2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-37301HIGH7.5A CWE-191: Integer Underflow (Wrap or Wraparound) vulnerability exists that could cause a denial of service of the contr...
CVE-2022-2513MEDIUM5.5A vulnerability exists in the Intelligent Electronic Device (IED) Connectivity Package (ConnPack) credential storage fun...
CVE-2022-41131HIGH7.8Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Airfl...
CVE-2022-40954MEDIUM5.5Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Airfl...
CVE-2022-40189CRITICAL9.8Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Airfl...
CVE-2022-38649CRITICAL9.8Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Airfl...
CVE-2022-45363MEDIUM5.4Auth. (subscriber+) Stored Cross-Site Scripting (XSS) in Muffingroup Betheme theme <= 26.6.1 on WordPress.
CVE-2022-37931HIGH7.8A vulnerability in NetBatch-Plus software allows unauthorized access to the application.  HPE has provided a workaround...
CVE-2022-4111MEDIUM6.5Unrestricted file size limit can lead to DoS in tooljet/tooljet <1.27 by allowing a logged in attacker to upload profile...
CVE-2022-40602CRITICAL9.8A flaw in the Zyxel LTE3301-M209 firmware verisons prior to V1.00(ABLG.6)C0 could allow a remote attacker to access the ...
CVE-2022-36227CRITICAL9.8In libarchive before 3.6.2, the software does not check for an error after calling calloc function that can return with ...
CVE-2022-35407HIGH7.8An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. A stack buffer overflow leads to arbitrary code...
CVE-2022-43685HIGH8.8CKAN through 2.9.6 account takeovers by unauthenticated users when an existing user id is sent via an HTTP POST request....
CVE-2022-43215CRITICAL9.8Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the endDate parameter at getOrde...
CVE-2022-43214CRITICAL9.8Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the orderId parameter at printOr...
CVE-2022-41940MEDIUM6.5Engine.IO is the implementation of transport-based cross-browser/cross-device bi-directional communication layer for Soc...
CVE-2022-41937HIGH8.1XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. The application...
CVE-2022-41936HIGH7.5XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. The `modificati...
CVE-2022-41326CRITICAL9.8The web conferencing component of Mitel MiCollab through 9.6.0.13 could allow an unauthenticated attacker to upload arbi...
CVE-2022-41223MEDIUM6.8The Director database component of MiVoice Connect through 19.3 (22.22.6100.0) could allow an authenticated attacker to ...
CVE-2022-40842CRITICAL9.1ndk design NdkAdvancedCustomizationFields 3.5.0 is vulnerable to Server-side request forgery (SSRF) via rotateimg.php.
CVE-2022-40765MEDIUM6.8A vulnerability in the Edge Gateway component of Mitel MiVoice Connect through 19.3 (22.22.6100.0) could allow an authen...
CVE-2022-36180CRITICAL9.6Fusiondirectory 1.3 is vulnerable to Cross Site Scripting (XSS) via /fusiondirectory/index.php?message=[injection], /fus...
CVE-2022-36179CRITICAL9.8Fusiondirectory 1.3 suffers from Improper Session Handling.
CVE-2022-30529HIGH7.2File upload vulnerability in asith-eranga ISIC tour booking through version published on Feb 13th 2018, allows attackers...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now