2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2022-29849HIGH7.8In Progress OpenEdge before 11.7.14 and 12.x before 12.2.9, certain SUID binaries within the OpenEdge application were s...
CVE-2022-28451HIGH7.5nopCommerce 4.50.1 is vulnerable to Directory Traversal via the backup file in the Maintenance feature.
CVE-2022-26068HIGH7.5This affects the package pistacheio/pistache before 0.0.3.20220425. It is possible to traverse directories to fetch arbi...
CVE-2022-25850HIGH7.5The package github.com/hoppscotch/proxyscotch before 1.0.0 are vulnerable to Server-side Request Forgery (SSRF) when int...
CVE-2022-25844HIGH7.5The package angular after 1.7.0 are vulnerable to Regular Expression Denial of Service (ReDoS) by providing a custom loc...
CVE-2022-25647HIGH7.5The package com.google.code.gson:gson before 2.8.9 are vulnerable to Deserialization of Untrusted Data via the writeRepl...
CVE-2022-25645HIGH8.1All versions of package dset are vulnerable to Prototype Pollution via 'dset/merge' mode, as the dset function checks fo...
CVE-2022-21227HIGH7.5The package sqlite3 before 5.0.3 are vulnerable to Denial of Service (DoS) which will invoke the toString function of th...
CVE-2022-21144HIGH7.5This affects all versions of package libxmljs. When invoking the libxmljs.parseXml function with a non-buffer argument t...
CVE-2022-1544HIGH7.8Formula Injection/CSV Injection due to Improper Neutralization of Formula Elements in CSV File in GitHub repository luya...
CVE-2022-28323HIGH7.5An issue was discovered in MediaWiki through 1.37.2. The SecurePoll extension allows a leak because sorting by timestamp...
CVE-2022-29265HIGH7.5Multiple components in Apache NiFi 0.0.1 to 1.16.0 do not restrict XML External Entity references in the default configu...
CVE-2022-29967HIGH7.5static_compressed_inmemory_website_callback.c in Glewlwyd through 2.6.2 allows directory traversal.
CVE-2022-29945HIGH7.5DJI drone devices sold in 2017 through 2022 broadcast unencrypted information about the drone operator's physical locati...
CVE-2022-1543HIGH8.8Improper handling of Length parameter in GitHub repository erudika/scoold prior to 1.49.4. When the text size is large e...
CVE-2022-29937HIGH8.8USU Oracle Optimization before 5.17.5 allows authenticated DataCollection users to achieve agent root access because som...
CVE-2022-29936HIGH8.8USU Oracle Optimization before 5.17 allows authenticated quantum users to achieve remote code execution because of /v2/q...
CVE-2022-29935HIGH7.5USU Oracle Optimization before 5.17.5 allows attackers to discover the quantum credentials via an agent-installer downlo...
CVE-2022-29934HIGH7.8USU Oracle Optimization before 5.17.5 lacks Polkit authentication, which allows smartcollector users to achieve root acc...
CVE-2022-29451HIGH8.8Cross-Site Request Forgery (CSRF) leading to Arbitrary File Upload vulnerability in Rara One Click Demo Import plugin <=...
CVE-2022-1403HIGH7.8ASDA-Soft: Version 5.4.1.0 and prior does not properly sanitize input while processing a specific project file, allowing...
CVE-2022-1402HIGH7.1ASDA-Soft: Version 5.4.1.0 and prior does not properly sanitize input while processing a specific project file, allowing...
CVE-2022-29856HIGH7.5A hardcoded cryptographic key in Automation360 22 allows an attacker to decrypt exported RPA packages.
CVE-2022-1353HIGH7.1A vulnerability was found in the pfkey_register function in net/key/af_key.c in the Linux kernel. This flaw allows a loc...
CVE-2022-1227HIGH8.8A privilege escalation flaw was found in Podman. This flaw allows an attacker to publish a malicious image to a public r...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now