2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2022-31028HIGH7.5MinIO is a multi-cloud object storage solution. Starting with version RELEASE.2019-09-25T18-25-51Z and ending with versi...
CVE-2022-29564HIGH7.5Jamf Private Access before 2022-05-16 has Incorrect Access Control, in which an unauthorized user can reach a system in ...
CVE-2022-27438HIGH8.1Caphyon Ltd Advanced Installer 19.3 and earlier and many products that use the updater from Advanced Installer (Advanced...
CVE-2022-30469HIGH8.8In Afian Filerun 20220202, lack of sanitization of the POST parameter "metadata[]" in `/?module=fileman&section=get&page...
CVE-2022-29631HIGH7.5Jodd HTTP v6.0.9 was discovered to contain multiple CLRF injection vulnerabilities via the components jodd.http.HttpRequ...
CVE-2022-30587HIGH7.5Gradle Enterprise through 2022.2.2 has Incorrect Access Control that leads to information disclosure.
CVE-2022-32275HIGH7.5Grafana 8.4.3 allows reading files via (for example) a /dashboard/snapshot/%7B%7Bconstructor.constructor'/.. /.. /.. /.....
CVE-2022-30586HIGH7.2Gradle Enterprise through 2022.2.2 has Incorrect Access Control that leads to code execution.
CVE-2022-22396HIGH7.5Credentials are printed in clear text in the IBM Spectrum Protect Plus 10.1.0.0 through 10.1.9.3 virgo log file in certa...
CVE-2022-23712HIGH7.5A Denial of Service flaw was discovered in Elasticsearch. Using this vulnerability, an unauthenticated attacker could fo...
CVE-2022-21757HIGH7.5In WIFI Firmware, there is a possible system crash due to a missing count check. This could lead to remote denial of ser...
CVE-2022-21745HIGH8.8In WIFI Firmware, there is a possible memory corruption due to a use after free. This could lead to remote escalation of...
CVE-2022-1680HIGH8.8An account takeover issue has been discovered in GitLab EE affecting all versions starting from 11.10 before 14.9.5, all...
CVE-2022-31486HIGH8.8An authenticated attacker can send a specially crafted route to the “edit_route.cgi” binary and have it execute shell co...
CVE-2022-31484HIGH7.5An unauthenticated attacker can send a specially crafted network packet to delete a user from the web interface. This vu...
CVE-2022-31483HIGH8.8An authenticated attacker can upload a file with a filename including “..” and “/” to achieve the ability to upload the ...
CVE-2022-31482HIGH7.5An unauthenticated attacker can send a specially crafted unauthenticated HTTP request to the device that can overflow a ...
CVE-2022-31480HIGH7.5An unauthenticated attacker could arbitrarily upload firmware files to the target device, ultimately causing a Denial-of...
CVE-2022-1944HIGH7.1When the feature is configured, improper authorization in the Interactive Web Terminal in GitLab CE/EE affecting all ver...
CVE-2022-30860HIGH7.2FUDforum 3.1.2 is vulnerable to Remote Code Execution through Upload File feature of File Administration System in Admin...
CVE-2022-32291HIGH8.8In Real Player through 20.1.0.312, attackers can execute arbitrary code by placing a UNC share pathname (for a DLL file)...
CVE-2022-29778HIGH8.8D-Link DIR-890L 1.20b01 allows attackers to execute arbitrary code due to the hardcoded option Wake-On-Lan for the param...
CVE-2022-26493HIGH8.8Xecurify's miniOrange Premium, Standard, and Enterprise Drupal SAML SP modules possess an authentication and authorizati...
CVE-2022-1987HIGH8.1Buffer Over-read in GitHub repository bfabiszewski/libmobi prior to 0.11.
CVE-2022-32268HIGH8.8StarWind SAN and NAS v0.2 build 1914 allow remote code execution. A flaw was found in REST API in StarWind Stack. REST c...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now