2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2022-0711HIGH7.5A flaw was found in the way HAProxy processed HTTP responses containing the "Set-Cookie2" header. This flaw could allow ...
CVE-2022-0819HIGH8.8Code Injection in GitHub repository dolibarr/dolibarr prior to 15.0.1.
CVE-2022-25634HIGH7.5Qt through 5.15.8 and 6.x through 6.2.3 can load system library files from an unintended working directory.
CVE-2022-0829HIGH8.1Improper Authorization in GitHub repository webmin/webmin prior to 1.990.
CVE-2022-0824HIGH8.8Improper Access Control to Remote Code Execution in GitHub repository webmin/webmin prior to 1.990.
CVE-2022-22301HIGH7.8An improper neutralization of special elements used in an OS Command vulnerability [CWE-78] in FortiAP-C console 5.4.0 t...
CVE-2022-24255HIGH8.8Extensis Portfolio v4.0 was discovered to contain hardcoded credentials which allows attackers to gain administrator pri...
CVE-2022-24254HIGH8.8An unrestricted file upload vulnerability in the Backup/Restore Archive component of Extensis Portfolio v4.0 allows remo...
CVE-2022-24253HIGH8.8Extensis Portfolio v4.0 was discovered to contain an authenticated unrestricted file upload vulnerability via the compon...
CVE-2022-24252HIGH8.8An unrestricted file upload vulnerability in the FileTransferServlet component of Extensis Portfolio v4.0 allows remote ...
CVE-2022-24251HIGH8.8Extensis Portfolio v4.0 was discovered to contain an authenticated unrestricted file upload vulnerability via the Catalo...
CVE-2022-22300HIGH8.8A improper handling of insufficient permissions or privileges in Fortinet FortiAnalyzer version 5.6.0 through 5.6.11, Fo...
CVE-2022-23387HIGH7.5An issue was discovered in taocms 3.0.2. This is a SQL blind injection that can obtain database data through the Comment...
CVE-2022-23380HIGH8.8There is a SQL injection vulnerability in the background of taocms 3.0.2 in parameter id:action=admin&id=2&ctrl=edit.
CVE-2022-23377HIGH7.5Archeevo below 5.0 is affected by local file inclusion through file=~/web.config to allow an attacker to retrieve local ...
CVE-2022-0777HIGH7.5Weak Password Recovery Mechanism for Forgotten Password in GitHub repository microweber/microweber prior to 1.3.
CVE-2022-25018HIGH8.8Pluxml v5.8.7 was discovered to allow attackers to execute arbitrary code via crafted PHP code inserted into static page...
CVE-2022-22262HIGH7.7ROG Live Service’s function for deleting temp files created by installation has an improper link resolution before file ...
CVE-2022-25412HIGH8.1Maxsite CMS v180 was discovered to contain multiple arbitrary file deletion vulnerabilities in /admin_page/all-files-upd...
CVE-2022-23906HIGH7.2CMS Made Simple v2.2.15 was discovered to contain a Remote Command Execution (RCE) vulnerability via the upload avatar f...
CVE-2022-26181HIGH7.8Dropbox Lepton v1.2.1-185-g2a08b77 was discovered to contain a heap-buffer-overflow in the function aligned_dealloc():sr...
CVE-2022-25023HIGH8.8Audio File commit 004065d was discovered to contain a heap-buffer overflow in the function fouBytesToInt():AudioFile.h.
CVE-2022-24712HIGH8.8CodeIgniter4 is the 4.x branch of CodeIgniter, a PHP full-stack web framework. A vulnerability in versions prior to 4.1....
CVE-2022-24685HIGH7.5HashiCorp Nomad and Nomad Enterprise 1.0.17, 1.1.11, and 1.2.5 allow invalid HCL for the jobs parse endpoint, which may ...
CVE-2022-23911HIGH7.2The Testimonial WordPress Plugin WordPress plugin before 1.4.7 does not validate and escape the id parameter before usin...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now