2022 CVE Vulnerabilities

27,525 CVEs published in 2022.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2022-23088CRITICAL9.8The 802.11 beacon handling routine failed to validate the length of an IEEE 802.11s Mesh ID before copying it to a heap-...
CVE-2022-48623CRITICAL9.1The Cpanel::JSON::XS package before 4.33 for Perl performs out-of-bounds accesses in a way that allows attackers to obta...
CVE-2022-34381CRITICAL9.8 Dell BSAFE SSL-J version 7.0 and all versions prior to 6.5, and Dell BSAFE Crypto-J versions prior to 6.2.6.1 contain a...
CVE-2022-47072CRITICAL9.8SQL injection vulnerability in Enterprise Architect 16.0.1605 32-bit allows attackers to run arbitrary SQL commands via ...
CVE-2022-45790CRITICAL9.1The Omron FINS protocol has an authenticated feature to prevent access to memory regions. Authentication is susceptible ...
CVE-2022-40700CRITICAL9.8Server-Side Request Forgery (SSRF) vulnerability in Montonio Montonio for WooCommerce, Wpopal Wpopal Core Features, AMO ...
CVE-2022-41786CRITICAL9.8Missing Authorization vulnerability in WP Job Portal WP Job Portal – A Complete Job Board.This issue affects WP Job Port...
CVE-2022-36418CRITICAL9.8Missing Authorization vulnerability in Vagary Digital HREFLANG Tags Lite.This issue affects HREFLANG Tags Lite: from n/a...
CVE-2022-1609CRITICAL9.8The School Management WordPress plugin before 9.9.7 contains an obfuscated backdoor injected in it's license checking co...
CVE-2022-4961CRITICAL9.8A vulnerability was found in Weitong Mall 1.0.0. It has been declared as critical. Affected by this vulnerability is an ...
CVE-2022-48620CRITICAL9.8uev (aka libuev) before 2.4.1 has a buffer overflow in epoll_wait if maxevents is a large number.
CVE-2022-46025CRITICAL9.1Totolink N200RE_V5 V9.3.5u.6255_B20211224 is vulnerable to Incorrect Access Control. The device allows remote attackers ...
CVE-2022-46839CRITICAL9.8Unrestricted Upload of File with Dangerous Type vulnerability in JS Help Desk JS Help Desk – Best Help Desk & Support Pl...
CVE-2022-34268CRITICAL9.8An issue was discovered in RWS WorldServer before 11.7.3. /clientLogin deserializes Java objects without authentication,...
CVE-2022-34267CRITICAL9.8An issue was discovered in RWS WorldServer before 11.7.3. Adding a token parameter with the value of 02 bypasses all aut...
CVE-2022-47532CRITICAL9.8FileRun 20220519 allows SQL Injection via the "dir" parameter in a /?module=users&section=cpanel&page=list request.
CVE-2022-45377CRITICAL9.8Unrestricted Upload of File with Dangerous Type vulnerability in Glen Don L. Mongaya Drag and Drop Multiple File Upload ...
CVE-2022-45135CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Cocoon.This...
CVE-2022-42541CRITICAL9.8Remote code execution
CVE-2022-42540CRITICAL9.8Elevation of privilege
CVE-2022-42538CRITICAL9.8Elevation of privilege
CVE-2022-42537CRITICAL9.8Remote code execution
CVE-2022-42536CRITICAL9.8Remote code execution
CVE-2022-41951CRITICAL9.8OroPlatform is a PHP Business Application Platform (BAP) designed to make development of custom business applications ea...
CVE-2022-46337CRITICAL9.8A cleverly devised username might bypass LDAP authentication checks. In LDAP-authenticated Derby installations, this co...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now