2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-30122HIGH7.5A possible denial of service vulnerability exists in Rack <2.0.9.1, <2.1.4.1 and <2.2.3.1 in the multipart parsing compo...
CVE-2022-2827HIGH7.5AMI MegaRAC User Enumeration Vulnerability
CVE-2022-27773CRITICAL9.8A privilege escalation vulnerability is identified in Ivanti EPM (LANDesk Management Suite) that allows a user to execut...
CVE-2022-23143MEDIUM6.5ZTE OTCP product is impacted by a permission and access control vulnerability. Due to improper permission settings, an a...
CVE-2022-46169CRITICAL9.8Cacti is an open source platform which provides a robust and extensible operational monitoring and fault management fram...
CVE-2022-46164CRITICAL9.8NodeBB is an open source Node.js based forum software. Due to a plain object with a prototype being used in socket.io me...
CVE-2022-45481CRITICAL9.8The default configuration of Lazy Mouse does not require a password, allowing remote unauthenticated users to execute ar...
CVE-2022-45479CRITICAL9.8PC Keyboard allows remote unauthenticated users to send instructions to the server to execute arbitrary code without any...
CVE-2022-44039CRITICAL9.8Franklin Fueling System FFS Colibri 1.9.22.8925 is affected by: File system overwrite. The impact is: File system rewrit...
CVE-2022-42706MEDIUM4.9An issue was discovered in Sangoma Asterisk through 16.28, 17 and 18 through 18.14, 19 through 19.6, and certified throu...
CVE-2022-42705MEDIUM6.5A use-after-free in res_pjsip_pubsub.c in Sangoma Asterisk 16.28, 18.14, 19.6, and certified/18.9-cert2 may allow a remo...
CVE-2022-37783HIGH7.5All Craft CMS versions between 3.0.0 and 3.7.32 disclose password hashes of users who authenticate using their E-Mail ad...
CVE-2022-37325HIGH7.5In Sangoma Asterisk through 16.28.0, 17.x and 18.x through 18.14.0, and 19.x through 19.6.0, an incoming Setup message t...
CVE-2022-45771HIGH8.8An issue in the /api/audits component of Pwndoc v0.5.3 allows attackers to escalate privileges and execute arbitrary cod...
CVE-2022-43516CRITICAL9.8A Firewall Rule which allows all incoming TCP connections to all programs from any source and to all ports is created in...
CVE-2022-43097MEDIUM5.4Phpgurukul User Registration & User Management System v3.0 was discovered to contain multiple stored cross-site scriptin...
CVE-2022-23467MEDIUM4.6OpenRazer is an open source driver and user-space daemon to control Razer device lighting and other features on GNU/Linu...
CVE-2022-4293MEDIUM5.5Floating Point Comparison with Incorrect Operator in GitHub repository vim/vim prior to 9.0.0804.
CVE-2022-4292HIGH7.8Use After Free in GitHub repository vim/vim prior to 9.0.0882.
CVE-2022-43515CRITICAL9.8Zabbix Frontend provides a feature that allows admins to maintain the installation and ensure that only certain IP addre...
CVE-2022-3926MEDIUM6.5The WP OAuth Server (OAuth Authentication) WordPress plugin before 3.4.2 does not have CSRF check when regenerating secr...
CVE-2022-3909MEDIUM4.8The Add Comments WordPress plugin through 1.0.1 does not sanitise and escape some of its settings, which could allow hig...
CVE-2022-3907HIGH7.5The Clerk WordPress plugin before 4.0.0 is affected by time-based attacks in the validation function for all API request...
CVE-2022-3892MEDIUM4.8The WP OAuth Server (OAuth Authentication) WordPress plugin before 4.2.2 does not sanitize and escape Client IDs, which ...
CVE-2022-3858HIGH7.2The Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line, WeChat, Email, SMS, Call Button WordPress plugin befo...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now