2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2022-0988HIGH7.5Delta Electronics DIAEnergie (Version 1.7.5 and prior) is vulnerable to cleartext transmission as the web application ru...
CVE-2022-0983HIGH8.8An SQL injection risk was identified in Badges code relating to configuring criteria. Access to the relevant capability ...
CVE-2022-0759HIGH8.1A flaw was found in all versions of kubeclient up to (but not including) v4.9.3, the Ruby client for Kubernetes REST API...
CVE-2022-0500HIGH7.8A flaw was found in unrestricted eBPF usage by the BPF_BTF_LOAD, leading to a possible out-of-bounds memory write in the...
CVE-2022-0435HIGH8.8A stack overflow flaw was found in the Linux kernel's TIPC protocol functionality in the way a user sends a packet with ...
CVE-2022-0330HIGH7.8A random memory access flaw was found in the Linux kernel's GPU i915 kernel driver functionality in the way a user may r...
CVE-2022-27882HIGH7.5slaacd in OpenBSD 6.9 and 7.0 before 2022-03-22 has an integer signedness error and resultant heap-based buffer overflow...
CVE-2022-27881HIGH7.5engine.c in slaacd in OpenBSD 6.9 and 7.0 before 2022-02-21 has a buffer overflow triggerable by an IPv6 router advertis...
CVE-2022-24778HIGH7.5The imgcrypt library provides API exensions for containerd to support encrypted container images and implements the ctd-...
CVE-2022-24777HIGH7.5grpc-swift is the Swift language implementation of gRPC, a remote procedure call (RPC) framework. Prior to version 1.7.2...
CVE-2022-27227HIGH7.5In PowerDNS Authoritative Server before 4.4.3, 4.5.x before 4.5.4, and 4.6.x before 4.6.1 and PowerDNS Recursor before 4...
CVE-2022-1064HIGH8.8SQL injection through marking blog comments on bulk as spam in GitHub repository forkcms/forkcms prior to 5.11.1.
CVE-2022-22688HIGH8.8Improper neutralization of special elements used in a command ('Command Injection') vulnerability in File service functi...
CVE-2022-25571HIGH7.5Bluedon Information Security Technologies Co.,Ltd Internet Access Detector v1.0 was discovered to contain an information...
CVE-2022-24781HIGH7.1Geon is a board game based on solving questions about the Pythagorean Theorem. Malicious users can obtain the uuid from ...
CVE-2022-25568HIGH7.5MotionEye v0.42.1 and below allows attackers to access sensitive information via a GET request to /config/list. To explo...
CVE-2022-0153HIGH7.5SQL Injection in GitHub repository forkcms/forkcms prior to 5.11.1.
CVE-2022-0551HIGH7.2Improper Input Validation vulnerability in project file upload in Nozomi Networks Guardian and CMC allows an authenticat...
CVE-2022-0550HIGH7.2Improper Input Validation vulnerability in custom report logo upload in Nozomi Networks Guardian, and CMC allows an auth...
CVE-2022-1061HIGH7.5Heap Buffer Overflow in parseDragons in GitHub repository radareorg/radare2 prior to 5.6.8.
CVE-2022-0315HIGH7.5Insecure Temporary File in GitHub repository horovod/horovod prior to 0.24.0.
CVE-2022-25268HIGH8.8Passwork On-Premise Edition before 4.6.13 allows CSRF via the groups, password, and history subsystems.
CVE-2022-25267HIGH8.8Passwork On-Premise Edition before 4.6.13 allows migration/uploadExportFile Directory Traversal (to upload files).
CVE-2022-27192HIGH7.5The Reporting module in Aseco Lietuva document management system DVS Avilys before 3.5.58 allows unauthorized file downl...
CVE-2022-24768HIGH8.8Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. All unpatched versions of Argo CD starting wit...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now