2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-43509HIGH7.8Out-of-bounds write vulnerability exists in CX-Programmer v.9.77 and earlier, which may lead to information disclosure a...
CVE-2022-43508HIGH7.8Use-after free vulnerability exists in CX-Programmer v.9.77 and earlier, which may lead to information disclosure and/or...
CVE-2022-43468HIGH7.5External initialization of trusted variables or data stores vulnerability exists in WordPress Popular Posts 6.0.5 and ea...
CVE-2022-43464HIGH8.8Hidden functionality vulnerability in UDR-JA1604/UDR-JA1608/UDR-JA1616 firmware versions 71x10.1.107112.43A and earlier ...
CVE-2022-42486MEDIUM4.8Stored cross-site scripting vulnerability in User group management of baserCMS versions prior to 4.7.2 allows a remote a...
CVE-2022-41994MEDIUM4.8Stored cross-site scripting vulnerability in Permission Settings of baserCMS versions prior to 4.7.2 allows a remote aut...
CVE-2022-41800HIGH8.7 In all versions of BIG-IP, when running in Appliance mode, an authenticated user assigned the Administrator role may be...
CVE-2022-41783MEDIUM5.5tdpServer of TP-Link RE300 V1 improperly processes its input, which may allow an attacker to cause a denial-of-service (...
CVE-2022-41622HIGH8.8In all versions,  BIG-IP and BIG-IQ are vulnerable to cross-site request forgery (CSRF) attacks through iControl SOAP. ...
CVE-2022-37406MEDIUM4.8Cross-site scripting vulnerability in Aficio SP 4210N firmware versions prior to Web Support 1.05 allows a remote authen...
CVE-2022-44849HIGH8.8A Cross-Site Request Forgery (CSRF) in the Administrator List of MetInfo v7.7 allows attackers to arbitrarily add Super ...
CVE-2022-45026CRITICAL9.8An issue in Markdown Preview Enhanced v0.6.5 and v0.19.6 for VSCode and Atom allows attackers to execute arbitrary comma...
CVE-2022-45025CRITICAL9.8Markdown Preview Enhanced v0.6.5 and v0.19.6 for VSCode and Atom was discovered to contain a command injection vulnerabi...
CVE-2022-45010CRITICAL9.8Simple Phone Book/Directory Web App v1.0 was discovered to contain a SQL injection vulnerability via the editid paramete...
CVE-2022-45009HIGH7.2Online Leave Management System v1.0 was discovered to contain an arbitrary file upload vulnerability at /leave_system/cl...
CVE-2022-45008MEDIUM4.8Online Leave Management System v1.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the c...
CVE-2022-44942HIGH8.1Casdoor before v1.126.1 was discovered to contain an arbitrary file deletion vulnerability via the uploadFile function.
CVE-2022-44153MEDIUM6.1Rapid Software LLC Rapid SCADA 5.8.4 is vulnerable to Cross Site Scripting (XSS).
CVE-2022-45918MEDIUM6.5ILIAS before 7.16 allows External Control of File Name or Path.
CVE-2022-45917MEDIUM6.1ILIAS before 7.16 has an Open Redirect.
CVE-2022-45916MEDIUM5.4ILIAS before 7.16 allows XSS.
CVE-2022-45915HIGH8.8ILIAS before 7.16 allows OS Command Injection.
CVE-2022-42329MEDIUM5.5Guests can trigger deadlock in Linux netback driver T[his CNA information record relates to multiple CVEs; the text expl...
CVE-2022-42328MEDIUM5.5Guests can trigger deadlock in Linux netback driver T[his CNA information record relates to multiple CVEs; the text expl...
CVE-2022-3643MEDIUM6.5Guests can trigger NIC interface reset/abort/crash via netback It is possible for a guest to trigger a NIC interface res...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now