: AndroidVersions: Android kernelAndroid ID: A-208744915References: N/A
CVE-2022-20188HIGH7.5Product: AndroidVersions: Android kernelAndroid ID: A-207254598References: N/A
CVE-2022-20186HIGH7.8In kbase_mem_alias of mali_kbase_mem_linux.c, there is a possible arbitrary code execution due to improper input validat...
CVE-2022-20184HIGH7.5Product: AndroidVersions: Android kernelAndroid ID: A-209153114References: N/A
CVE-2022-20181HIGH7.5Product: AndroidVersions: Android kernelAndroid ID: A-210936609References: N/A

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now