2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-44279MEDIUM6.1Garage Management System v1.0 is vulnerable to Cross Site Scripting (XSS) via /garage/php_action/createBrand.php.
CVE-2022-4172MEDIUM6.5An integer overflow and buffer overflow issues were found in the ACPI Error Record Serialization Table (ERST) device of ...
CVE-2022-4144MEDIUM6.5An out-of-bounds read flaw was found in the QXL display device emulation in QEMU. The qxl_phys2virt() function does not ...
CVE-2022-46150MEDIUM4.3Discourse is an open-source discussion platform. Prior to version 2.8.13 of the `stable` branch and version 2.9.0.beta14...
CVE-2022-46152HIGH8.8OP-TEE Trusted OS is the secure side implementation of OP-TEE project, a Trusted Execution Environment. Versions prior t...
CVE-2022-46148MEDIUM5.4Discourse is an open-source messaging platform. In versions 2.8.10 and prior on the `stable` branch and versions 2.9.0.b...
CVE-2022-44356HIGH7.5WAVLINK Quantum D4G (WL-WN531G3) running firmware versions M31G3.V5030.201204 and M31G3.V5030.200325 has an access contr...
CVE-2022-44355MEDIUM6.1SolarView Compact 7.0 is vulnerable to Cross-site Scripting (XSS) via /network_test.php.
CVE-2022-44354CRITICAL9.8SolarView Compact 4.0 and 5.0 is vulnerable to Unrestricted File Upload via a crafted php file.
CVE-2022-25848HIGH7.5This affects all versions of package static-dev-server. This is because when paths from users to the root directory are ...
CVE-2022-21126HIGH7.8The package com.github.samtools:htsjdk before 3.0.1 are vulnerable to Creation of Temporary File in Directory with Insec...
CVE-2022-45343HIGH7.8GPAC v2.1-DEV-rev478-g696e6f868-master was discovered to contain a heap use-after-free via the Q_IsTypeOn function at /g...
CVE-2022-44635HIGH8.8Apache Fineract allowed an authenticated user to perform remote code execution due to a path traversal vulnerability in ...
CVE-2022-46146HIGH8.8Prometheus Exporter Toolkit is a utility package to build exporters. Prior to versions 0.7.2 and 0.8.2, if someone has a...
CVE-2022-36433MEDIUM6.1The blog-post creation functionality in the Amasty Blog Pro 2.10.3 plugin for Magento 2 allows injection of JavaScript c...
CVE-2022-4202HIGH8.8A vulnerability, which was classified as problematic, was found in GPAC 2.1-DEV-rev490-g68064e101-master. Affected is th...
CVE-2022-45329HIGH7.5AeroCMS v0.0.1 was discovered to contain a SQL Injection vulnerability via the Search parameter. This vulnerability allo...
CVE-2022-43326HIGH7.5An Insecure Direct Object Reference (IDOR) vulnerability in the password reset function of Telos Alliance Omnia MPX Node...
CVE-2022-41568HIGH7.5LINE client for iOS before 12.17.0 might be crashed by sharing an invalid shared key of e2ee in group chat.
CVE-2022-40799HIGH8.8Data Integrity Failure in 'Backup Config' in D-Link DNR-322L <= 2.60B15 allows an authenticated attacker to execute OS l...
CVE-2022-45204MEDIUM5.5GPAC v2.1-DEV-rev428-gcb8ae46c8-master was discovered to contain a memory leak via the function dimC_box_read at isomedi...
CVE-2022-45202HIGH7.8GPAC v2.1-DEV-rev428-gcb8ae46c8-master was discovered to contain a stack overflow via the function dimC_box_read at isom...
CVE-2022-44038CRITICAL9.8Russound XSourcePlayer 777D v06.08.03 was discovered to contain a remote code execution vulnerability via the scriptRunn...
CVE-2022-44037HIGH8.8An access control issue in APsystems ENERGY COMMUNICATION UNIT (ECU-C) Power Control Software V4.1NA, V3.11.4, W2.1NA, V...
CVE-2022-42109CRITICAL9.8Online-shopping-system-advanced 1.0 was discovered to contain a SQL injection vulnerability via the p parameter at /shop...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now