2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2022-26353HIGH7.5A flaw was found in the virtio-net device of QEMU. This flaw was inadvertently introduced with the fix for CVE-2021-3748...
CVE-2022-25252HIGH7.5When connecting to a certain port Axeda agent (All versions) and Axeda Desktop Server for Windows (All versions) when re...
CVE-2022-25250HIGH7.5When connecting to a certain port Axeda agent (All versions) and Axeda Desktop Server for Windows (All versions) may all...
CVE-2022-25249HIGH7.5When connecting to a certain port Axeda agent (All versions) and Axeda Desktop Server for Windows (All versions) (disreg...
CVE-2022-25246HIGH8.8Axeda agent (All versions) and Axeda Desktop Server for Windows (All versions) uses hard-coded credentials for its Ultra...
CVE-2022-0918HIGH7.5A vulnerability was discovered in the 389 Directory Server that allows an unauthenticated attacker with network access t...
CVE-2022-0811HIGH8.8A flaw was found in CRI-O in the way it set kernel options for a pod. This issue allows anyone with rights to deploy a p...
CVE-2022-24751HIGH7.4Zulip is an open source group chat application. Starting with version 4.0 and prior to version 4.11, Zulip is vulnerable...
CVE-2022-27223HIGH8.8In drivers/usb/gadget/udc/udc-xilinx.c in the Linux kernel before 5.16.12, the endpoint index is not validated and might...
CVE-2022-23989HIGH7.5In Stormshield Network Security (SNS) before 3.7.25, 3.8.x through 3.11.x before 3.11.13, 4.x before 4.2.10, and 4.3.x b...
CVE-2022-25491HIGH7.5HMS v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter in appointment.php.
CVE-2022-25486HIGH7.8CuppaCMS v1.0 was discovered to contain a local file inclusion via the url parameter in /alerts/alertConfigField.php.
CVE-2022-25485HIGH7.8CuppaCMS v1.0 was discovered to contain a local file inclusion via the url parameter in /alerts/alertLightbox.php.
CVE-2022-27204HIGH8.8A cross-site request forgery vulnerability in Jenkins Extended Choice Parameter Plugin 346.vd87693c5a_86c and earlier al...
CVE-2022-27198HIGH8A cross-site request forgery (CSRF) vulnerability in Jenkins CloudBees AWS Credentials Plugin 189.v3551d5642995 and earl...
CVE-2022-22771HIGH8.8The Server component of TIBCO Software Inc.'s TIBCO JasperReports Library, TIBCO JasperReports Library for ActiveMatrix ...
CVE-2022-0778HIGH7.5The BN_mod_sqrt() function, which computes a modular square root, contains a bug that can cause it to loop forever for n...
CVE-2022-26779HIGH7.5Apache CloudStack prior to 4.16.1.0 used insecure random number generation for project invitation tokens. If a project i...
CVE-2022-24756HIGH7.5Bareos is open source software for backup, archiving, and recovery of data for operating systems. When Bareos Director >...
CVE-2022-24721HIGH8.1CometD is a scalable comet implementation for web messaging. In any version prior to 5.0.11, 6.0.6, and 7.0.6, internal ...
CVE-2022-0944HIGH7.2Template injection in connection test endpoint leads to RCE in GitHub repository sqlpad/sqlpad prior to 6.10.1.
CVE-2022-24740HIGH7.5Volto is a ReactJS-based frontend for the Plone Content Management System. Between versions 14.0.0-alpha.5 and 15.0.0-al...
CVE-2022-24743HIGH8.2Sylius is an open source eCommerce platform. Prior to versions 1.10.11 and 1.11.2, the reset password token was not set ...
CVE-2022-0943HIGH7.8Heap-based Buffer Overflow occurs in vim in GitHub repository vim/vim prior to 8.2.4563.
CVE-2022-24578HIGH7.8GPAC 1.0.1 is affected by a heap-based buffer overflow in SFS_AddString () at bifs/script_dec.c.

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now