2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2022-29662HIGH7.2CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the id parameter at /admin.ph...
CVE-2022-29661HIGH7.2CSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at /ad...
CVE-2022-29721HIGH7.574cmsSE v3.5.1 was discovered to contain a SQL injection vulnerability via the keyword parameter at /home/jobfairol/resu...
CVE-2022-29720HIGH7.574cmsSE v3.5.1 was discovered to contain an arbitrary file read vulnerability via the component \index\controller\Downlo...
CVE-2022-27169HIGH7.5An information disclosure vulnerability exists in the OAS Engine SecureBrowseFile functionality of Open Automation Softw...
CVE-2022-26303HIGH7.5An external config control vulnerability exists in the OAS Engine SecureAddUser functionality of Open Automation Softwar...
CVE-2022-26077HIGH7.5A cleartext transmission of sensitive information vulnerability exists in the OAS Engine configuration communications fu...
CVE-2022-26067HIGH7.5An information disclosure vulnerability exists in the OAS Engine SecureTransferFiles functionality of Open Automation So...
CVE-2022-26043HIGH7.5An external config control vulnerability exists in the OAS Engine SecureAddSecurity functionality of Open Automation Sof...
CVE-2022-26026HIGH7.5A denial of service vulnerability exists in the OAS Engine SecureConfigValues functionality of Open Automation Software ...
CVE-2022-29248HIGH8.1Guzzle is a PHP HTTP client. Guzzle prior to versions 6.5.6 and 7.4.3 contains a vulnerability with the cookie middlewar...
CVE-2022-30428HIGH7.5In ginadmin through 05-10-2022, the incoming path value is not filtered, resulting in arbitrary file reading.
CVE-2022-30427HIGH7.5In ginadmin through 05-10-2022 the incoming path value is not filtered, resulting in directory traversal.
CVE-2022-27305HIGH8.8Gibbon v23 does not generate a new session ID cookie after a user authenticates, making the application vulnerable to se...
CVE-2022-1678HIGH7.5An issue was discovered in the Linux Kernel from 4.18 to 4.19, an improper update of sock reference in TCP pacing can le...
CVE-2022-22127HIGH7.2Tableau is aware of a broken access control vulnerability present in Tableau Server affecting Tableau Server customers u...
CVE-2022-29651HIGH7.2An arbitrary file upload vulnerability in the Select Image function of Online Food Ordering System v1.0 allows attackers...
CVE-2022-1851HIGH7.8Out-of-bounds Read in GitHub repository vim/vim prior to 8.2.
CVE-2022-30323HIGH8.6go-getter up to 1.5.11 and 2.0.2 panicked when processing password-protected ZIP files. Fixed in 1.6.1 and 2.1.0.
CVE-2022-30322HIGH8.6go-getter up to 1.5.11 and 2.0.2 allowed asymmetric resource exhaustion when go-getter processed malicious HTTP response...
CVE-2022-30321HIGH8.6go-getter up to 1.5.11 and 2.0.2 allowed arbitrary host access via go-getter path traversal, symlink processing, and com...
CVE-2022-1883HIGH8.8SQL Injection in GitHub repository camptocamp/terraboard prior to 2.2.0.
CVE-2022-1815HIGH7.5Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository jgraph/drawio prior to 18.1.2.
CVE-2022-22497HIGH7.5IBM Aspera Faspex 4.4.1 and 5.0.0 could allow unauthorized access due to an incorrectly computed security token. IBM X-F...
CVE-2022-29333HIGH7.8A vulnerability in CyberLink Power Director v14 allows attackers to escalate privileges via a crafted .exe file.

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now