2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2022-22521HIGH7.3In Miele Benchmark Programming Tool with versions Prior to 1.2.71, executable files manipulated by attackers are unknowi...
CVE-2022-29505HIGH7.8Due to build misconfiguration in openssl dependency, LINE for Windows before 7.8 is vulnerable to DLL injection that cou...
CVE-2022-27905HIGH7.2In ControlUp Real-Time Agent before 8.6, an unquoted path can result in privilege escalation. An attacker would require ...
CVE-2022-27239HIGH7.8In cifs-utils through 6.14, a stack-based buffer overflow when parsing the mount.cifs ip= command-line argument could le...
CVE-2022-29701HIGH7.5A lack of rate limiting in the 'forgot password' feature of Zammad v5.1.0 allows attackers to send an excessive amount o...
CVE-2022-29700HIGH7.5A lack of password length restriction in Zammad v5.1.0 allows for the creation of extremely long passwords which can cau...
CVE-2022-28085HIGH7.8A flaw was found in htmldoc commit 31f7804. A heap buffer overflow in the function pdf_write_names in ps-pdf.cxx may lea...
CVE-2022-28918HIGH8.1GreenCMS v2.3.0603 was discovered to contain an arbitrary file deletion vulnerability via /index.php?m=admin&c=custom&a=...
CVE-2022-28528HIGH8.8bloofoxCMS v0.5.2.1 was discovered to contain an arbitrary file upload vulnerability via /admin/index.php?mode=content&p...
CVE-2022-28527HIGH8.1dhcms v20170919 was discovered to contain an arbitrary folder deletion vulnerability via /admin.php?r=admin/AdminBackup/...
CVE-2022-28525HIGH8.8ED01-CMS v20180505 was discovered to contain an arbitrary file upload vulnerability via /admin/users.php?source=edit_use...
CVE-2022-28523HIGH8.1HongCMS 3.0.0 allows arbitrary file deletion via the component /admin/index.php/template/ajax?action=delete.
CVE-2022-28059HIGH8.1Verydows v2.0 was discovered to contain an arbitrary file deletion vulnerability via \backend\database_controller.php.
CVE-2022-28058HIGH8.1Verydows v2.0 was discovered to contain an arbitrary file deletion vulnerability via \backend\file_controller.php.
CVE-2022-24882HIGH7.5FreeRDP is a free implementation of the Remote Desktop Protocol (RDP). In versions prior to 2.7.0, NT LAN Manager (NTLM)...
CVE-2022-23942HIGH7.5Apache Doris, prior to 1.0.0, used a hardcoded key and IV to initialize the cipher used for ldap password, which may lea...
CVE-2022-29419HIGH8.8SQL Injection (SQLi) vulnerability in Don Crowther's 3xSocializer plugin <= 0.98.22 at WordPress possible for users with...
CVE-2022-1441HIGH7.8MP4Box is a component of GPAC-2.0.0, which is a widely-used third-party package on RPM Fusion. When MP4Box tries to pars...
CVE-2022-24792HIGH7.5PJSIP is a free and open source multimedia communication library written in C. A denial-of-service vulnerability affects...
CVE-2022-22392HIGH7.8IBM Planning Analytics Local 2.0 could allow an attacker to upload arbitrary executable files which, when executed by an...
CVE-2022-1392HIGH7.5The Videos sync PDF WordPress plugin through 1.7.4 does not validate the p parameter before using it in an include state...
CVE-2022-0656HIGH7.5The Web To Print Shop : uDraw WordPress plugin before 3.3.3 does not validate the url parameter in its udraw_convert_url...
CVE-2022-26111HIGH8.8The BeanShell components of IRISNext through 9.8.28 allow execution of arbitrary commands on the target server by creati...
CVE-2022-28053HIGH8.8Typemill v1.5.3 was discovered to contain an arbitrary file upload vulnerability via the upload function. This vulnerabi...
CVE-2022-28871HIGH7.5A Denial-of-Service (DoS) vulnerability was discovered in F-Secure Atlant whereby the fsicapd component used in certain ...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now