2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2022-24232HIGH7.8A local file inclusion in Hospital Patient Record Management System v1.0 allows attackers to execute arbitrary code via ...
CVE-2022-23922HIGH7.8WIN-911 2021 R1 and R2 are vulnerable to a permissions misconfiguration that may allow an attacker to locally write file...
CVE-2022-23104HIGH7.8WIN-911 2021 R1 and R2 are vulnerable to a permissions misconfiguration that may allow an attacker to locally write file...
CVE-2022-21824HIGH8.2Due to the formatting logic of the "console.table()" function it was not safe to allow user controlled input to be passe...
CVE-2022-0651HIGH7.5The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of t...
CVE-2022-0546HIGH7.8A missing bounds check in the image loader used in Blender 3.x and 2.93.8 leads to out-of-bounds heap access, allowing a...
CVE-2022-0545HIGH7.8An integer overflow in the processing of loaded 2D images leads to a write-what-where vulnerability and an out-of-bounds...
CVE-2022-22793HIGH7.5Cybonet - PineApp Mail Relay Local File Inclusion. Attacker can send a request to : /manage/mailpolicymtm/log/eml_viewer...
CVE-2022-24707HIGH8.8Anuko Time Tracker is an open source, web-based time tracking application written in PHP. UNION SQL injection and time-b...
CVE-2022-0732HIGH7.5The backend infrastructure shared by multiple mobile device monitoring services does not adequately authenticate or auth...
CVE-2022-25838HIGH8.1Laravel Fortify before 1.11.1 allows reuse within a short time window, thus calling into question the "OT" part of the "...
CVE-2022-25640HIGH7.5In wolfSSL before 5.2.0, a TLS 1.3 server cannot properly enforce a requirement for mutual authentication. A client can ...
CVE-2022-25636HIGH7.8net/netfilter/nf_dup_netdev.c in the Linux kernel 5.4 through 5.6.10 allows local users to gain privileges because of a ...
CVE-2022-25401HIGH7.5The copy function of the file manager in Cuppa CMS v1.0 allows any file to be copied to the current directory, granting ...
CVE-2022-25360HIGH8.8WatchGuard Firebox and XTM appliances allow an authenticated remote attacker with unprivileged credentials to upload fil...
CVE-2022-25293HIGH8.8A systemd stack-based buffer overflow in WatchGuard Firebox and XTM appliances allows an authenticated remote attacker t...
CVE-2022-25292HIGH8.8A wgagent stack-based buffer overflow in WatchGuard Firebox and XTM appliances allows an authenticated remote attacker t...
CVE-2022-25291HIGH8.8An integer overflow in WatchGuard Firebox and XTM appliances allows an authenticated remote attacker to trigger a heap-b...
CVE-2022-25104HIGH7.5HorizontCMS v1.0.0-beta.2 was discovered to contain an arbitrary file download vulnerability via the component /admin/fi...
CVE-2022-25101HIGH7.8A vulnerability in the component /templates/install.php of WBCE CMS v1.5.2 allows attackers to execute arbitrary code vi...
CVE-2022-25099HIGH7.8A vulnerability in the component /languages/index.php of WBCE CMS v1.5.2 allows attackers to execute arbitrary code via ...
CVE-2022-24610HIGH8.6Settings/network settings/wireless settings on the Alecto DVC-215IP camera version 63.1.1.173 and below shows the Wi-Fi ...
CVE-2022-24407HIGH8.8In Cyrus SASL 2.1.17 through 2.1.27 before 2.1.28, plugins/sql.c does not escape the password for a SQL INSERT or UPDATE...
CVE-2022-23986HIGH7.5SQL injection vulnerability in the phpUploader v1.2 and earlier allows a remote unauthenticated attacker to obtain the i...
CVE-2022-23176HIGH8.8WatchGuard Firebox and XTM appliances allow a remote attacker with unprivileged credentials to access the system with a ...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now