2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2022-30695HIGH7.8Local privilege escalation due to excessive permissions assigned to child processes. The following products are affected...
CVE-2022-1679HIGH7.8A use-after-free flaw was found in the Linux kernel’s Atheros wireless adapter driver in the way a user forces the ath9k...
CVE-2022-30523HIGH7.8Trend Micro Password Manager (Consumer) version 5.0.0.1266 and below is vulnerable to a Link Following Privilege Escalat...
CVE-2022-1721HIGH7.5Path Traversal in WellKnownServlet in GitHub repository jgraph/drawio prior to 18.0.5. Read local files of the web appli...
CVE-2022-1713HIGH7.5SSRF on /proxy in GitHub repository jgraph/drawio prior to 18.0.4. An attacker can make a request as the server and read...
CVE-2022-1409HIGH7.2The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.5.8 does not properly validate images, allowing high...
CVE-2022-1182HIGH8.8The Visual Slide Box Builder WordPress plugin through 3.2.9 does not sanitise and escape various parameters before using...
CVE-2022-1103HIGH8.8The Advanced Uploader WordPress plugin through 4.2 allows any authenticated users like subscriber to upload arbitrary fi...
CVE-2022-0573HIGH8.8JFrog Artifactory before 7.36.1 and 6.23.41, is vulnerable to Insecure Deserialization of untrusted data which can lead ...
CVE-2022-29623HIGH7.8An arbitrary file upload vulnerability in the file upload module of Express Connect-Multiparty 2.2.0 allows attackers to...
CVE-2022-30012HIGH7.5In the POST request of the appointment.php page of HMS v.0, there are SQL injection vulnerabilities in multiple paramete...
CVE-2022-30782HIGH7.5Openmoney API through 2020-06-29 uses the JavaScript Math.random function, which does not provide cryptographically secu...
CVE-2022-29588HIGH7.5Konica Minolta bizhub MFP devices before 2022-04-14 use cleartext password storage for the /var/log/nginx/html/ADMINPASS...
CVE-2022-29586HIGH7.4Konica Minolta bizhub MFP devices before 2022-04-14 allow a Sandbox Escape. An attacker must attach a keyboard to a USB ...
CVE-2022-30781HIGH7.5Gitea before 1.16.7 does not escape git fetch remote.
CVE-2022-30763HIGH7.5Janet before 1.22.0 mishandles arrays.
CVE-2022-30049HIGH7.5A Server-Side Request Forgery (SSRF) in Rebuild v2.8.3 allows attackers to obtain the real IP address and scan Intranet ...
CVE-2022-28937HIGH7.5FISCO-BCOS release-3.0.0-rc2 was discovered to contain an issue where a malicious node, via an invalid proposal with an ...
CVE-2022-28936HIGH7.5FISCO-BCOS release-3.0.0-rc2 was discovered to contain an issue where a malicious node can trigger an integer overflow a...
CVE-2022-30708HIGH8.8Webmin through 1.991, when the Authentic theme is used, allows remote code execution when a user has been manually creat...
CVE-2022-25862HIGH7.5This affects the package sds from 0.0.0. The library could be tricked into adding or modifying properties of the Object....
CVE-2022-22281HIGH7.8A buffer overflow vulnerability in the SonicWall SSL-VPN NetExtender Windows Client (32 and 64 bit) in 10.2.322 and earl...
CVE-2022-1701HIGH7.5SonicWall SMA1000 series firmware 12.4.0, 12.4.1-02965 and earlier versions uses a shared and hard-coded encryption key ...
CVE-2022-22252HIGH7.5The DFX module has a UAF vulnerability.Successful exploitation of this vulnerability may affect system stability.
CVE-2022-30417HIGH7.2Covid-19 Travel Pass Management System v1.0 is vulnerable to SQL Injection via ctpms/admin/?page=user/manage_user&id=.

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now