2022 CVE Vulnerabilities

27,525 CVEs published in 2022.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2022-41653CRITICAL9.8Daikin SVMPC1 version 2.1.22 and prior and SVMPC2 version 1.2.3 and prior are vulnerable to an attacker obtaining user l...
CVE-2022-2757CRITICAL9.1 Due to the lack of adequately implemented access-control rules, all versions Kingspan TMS300 CS are vulnerable to an ...
CVE-2022-46404CRITICAL9.8A command injection vulnerability has been identified in Atos Unify OpenScape 4000 Assistant and Unify OpenScape 4000 Ma...
CVE-2022-45005CRITICAL9.8IP-COM EW9 V15.11.0.14(9732) was discovered to contain a command injection vulnerability in the cmd_get_ping_output func...
CVE-2022-4454CRITICAL9.8A vulnerability, which was classified as critical, has been found in m0ver bible-online. Affected by this issue is the f...
CVE-2022-46364CRITICAL9.8A SSRF vulnerability in parsing the href attribute of XOP:Include in MTOM requests in versions of Apache CXF before 3.5....
CVE-2022-27518CRITICAL9.8Unauthenticated remote arbitrary code execution
CVE-2022-46353CRITICAL9.8A vulnerability has been identified in SCALANCE X204RNA (HSR) (All versions < V3.2.7), SCALANCE X204RNA (PRP) (All versi...
CVE-2022-43724CRITICAL9.8A vulnerability has been identified in SICAM PAS/PQS (All versions < V7.0). Affected software transmits the database cre...
CVE-2022-20473CRITICAL9.8In toLanguageTag of LocaleListCache.cpp, there is a possible out of bounds read due to an incorrect bounds check. This c...
CVE-2022-20472CRITICAL9.8In toLanguageTag of LocaleListCache.cpp, there is a possible out of bounds read due to an incorrect bounds check. This c...
CVE-2022-4446CRITICAL9.8PHP Remote File Inclusion in GitHub repository tsolucio/corebos prior to 8.0.
CVE-2022-41271CRITICAL9.4An unauthenticated user can attach to an open interface exposed through JNDI by the Messaging System of SAP NetWeaver Pr...
CVE-2022-4314CRITICAL9.8Improper Privilege Management in GitHub repository ikus060/rdiffweb prior to 2.5.2.
CVE-2022-3982CRITICAL9.8The Booking calendar, Appointment Booking System WordPress plugin before 3.2.2 does not validate uploaded files, which c...
CVE-2022-3921CRITICAL9.8The Listingo WordPress theme before 3.2.7 does not validate files to be uploaded via an AJAX action available to unauthe...
CVE-2022-3915CRITICAL9.8The Dokan WordPress plugin before 3.7.6 does not properly sanitise and escape a parameter before using it in a SQL state...
CVE-2022-3900CRITICAL9.8The Cooked Pro WordPress plugin before 1.7.5.7 does not properly validate or sanitize the recipe_args parameter before u...
CVE-2022-38656CRITICAL9.8HCL Commerce, when using Elasticsearch, can allow a remote attacker to cause a denial of service attack on the site and ...
CVE-2022-37932CRITICAL9.8A potential security vulnerability has been identified in Hewlett Packard Enterprise OfficeConnect 1820, 1850, and 1920S...
CVE-2022-37897CRITICAL9.8There is a command injection vulnerability that could lead to unauthenticated remote code execution by sending specially...
CVE-2022-3485CRITICAL9.8In IFM Moneo Appliance with version up to 1.9.3 an unauthenticated remote attacker can reset the administrator password ...
CVE-2022-46682CRITICAL9.8Jenkins Plot Plugin 2.1.11 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
CVE-2022-4399CRITICAL9.8A vulnerability was found in TicklishHoneyBee nodau. It has been rated as critical. Affected by this issue is some unkno...
CVE-2022-45145CRITICAL9.8egg-compile.scm in CHICKEN 5.x before 5.3.1 allows arbitrary OS command execution during package installation via escape...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now