2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-45939HIGH7.8GNU Emacs through 28.2 allows attackers to execute commands via shell metacharacters in the name of a source-code file, ...
CVE-2022-45934HIGH7.8An issue was discovered in the Linux kernel through 6.0.10. l2cap_config_req in net/bluetooth/l2cap_core.c has an intege...
CVE-2022-43705CRITICAL9.1In Botan before 2.19.3, it is possible to forge OCSP responses due to a certificate verification error. This issue was i...
CVE-2022-45933CRITICAL9.8KubeView through 0.1.31 allows attackers to obtain control of a Kubernetes cluster because api/scrape/kube-system does n...
CVE-2022-45932HIGH7.5A SQL injection issue was discovered in AAA in OpenDaylight (ODL) before 0.16.5. The aaa-idm-store-h2/src/main/java/org/...
CVE-2022-45931HIGH7.5A SQL injection issue was discovered in AAA in OpenDaylight (ODL) before 0.16.5. The aaa-idm-store-h2/src/main/java/org/...
CVE-2022-45930HIGH7.5A SQL injection issue was discovered in AAA in OpenDaylight (ODL) before 0.16.5. The aaa-idm-store-h2/src/main/java/org/...
CVE-2022-45919HIGH7An issue was discovered in the Linux kernel through 6.0.10. In drivers/media/dvb-core/dvb_ca_en50221.c, a use-after-free...
CVE-2022-45914MEDIUM6.5The ESL (Electronic Shelf Label) protocol, as implemented by (for example) the OV80e934802 RF transceiver on the ETAG-21...
CVE-2022-24999HIGH7.5qs before 6.10.3, as used in Express before 4.17.3 and other products, allows attackers to cause a Node process hang for...
CVE-2022-45909CRITICAL9.1drachtio-server before 0.8.19 has a heap-based buffer over-read via a long Request-URI in an INVITE request.
CVE-2022-45908CRITICAL9.8In PaddlePaddle before 2.4, paddle.audio.functional.get_window is vulnerable to code injection because it calls eval on ...
CVE-2022-45907CRITICAL9.8In PyTorch before trunk/89695, torch.jit.annotations.parse_type_line can cause arbitrary code execution because eval is ...
CVE-2022-45225MEDIUM6.1Book Store Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in /bsms_ci/index...
CVE-2022-44844CRITICAL9.8TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the pass paramete...
CVE-2022-44843CRITICAL9.8TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the port paramete...
CVE-2022-39333MEDIUM6.1Nexcloud desktop is the Desktop sync client for Nextcloud. An attacker can inject arbitrary HyperText Markup Language in...
CVE-2022-39332MEDIUM5.4Nexcloud desktop is the Desktop sync client for Nextcloud. An attacker can inject arbitrary HyperText Markup Language in...
CVE-2022-39325MEDIUM6.1BaserCMS is a content management system with a japanese language focus. In affected versions there is a cross-site scrip...
CVE-2022-45152CRITICAL9.1A blind Server-Side Request Forgery (SSRF) vulnerability was found in Moodle. This flaw exists due to insufficient valid...
CVE-2022-41954LOW3.3MPXJ is an open source library to read and write project plans from a variety of file formats and databases. On Unix-lik...
CVE-2022-41926MEDIUM5.5Nextcould talk android is the android OS implementation of the nextcloud talk chat system. In affected versions the rece...
CVE-2022-41158CRITICAL9.8Remote code execution vulnerability can be achieved by using cookie values as paths to a file by this builder program. A...
CVE-2022-41157CRITICAL9.8A specific file on the sERP server if Kyungrinara(ERP solution) has a fixed password with the SYSTEM authority. This vul...
CVE-2022-41156HIGH7.8Remote code execution vulnerability due to insufficient verification of URLs, etc. in OndiskPlayerAgent. A remote attack...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now