2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-25790 | HIGH | 7.8 | 1.4% | Apr 11, 2022 | A maliciously crafted DWF file in Autodesk AutoCAD 2022, 2021, 2020, 2019 and Autodesk Navisworks 2022 can be used to wr... |
| CVE-2022-25789 | HIGH | 7.8 | 1.5% | Apr 11, 2022 | A maliciously crafted DWF, 3DS and DWFX files in Autodesk AutoCAD 2022, 2021, 2020, 2019 can be used to trigger use-afte... |
| CVE-2022-24815 | HIGH | 8.1 | 1.3% | Apr 11, 2022 | JHipster is a development platform to quickly generate, develop, & deploy modern web applications & microservice archite... |
| CVE-2022-22964 | HIGH | 7.8 | 0.2% | Apr 11, 2022 | VMware Horizon Agent for Linux (prior to 22.x) contains a local privilege escalation that allows a user to escalate to r... |
| CVE-2022-22962 | HIGH | 7.8 | 0.3% | Apr 11, 2022 | VMware Horizon Agent for Linux (prior to 22.x) contains a local privilege escalation as a user is able to change the def... |
| CVE-2022-22572 | HIGH | 8.8 | 2.4% | Apr 11, 2022 | A non-admin user with user management permission can escalate his privilege to admin user via password reset functionali... |
| CVE-2022-22257 | HIGH | 7.5 | 0.5% | Apr 11, 2022 | The customization framework has a vulnerability of improper permission control.Successful exploitation of this vulnerabi... |
| CVE-2022-22256 | HIGH | 7.5 | 0.7% | Apr 11, 2022 | The DFX module has an access control vulnerability.Successful exploitation of this vulnerability may affect data confide... |
| CVE-2022-22255 | HIGH | 7.5 | 0.7% | Apr 11, 2022 | The application framework has a common DoS vulnerability.Successful exploitation of this vulnerability may affect the av... |
| CVE-2022-22254 | HIGH | 7.5 | 0.7% | Apr 11, 2022 | A permission bypass vulnerability exists when the NFC CAs access the TEE.Successful exploitation of this vulnerability m... |
| CVE-2022-22253 | HIGH | 7.5 | 0.3% | Apr 11, 2022 | The DFX module has a vulnerability of improper validation of integrity check values.Successful exploitation of this vuln... |
| CVE-2022-1316 | HIGH | 7.8 | 0.4% | Apr 11, 2022 | Incorrect Permission Assignment for Critical Resource in GitHub repository zerotier/zerotierone prior to 1.8.8. Local Pr... |
| CVE-2022-1262 | HIGH | 7.8 | 2.2% | Apr 11, 2022 | A command injection vulnerability in the protest binary allows an attacker with access to the remote command line interf... |
| CVE-2022-0999 | HIGH | 8.8 | 1.3% | Apr 11, 2022 | An authenticated user may be able to misuse parameters to inject arbitrary operating system commands into mySCADA myPRO ... |
| CVE-2022-1023 | HIGH | 7.2 | 1.5% | Apr 11, 2022 | The Podcast Importer SecondLine WordPress plugin before 1.3.8 does not sanitise and properly escape some imported data, ... |
| CVE-2022-1008 | HIGH | 7.2 | 1.7% | Apr 11, 2022 | The One Click Demo Import WordPress plugin before 3.1.0 does not validate the imported file, allowing high privilege use... |
| CVE-2022-1006 | HIGH | 7.2 | 1.5% | Apr 11, 2022 | The Advanced Booking Calendar WordPress plugin before 1.7.1 does not sanitise and escape the id parameter when editing C... |
| CVE-2022-0989 | HIGH | 7.5 | 1.2% | Apr 11, 2022 | An unprivileged user could use the functionality of the NS WooCommerce Watermark WordPress plugin through 2.11.3 to load... |
| CVE-2022-0920 | HIGH | 7.5 | 1.4% | Apr 11, 2022 | The Salon booking system Free and Pro WordPress plugins before 7.6.3 do not have proper authorisation in some of its end... |
| CVE-2022-0828 | HIGH | 7.5 | 1.5% | Apr 11, 2022 | The Download Manager WordPress plugin before 3.2.34 uses the uniqid php function to generate the master key for a downlo... |
| CVE-2022-27089 | HIGH | 7.8 | 0.2% | Apr 11, 2022 | In Fujitsu PlugFree Network <= 7.3.0.3, an Unquoted service path in PFNService.exe software allows a local attacker to p... |
| CVE-2022-27088 | HIGH | 7.8 | 0.6% | Apr 11, 2022 | Ivanti DSM Remote <= 6.3.1.1862 is vulnerable to an unquoted service path allowing local users to launch processes with ... |
| CVE-2022-27041 | HIGH | 7.5 | 1.3% | Apr 11, 2022 | Due to lack of protection, parameter student_id in OpenSIS Classic 8.0 /modules/eligibility/Student.php can be used to i... |
| CVE-2022-26413 | HIGH | 8 | 0.7% | Apr 11, 2022 | A command injection vulnerability in the CGI program of Zyxel VMG3312-T20A firmware version 5.30(ABFX.5)C0 could allow a... |
| CVE-2022-0556 | HIGH | 7.8 | 0.3% | Apr 11, 2022 | A local privilege escalation vulnerability caused by incorrect permission assignment in some directories of the Zyxel AP... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now