2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2022-29534HIGH7.5An issue was discovered in MISP before 2.4.158. In UsersController.php, password confirmation can be bypassed via vector...
CVE-2022-24872HIGH8.1Shopware is an open commerce platform based on Symfony Framework and Vue. Permissions set to sales channel context by ad...
CVE-2022-24862HIGH7.7Databasir is a team-oriented relational database model document management platform. Databasir 1.01 has Server-Side Requ...
CVE-2022-24861HIGH8.8Databasir is a team-oriented relational database model document management platform. Databasir 1.01 has remote code exec...
CVE-2022-26516HIGH7.8Authorized users may install a maliciously modified package file when updating the device via the web user interface. Th...
CVE-2022-25343HIGH7.5An issue was discovered on Olivetti d-COLOR MF3555 2XD_S000.002.271 devices. The Web Application is affected by Denial o...
CVE-2022-25342HIGH8.1An issue was discovered on Olivetti d-COLOR MF3555 2XD_S000.002.271 devices. The Web Application is affected by Broken A...
CVE-2022-29527HIGH7Amazon AWS amazon-ssm-agent before 3.1.1208.0 creates a world-writable sudoers file, which allows local attackers to inj...
CVE-2022-28327HIGH7.5The generic P-256 feature in crypto/elliptic in Go before 1.17.9 and 1.18.x before 1.18.1 allows a panic via long scalar...
CVE-2022-27536HIGH7.5Certificate.Verify in crypto/x509 in Go 1.18.x before 1.18.1 can be caused to panic on macOS when presented with certain...
CVE-2022-24675HIGH7.5encoding/pem in Go before 1.17.9 and 1.18.x before 1.18.1 has a Decode stack overflow via a large amount of PEM data.
CVE-2022-29266HIGH7.5In APache APISIX before 3.13.1, the jwt-auth plugin has a security issue that leaks the user's secret key because the er...
CVE-2022-27629HIGH8.8Cross-site request forgery (CSRF) vulnerability in 'MicroPayments - Paid Author Subscriptions, Content, Downloads, Membe...
CVE-2022-24826HIGH7.8On Windows, if Git LFS operates on a malicious repository with a `..exe` file as well as a file named `git.exe`, and `gi...
CVE-2022-0071HIGH8.8Incomplete fix for CVE-2021-3101. Hotdog, prior to v1.0.2, did not mimic the resource limits, device restrictions, or sy...
CVE-2022-0070HIGH8.8Incomplete fix for CVE-2021-3100. The Apache Log4j hotpatch package starting with log4j-cve-2021-44228-hotpatch-1.1-16 w...
CVE-2022-27527HIGH7.8A Memory Corruption vulnerability may lead to code execution through maliciously crafted DLL files. It was fixed in PDFT...
CVE-2022-25788HIGH7.8A maliciously crafted JT file in Autodesk AutoCAD 2022 may be used to write beyond the allocated buffer while parsing JT...
CVE-2022-21497HIGH8.1Vulnerability in the Oracle Web Services Manager product of Oracle Fusion Middleware (component: Web Services Security)....
CVE-2022-21491HIGH7.8Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that...
CVE-2022-21476HIGH7.5Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries)....
CVE-2022-21466HIGH7.5Vulnerability in the Oracle Commerce Guided Search product of Oracle Commerce (component: Tools and Frameworks). The sup...
CVE-2022-21464HIGH8.2Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Business Logic Infra SEC). ...
CVE-2022-21449HIGH7.5Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries)....
CVE-2022-21446HIGH8.2Vulnerability in the Oracle Solaris product of Oracle Systems (component: Utility). The supported version that is affect...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now