2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2022-27525HIGH7.8A malicious crafted .dwf or .pct file when consumed through DesignReview.exe application could lead to memory corruption...
CVE-2022-23976HIGH8.1Cross-Site Request Forgery (CSRF) in Access Demo Importer <= 1.0.7 on WordPress allows an attacker to reset all data (po...
CVE-2022-1341HIGH7.5An issue was discovered in in bwm-ng v0.6.2. An arbitrary null write exists in get_cmdln_options() function in src/optio...
CVE-2022-26665HIGH7.5An Insecure Direct Object Reference issue exists in the Tyler Odyssey Portal platform before 17.1.20. This may allow an ...
CVE-2022-27908HIGH8.8Zoho ManageEngine OpManager before 125588 (and before 125603) is vulnerable to authenticated SQL Injection in the Invent...
CVE-2022-1381HIGH7.8global heap buffer overflow in skip_range in GitHub repository vim/vim prior to 8.2.4763. This vulnerability is capable ...
CVE-2022-29281HIGH8.8Notable before 1.9.0-beta.8 doesn't effectively prevent the opening of executable files when clicking on a link. There i...
CVE-2022-29072HIGH7.87-Zip through 21.07 on Windows allows privilege escalation and command execution when a file with the .7z extension is d...
CVE-2022-27426HIGH8.8A Server-Side Request Forgery (SSRF) in Chamilo LMS v1.11.13 allows attackers to enumerate the internal network and exec...
CVE-2022-27421HIGH7.2Chamilo LMS v1.11.13 lacks validation on the user modification form, allowing attackers to escalate privileges to Platfo...
CVE-2022-24279HIGH7.5The package madlib-object-utils before 0.1.8 are vulnerable to Prototype Pollution via the setValue method, as it allows...
CVE-2022-28113HIGH7.2An issue in upload.csp of FANTEC GmbH MWiD25-DS Firmware v2.000.030 allows attackers to write files and reset the user p...
CVE-2022-27048HIGH7.4A vulnerability has been discovered in Moxa MGate which allows an attacker to perform a man-in-the-middle (MITM) attack ...
CVE-2022-26924HIGH7.5YARP Denial of Service Vulnerability
CVE-2022-26921HIGH7.3Visual Studio Code Elevation of Privilege Vulnerability
CVE-2022-26919HIGH8.1Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
CVE-2022-26918HIGH7.8Windows Fax Compose Form Remote Code Execution Vulnerability
CVE-2022-26917HIGH7.8Windows Fax Compose Form Remote Code Execution Vulnerability
CVE-2022-26916HIGH7.8Windows Fax Compose Form Remote Code Execution Vulnerability
CVE-2022-26915HIGH7.5Windows Secure Channel Denial of Service Vulnerability
CVE-2022-26914HIGH7.8Win32k Elevation of Privilege Vulnerability
CVE-2022-26904HIGH7Windows User Profile Service Elevation of Privilege Vulnerability
CVE-2022-26903HIGH7.8Windows Graphics Component Remote Code Execution Vulnerability
CVE-2022-26901HIGH7.8Microsoft Excel Remote Code Execution Vulnerability
CVE-2022-26898HIGH7.2Azure Site Recovery Remote Code Execution Vulnerability

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now