2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-4011CRITICAL9.8A vulnerability was found in Simple History Plugin. It has been rated as critical. This issue affects some unknown proce...
CVE-2022-2166CRITICAL9.8Improper Restriction of Excessive Authentication Attempts in GitHub repository mastodon/mastodon prior to 4.0.0.
CVE-2022-41917MEDIUM4.3OpenSearch is a community-driven, open source fork of Elasticsearch and Kibana. OpenSearch allows users to specify a loc...
CVE-2022-3920HIGH7.5HashiCorp Consul and Consul Enterprise 1.13.0 up to 1.13.3 do not filter cluster filtering's imported nodes and services...
CVE-2022-41918MEDIUM6.3OpenSearch is a community-driven, open source fork of Elasticsearch and Kibana. There is an issue with the implementatio...
CVE-2022-41916HIGH7.5Heimdal is an implementation of ASN.1/DER, PKIX, and Kerberos. Versions prior to 7.7.1 are vulnerable to a denial of ser...
CVE-2022-4006HIGH7.5A vulnerability, which was classified as problematic, has been found in WBCE CMS. Affected by this issue is the function...
CVE-2022-30769MEDIUM4.6Session fixation exists in ZoneMinder through 1.36.12 as an attacker can poison a session cookie to the next logged-in u...
CVE-2022-30768MEDIUM5.4A Stored Cross Site Scripting (XSS) issue in ZoneMinder 1.36.12 allows an attacker to execute HTML or JavaScript code vi...
CVE-2022-29279HIGH8.2Use of a untrusted pointer allows tampering with SMRAM and OS memory in SdHostDriver and SdMmcDevice Use of a untrusted ...
CVE-2022-29278HIGH8.2Incorrect pointer checks within the NvmExpressDxe driver can allow tampering with SMRAM and OS memory Incorrect pointer ...
CVE-2022-29277HIGH8.8Incorrect pointer checks within the the FwBlockServiceSmm driver can allow arbitrary RAM modifications During review of ...
CVE-2022-29276HIGH8.2SMI functions in AhciBusDxe use untrusted inputs leading to corruption of SMRAM. SMI functions in AhciBusDxe use untrust...
CVE-2022-43279HIGH7.2LimeSurvey before v5.0.4 was discovered to contain a SQL injection vulnerability via the component /application/views/th...
CVE-2022-43265CRITICAL9.8An arbitrary file upload vulnerability in the component /pages/save_user.php of Canteen Management System v1.0 allows at...
CVE-2022-42785CRITICAL9.8Multiple W&T products of the ComServer Series are prone to an authentication bypass. An unathenticated remote attacker, ...
CVE-2022-40753MEDIUM5.4 IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed ...
CVE-2022-3377HIGH7.8Horner Automation's Cscape version 9.90 SP 6 and prior does not properly validate user-supplied data. If a user opens a ...
CVE-2022-38385HIGH8.1 IBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.2.0 could allow an authenticated user to obtain highly sensitiv...
CVE-2022-38201MEDIUM6.1An unvalidated redirect vulnerability exists in Esri Portal for ArcGIS Quick Capture Web Designer versions 10.8.1 to 10....
CVE-2022-30772HIGH8.2Manipulation of the input address in PnpSmm function 0x52 could be used by malware to overwrite SMRAM or OS kernel memor...
CVE-2022-30771HIGH8.2Initialization function in PnpSmm could lead to SMRAM corruption when using subsequent PNP SMI functions Initialization ...
CVE-2022-30283HIGH7.5In UsbCoreDxe, tampering with the contents of the USB working buffer using DMA while certain USB transactions are in pro...
CVE-2022-29275HIGH8.2In UsbCoreDxe, untrusted input may allow SMRAM or OS memory tampering Use of untrusted pointers could allow OS or SMRAM ...
CVE-2022-24942CRITICAL9.8 Heap based buffer overflow in HTTP Server functionality in Micrium uC-HTTP 3.01.01 allows remote code execution via HTT...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now