2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-42895MEDIUM6.5There is an infoleak vulnerability in the Linux kernel's net/bluetooth/l2cap_core.c's l2cap_parse_conf_req function whic...
CVE-2022-45462CRITICAL9.8Alarm instance management has command injection when there is a specific command configured. It is only for logged-in us...
CVE-2022-4045MEDIUM6.5A denial-of-service vulnerability in the Mattermost allows an authenticated user to crash the server via multiple reques...
CVE-2022-4044MEDIUM6.5A denial-of-service vulnerability in Mattermost allows an authenticated user to crash the server via multiple large auto...
CVE-2022-4019MEDIUM6.5A denial-of-service vulnerability in the Mattermost Playbooks plugin allows an authenticated user to crash the server vi...
CVE-2022-45472MEDIUM5.4CAE LearningSpace Enterprise (with Intuity License) image 267r patch 639 allows DOM XSS, related to ontouchmove and onpo...
CVE-2022-43213CRITICAL9.8Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at editorder.ph...
CVE-2022-41446MEDIUM5.4An access control issue in /Admin/dashboard.php of Record Management System using CodeIgniter v1.0 allows attackers to a...
CVE-2022-40770HIGH7.2Zoho ManageEngine ServiceDesk Plus versions 13010 and prior are vulnerable to authenticated command injection. This can ...
CVE-2022-38147MEDIUM5.4Silverstripe silverstripe/framework through 4.11 allows XSS (issue 3 of 3).
CVE-2022-37421MEDIUM5.4Silverstripe silverstripe/cms through 4.11.0 allows XSS.
CVE-2022-36337HIGH8.2An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. A stack buffer overflow vulnerability in the Me...
CVE-2022-34830HIGH7.5An Arm product family through 2022-06-29 has a TOCTOU Race Condition that allows non-privileged user to make improper GP...
CVE-2022-42095MEDIUM4.8Backdrop CMS version 1.23.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Page con...
CVE-2022-38145MEDIUM5.4Silverstripe silverstripe/framework through 4.11 allows XSS (issue 1 of 3) via remote attackers adding a Javascript payl...
CVE-2022-37772HIGH7.5Maarch RM 2.8.3 solution contains an improper restriction of excessive authentication attempts due to excessive verbose ...
CVE-2022-37430MEDIUM5.4Silverstripe silverstripe/framework through 4.11 allows XSS vulnerability via href attribute of a link (issue 2 of 2).
CVE-2022-37429MEDIUM5.4Silverstripe silverstripe/framework through 4.11 allows XSS (issue 1 of 2) via JavaScript payload to the href attribute ...
CVE-2022-35500MEDIUM5.4Amasty Blog 2.10.3 is vulnerable to Cross Site Scripting (XSS) via leave comment functionality.
CVE-2022-43751HIGH7.8McAfee Total Protection prior to version 16.0.49 contains an uncontrolled search path element vulnerability due to the u...
CVE-2022-40870HIGH8.1The Web Client of Parallels Remote Application Server v18.0 is vulnerable to Host Header Injection attacks. This vulnera...
CVE-2022-40303HIGH7.5An issue was discovered in libxml2 before 2.10.3. When parsing a multi-gigabyte XML document with the XML_PARSE_HUGE par...
CVE-2022-38724MEDIUM5.4Silverstripe silverstripe/framework through 4.11.0, silverstripe/assets through 1.11.0, and silverstripe/asset-admin thr...
CVE-2022-37774MEDIUM5.3There is a broken access control vulnerability in the Maarch RM 2.8.3 solution. When accessing some specific document (p...
CVE-2022-37773MEDIUM6.5An authenticated SQL Injection vulnerability in the statistics page (/statistics/retrieve) of Maarch RM 2.8, via the fil...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now