2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2022-21442HIGH8.8Vulnerability in Oracle GoldenGate (component: OGG Core Library). The supported version that is affected is Prior to 23....
CVE-2022-21441HIGH7.5Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions th...
CVE-2022-21430HIGH8.5Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications Applications ...
CVE-2022-21424HIGH8.3Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications Applications ...
CVE-2022-21422HIGH7.5Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications Applications ...
CVE-2022-21421HIGH7.5Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Ana...
CVE-2022-21410HIGH7.2Vulnerability in the Oracle Database - Enterprise Edition Sharding component of Oracle Database Server. The supported ve...
CVE-2022-21404HIGH8.1Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Reactive WebServer). Supported versions tha...
CVE-2022-1384HIGH8.8Mattermost version 6.4.x and earlier fails to properly check the plugin version when a plugin is installed from the Mark...
CVE-2022-1329HIGH8.8The Elementor Website Builder plugin for WordPress is vulnerable to unauthorized execution of several AJAX actions due t...
CVE-2022-1119HIGH7.5The Simple File List WordPress plugin is vulnerable to Arbitrary File Download via the eeFile parameter found in the ~/i...
CVE-2022-27055HIGH7.5ecjia-daojia 1.38.1-20210202629 is vulnerable to information leakage via content/apps/installer/classes/Helper.php. When...
CVE-2022-29153HIGH7.5HashiCorp Consul and Consul Enterprise up to 1.9.16, 1.10.9, and 1.11.4 may allow server side request forgery when the C...
CVE-2022-29315HIGH8.8Invicti Acunetix before 14 allows CSV injection via the Description field on the Add Targets page, if the Export CSV fea...
CVE-2022-1065HIGH8.8A vulnerability within the authentication process of Abacus ERP allows a remote attacker to bypass the second authentica...
CVE-2022-28108HIGH8.8Selenium Server (Grid) before 4 allows CSRF because it permits non-JSON content types such as application/x-www-form-url...
CVE-2022-24841HIGH8.1fleetdm/fleet is an open source device management, built on osquery. All versions of fleet making use of the teams featu...
CVE-2022-29458HIGH7.1ncurses 6.3 before patch 20220416 has an out-of-bounds read and segmentation violation in convert_strings in tinfo/read_...
CVE-2022-29457HIGH8.8Zoho ManageEngine ADSelfService Plus before 6121, ADAuditPlus 7060, Exchange Reporter Plus 5701, and ADManagerPlus 7131 ...
CVE-2022-24863HIGH7.5http-swagger is an open source wrapper to automatically generate RESTful API documentation with Swagger 2.0. In versions...
CVE-2022-1037HIGH7.2The EXMAGE WordPress plugin before 1.0.7 does to ensure that images added via URLs are external images, which could lead...
CVE-2022-0661HIGH7.2The Ad Injection WordPress plugin through 1.2.0.19 does not properly sanitize the body of the adverts injected into the ...
CVE-2022-27530HIGH7.8A maliciously crafted TIF or PICT file in Autodesk AutoCAD 2022, 2021, 2020, 2019 can be used to write beyond the alloca...
CVE-2022-27529HIGH7.8A maliciously crafted PICT, BMP, PSD or TIF file in Autodesk AutoCAD 2022, 2021, 2020, 2019 may be used to write beyond ...
CVE-2022-27526HIGH7.8A malicious crafted TGA file when consumed through DesignReview.exe application could lead to memory corruption vulnerab...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now