2022 CVE Vulnerabilities

27,525 CVEs published in 2022.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2022-44371CRITICAL9.8hope-boot 1.0.0 has a deserialization vulnerability that can cause Remote Code Execution (RCE).
CVE-2022-42458CRITICAL9.8Authentication bypass using an alternate path or channel vulnerability in bingo!CMS version1.7.4.1 and earlier allows a ...
CVE-2022-46742CRITICAL9.8Code injection in paddle.audio.functional.get_window in PaddlePaddle 2.4.0-rc0 allows arbitrary code execution.
CVE-2022-46741CRITICAL9.1Out-of-bounds read in gather_tree in PaddlePaddle before 2.4. 
CVE-2022-45026CRITICAL9.8An issue in Markdown Preview Enhanced v0.6.5 and v0.19.6 for VSCode and Atom allows attackers to execute arbitrary comma...
CVE-2022-45025CRITICAL9.8Markdown Preview Enhanced v0.6.5 and v0.19.6 for VSCode and Atom was discovered to contain a command injection vulnerabi...
CVE-2022-45010CRITICAL9.8Simple Phone Book/Directory Web App v1.0 was discovered to contain a SQL injection vulnerability via the editid paramete...
CVE-2022-41910CRITICAL9.1TensorFlow is an open source platform for machine learning. The function MakeGrapplerFunctionItem takes arguments that d...
CVE-2022-41902CRITICAL9.1TensorFlow is an open source platform for machine learning. The function MakeGrapplerFunctionItem takes arguments that d...
CVE-2022-45359CRITICAL9.8Unauth. Arbitrary File Upload vulnerability in YITH WooCommerce Gift Cards premium plugin <= 3.19.0 on WordPress.
CVE-2022-46332CRITICAL9.6The Admin Smart Search feature in Proofpoint Enterprise Protection (PPS/PoD) contains a stored cross-site scripting vuln...
CVE-2022-44900CRITICAL9.1A directory traversal vulnerability in the SevenZipFile.extractall() function of the python library py7zr v0.20.0 and ea...
CVE-2022-46161CRITICAL9.8pdfmake is an open source client/server side PDF printing in pure JavaScript. In versions up to and including 0.2.5 pdfm...
CVE-2022-41559CRITICAL9.3The Web Client component of TIBCO Software Inc.'s TIBCO Nimbus contains an easily exploitable vulnerability that allows ...
CVE-2022-35843CRITICAL9.8An authentication bypass by assumed-immutable data vulnerability [CWE-302] in the FortiOS SSH login component 7.2.0, 7....
CVE-2022-46383CRITICAL9.8RackN Digital Rebar through 4.6.14, 4.7 through 4.7.22, 4.8 through 4.8.5, 4.9 through 4.9.12, and 4.10 through 4.10.8 h...
CVE-2022-25912CRITICAL9.8The package simple-git before 3.15.0 are vulnerable to Remote Code Execution (RCE) when enabling the ext transport proto...
CVE-2022-24439CRITICAL9.8All versions of package gitpython are vulnerable to Remote Code Execution (RCE) due to improper user input validation, w...
CVE-2022-40918CRITICAL9.8Buffer overflow in firmware lewei_cam binary version 2.0.10 in Force 1 Discovery Wifi U818A HD+ FPV Drone allows attacke...
CVE-2022-38337CRITICAL9.1When aborting a SFTP connection, MobaXterm before v22.1 sends a hardcoded password to the server. The server treats this...
CVE-2022-43549CRITICAL9.8Improper authentication in Veeam Backup for Google Cloud v1.0 and v3.0 allows attackers to bypass authentication mechani...
CVE-2022-40259CRITICAL9.8MegaRAC Default Credentials Vulnerability
CVE-2022-40242CRITICAL9.8MegaRAC Default Credentials Vulnerability
CVE-2022-35255CRITICAL9.1A weak randomness in WebCrypto keygen vulnerability exists in Node.js 18 due to a change with EntropySource() in SecretK...
CVE-2022-32224CRITICAL9.8A possible escalation to RCE vulnerability exists when using YAML serialized columns in Active Record < 7.0.3.1, <6.1.6....

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now