2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-39178MEDIUM5.3 Webvendome - webvendome Internal Server IP Disclosure. Send GET Request to the request which is shown in the picture. I...
CVE-2022-38165CRITICAL9.8Arbitrary file write in F-Secure Policy Manager through 2022-08-10 allows unauthenticated users to write the file with t...
CVE-2022-36924HIGH7.8The Zoom Rooms Installer for Windows prior to 5.12.6 contains a local privilege escalation vulnerability. A local low-pr...
CVE-2022-36787CRITICAL9.8 webvendome - webvendome SQL Injection. SQL Injection in the Parameter " DocNumber" Request : Get Request : /webvendome/...
CVE-2022-36786CRITICAL9.9DLINK - DSL-224 Post-auth RCE. DLINK router version 3.0.8 has an interface where you can configure NTP servers (Network ...
CVE-2022-36785HIGH7.5 D-Link – G integrated Access Device4 Information Disclosure & Authorization Bypass. *Information Disclosure – file con...
CVE-2022-36784CRITICAL9.8 Elsight – Elsight Halo  Remote Code Execution (RCE) Elsight Halo web panel allows us to perform connection validation. ...
CVE-2022-36357MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Webpsilon ULTIMATE TABLES plugin <= 1.6.5 versions.
CVE-2022-28768HIGH7.8The Zoom Client for Meetings Installer for macOS (Standard and for IT Admin) before version 5.12.6 contains a local priv...
CVE-2022-28766HIGH7.3Windows 32-bit versions of the Zoom Client for Meetings before 5.12.6 and Zoom Rooms for Conference Room before version ...
CVE-2022-23748HIGH7.8mDNSResponder.exe is vulnerable to DLL Sideloading attack. Executable improperly specifies how to load the DLL, from whi...
CVE-2022-20460MEDIUM6.7In (TBD) mprot_unmap? of (TBD), there is a possible way to corrupt the memory mapping due to improper input validation. ...
CVE-2022-20459MEDIUM6.7In (TBD) of (TBD), there is a possible way to redirect code execution due to improper input validation. This could lead ...
CVE-2022-20428MEDIUM6.7In (TBD) of (TBD), there is a possible out of bounds write due to a missing bounds check. This could lead to local escal...
CVE-2022-20427MEDIUM6.7In (TBD) of (TBD), there is a possible way to corrupt memory due to improper input validation. This could lead to local ...
CVE-2022-45072MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in WPML Multilingual CMS premium plugin <= 4.5.13 on WordPress.
CVE-2022-45071HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in WPML Multilingual CMS premium plugin <= 4.5.13 on WordPress.
CVE-2022-44725HIGH7.8OPC Foundation Local Discovery Server (LDS) through 1.04.403.478 uses a hard-coded file path to a configuration file. Th...
CVE-2022-44001CRITICAL9.8An issue was discovered in BACKCLICK Professional 5.9.63. User authentication for accessing the CORBA back-end services ...
CVE-2022-43192MEDIUM6.7An arbitrary file upload vulnerability in the component /dede/file_manage_control.php of Dedecms v5.7.101 allows attacke...
CVE-2022-42903LOW3.3Zoho ManageEngine SupportCenter Plus through 11024 allows low-privileged users to view the organization users list.
CVE-2022-3090MEDIUM5.3Red Lion Controls Crimson 3.0 versions 707.000 and prior, Crimson 3.1 versions 3126.001 and prior, and Crimson 3.2 versi...
CVE-2022-39389MEDIUM6.5Lightning Network Daemon (lnd) is an implementation of a lightning bitcoin overlay network node. All lnd nodes before ve...
CVE-2022-38461MEDIUM4.3Broken Access Control vulnerability in WPML Multilingual CMS premium plugin <= 4.5.10 on WordPress allows users with a s...
CVE-2022-43183HIGH8.8XXL-Job before v2.3.1 contains a Server-Side Request Forgery (SSRF) via the component /admin/controller/JobLogController...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now