2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-23044HIGH8.8Tiny File Manager version 2.4.8 allows an unauthenticated remote attacker to persuade users to perform unintended action...
CVE-2022-45040MEDIUM5.4A cross-site scripting (XSS) vulnerability in /admin/pages/sections_save.php of WBCE CMS v1.5.4 allows attackers to exec...
CVE-2022-45039HIGH7.2An arbitrary file upload vulnerability in the Server Settings module of WBCE CMS v1.5.4 allows attackers to execute arbi...
CVE-2022-45038MEDIUM5.4A cross-site scripting (XSS) vulnerability in /admin/settings/save.php of WBCE CMS v1.5.4 allows attackers to execute ar...
CVE-2022-45037MEDIUM5.4A cross-site scripting (XSS) vulnerability in /admin/users/index.php of WBCE CMS v1.5.4 allows attackers to execute arbi...
CVE-2022-45036MEDIUM5.4A cross-site scripting (XSS) vulnerability in the Search Settings module of WBCE CMS v1.5.4 allows attackers to execute ...
CVE-2022-44411HIGH7.5Web Based Quiz System v1.0 transmits user passwords in plaintext during the authentication process, allowing attackers t...
CVE-2022-38377LOW2.7An improper access control vulnerability [CWE-284] in FortiManager 7.2.0, 7.0.0 through 7.0.3, 6.4.0 through 6.4.7, 6.2....
CVE-2022-37720CRITICAL9Orchardproject Orchard CMS 1.10.3 is vulnerable to Cross Site Scripting (XSS). When a low privileged user such as an aut...
CVE-2022-38767HIGH7.5An issue was discovered in Wind River VxWorks 6.9 and 7, that allows a specifically crafted packet sent by a Radius serv...
CVE-2022-38166HIGH7.5In F-Secure Endpoint Protection for Windows and macOS before channel with Capricorn database 2022-11-22_07, the aerdl.dl...
CVE-2022-4141HIGH7.8Heap based buffer overflow in vim/vim 9.0.0946 and below by allowing an attacker to CTRL-W gf in the expression used in ...
CVE-2022-4091MEDIUM6.1A vulnerability was found in SourceCodester Canteen Management System. It has been classified as problematic. This affec...
CVE-2022-36133CRITICAL9.1The WebConfig functionality of Epson TM-C3500 and TM-C7500 devices with firmware version WAM31500 allows authentication ...
CVE-2022-40282HIGH8.8The web server of Hirschmann BAT-C2 before 09.13.01.00R04 allows authenticated command injection. This allows an authent...
CVE-2022-2721HIGH7.5In affected versions of Octopus Server it is possible for target discovery to print certain values marked as sensitive t...
CVE-2022-45888MEDIUM6.4An issue was discovered in the Linux kernel through 6.0.9. drivers/char/xillybus/xillyusb.c has a race condition and use...
CVE-2022-45887MEDIUM4.7An issue was discovered in the Linux kernel through 6.0.9. drivers/media/usb/ttusb-dec/ttusb_dec.c has a memory leak bec...
CVE-2022-45886HIGH7An issue was discovered in the Linux kernel through 6.0.9. drivers/media/dvb-core/dvb_net.c has a .disconnect versus dvb...
CVE-2022-45885HIGH7An issue was discovered in the Linux kernel through 6.0.9. drivers/media/dvb-core/dvb_frontend.c has a race condition th...
CVE-2022-45884HIGH7An issue was discovered in the Linux kernel through 6.0.9. drivers/media/dvb-core/dvbdev.c has a use-after-free, related...
CVE-2022-4135CRITICAL9.6Heap buffer overflow in GPU in Google Chrome prior to 107.0.5304.121 allowed a remote attacker who had compromised the r...
CVE-2022-29833MEDIUM6.5Insufficiently Protected Credentials vulnerability in Mitsubishi Electric Corporation GX Works3 versions 1.015R and late...
CVE-2022-29832MEDIUM6.5Cleartext Storage of Sensitive Information in Memory vulnerability in Mitsubishi Electric Corporation GX Works3 versions...
CVE-2022-29831HIGH7.5Use of Hard-coded Password vulnerability in Mitsubishi Electric Corporation GX Works3 versions from 1.015R to 1.095Z all...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now