2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2022-25790HIGH7.8A maliciously crafted DWF file in Autodesk AutoCAD 2022, 2021, 2020, 2019 and Autodesk Navisworks 2022 can be used to wr...
CVE-2022-25789HIGH7.8A maliciously crafted DWF, 3DS and DWFX files in Autodesk AutoCAD 2022, 2021, 2020, 2019 can be used to trigger use-afte...
CVE-2022-24815HIGH8.1JHipster is a development platform to quickly generate, develop, & deploy modern web applications & microservice archite...
CVE-2022-22964HIGH7.8VMware Horizon Agent for Linux (prior to 22.x) contains a local privilege escalation that allows a user to escalate to r...
CVE-2022-22962HIGH7.8VMware Horizon Agent for Linux (prior to 22.x) contains a local privilege escalation as a user is able to change the def...
CVE-2022-22572HIGH8.8A non-admin user with user management permission can escalate his privilege to admin user via password reset functionali...
CVE-2022-22257HIGH7.5The customization framework has a vulnerability of improper permission control.Successful exploitation of this vulnerabi...
CVE-2022-22256HIGH7.5The DFX module has an access control vulnerability.Successful exploitation of this vulnerability may affect data confide...
CVE-2022-22255HIGH7.5The application framework has a common DoS vulnerability.Successful exploitation of this vulnerability may affect the av...
CVE-2022-22254HIGH7.5A permission bypass vulnerability exists when the NFC CAs access the TEE.Successful exploitation of this vulnerability m...
CVE-2022-22253HIGH7.5The DFX module has a vulnerability of improper validation of integrity check values.Successful exploitation of this vuln...
CVE-2022-1316HIGH7.8Incorrect Permission Assignment for Critical Resource in GitHub repository zerotier/zerotierone prior to 1.8.8. Local Pr...
CVE-2022-1262HIGH7.8A command injection vulnerability in the protest binary allows an attacker with access to the remote command line interf...
CVE-2022-0999HIGH8.8An authenticated user may be able to misuse parameters to inject arbitrary operating system commands into mySCADA myPRO ...
CVE-2022-1023HIGH7.2The Podcast Importer SecondLine WordPress plugin before 1.3.8 does not sanitise and properly escape some imported data, ...
CVE-2022-1008HIGH7.2The One Click Demo Import WordPress plugin before 3.1.0 does not validate the imported file, allowing high privilege use...
CVE-2022-1006HIGH7.2The Advanced Booking Calendar WordPress plugin before 1.7.1 does not sanitise and escape the id parameter when editing C...
CVE-2022-0989HIGH7.5An unprivileged user could use the functionality of the NS WooCommerce Watermark WordPress plugin through 2.11.3 to load...
CVE-2022-0920HIGH7.5The Salon booking system Free and Pro WordPress plugins before 7.6.3 do not have proper authorisation in some of its end...
CVE-2022-0828HIGH7.5The Download Manager WordPress plugin before 3.2.34 uses the uniqid php function to generate the master key for a downlo...
CVE-2022-27089HIGH7.8In Fujitsu PlugFree Network <= 7.3.0.3, an Unquoted service path in PFNService.exe software allows a local attacker to p...
CVE-2022-27088HIGH7.8Ivanti DSM Remote <= 6.3.1.1862 is vulnerable to an unquoted service path allowing local users to launch processes with ...
CVE-2022-27041HIGH7.5Due to lack of protection, parameter student_id in OpenSIS Classic 8.0 /modules/eligibility/Student.php can be used to i...
CVE-2022-26413HIGH8A command injection vulnerability in the CGI program of Zyxel VMG3312-T20A firmware version 5.30(ABFX.5)C0 could allow a...
CVE-2022-0556HIGH7.8A local privilege escalation vulnerability caused by incorrect permission assignment in some directories of the Zyxel AP...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now