2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2022-1459HIGH8.3Non-Privilege User Can View Patient’s Disclosures in GitHub repository openemr/openemr prior to 6.1.0.1.
CVE-2022-29603HIGH8.1A SQL Injection vulnerability exists in UniverSIS UniverSIS-API through 1.2.1 via the $select parameter to multiple API ...
CVE-2022-29546HIGH7.5HtmlUnit NekoHtml Parser before 2.61.0 suffers from a denial of service vulnerability. Crafted input associated with the...
CVE-2022-1452HIGH7.1Out-of-bounds Read in r_bin_java_bootstrap_methods_attr_new function in GitHub repository radareorg/radare2 prior to 5.7...
CVE-2022-1451HIGH7.1Out-of-bounds Read in r_bin_java_constant_value_attr_new function in GitHub repository radareorg/radare2 prior to 5.7.0....
CVE-2022-1427HIGH7.8Out-of-bounds Read in mrb_obj_is_kind_of in in GitHub repository mruby/mruby prior to 3.2. # Impact: Possible arbitrary ...
CVE-2022-0354HIGH7.8A vulnerability was reported in Lenovo System Update that could allow a local user with interactive system access the ab...
CVE-2022-0192HIGH7.8A DLL search path vulnerability was reported in Lenovo PCManager prior to version 4.0.40.2175 that could allow privilege...
CVE-2022-27340HIGH8.8MCMS v5.2.7 contains a Cross-Site Request Forgery (CSRF) via /role/saveOrUpdateRole.do. This vulnerability allows attack...
CVE-2022-29583HIGH7.8service_windows.go in the kardianos service package for Go omits quoting that is sometimes needed for execution of a Win...
CVE-2022-29582HIGH7In the Linux kernel before 5.17.3, fs/io_uring.c has a use-after-free due to a race condition in io_uring timeouts. This...
CVE-2022-1437HIGH7.1Heap-based Buffer Overflow in GitHub repository radareorg/radare2 prior to 5.7.0. The bug causes the program reads data ...
CVE-2022-27406HIGH7.5FreeType commit 22a0cccb4d9d002f33c1ba7a4b36812c7d4f46b5 was discovered to contain a segmentation violation via the func...
CVE-2022-27405HIGH7.5FreeType commit 53dfdcd8198d2b3201a23c4bad9190519ba918db was discovered to contain a segmentation violation via the func...
CVE-2022-1429HIGH7.5SQL injection in GridHelperService.php in GitHub repository pimcore/pimcore prior to 10.3.6. This vulnerability is capab...
CVE-2022-28366HIGH7.5Certain Neko-related HTML parsers allow a denial of service via crafted Processing Instruction (PI) input that causes ex...
CVE-2022-26856HIGH7.8Dell EMC Repository Manager version 3.4.0 contains a plain-text password storage vulnerability. A local attacker could p...
CVE-2022-24424HIGH7.5Dell EMC AppSync versions from 3.9 to 4.3 contain a path traversal vulnerability in AppSync server. A remote unauthentic...
CVE-2022-24423HIGH7.5Dell iDRAC8 versions prior to 2.83.83.83 contain a denial of service vulnerability. A remote unauthenticated attacker co...
CVE-2022-28444HIGH7.5UCMS v1.6 was discovered to contain an arbitrary file read vulnerability.
CVE-2022-28440HIGH8.8An arbitrary file upload vulnerability in UCMS v1.6 allows attackers to execute arbitrary code via a crafted PHP file.
CVE-2022-28020HIGH8.8Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\posi...
CVE-2022-28019HIGH8.8Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\empl...
CVE-2022-28018HIGH8.8Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\sche...
CVE-2022-28017HIGH8.8Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\over...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now