2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-3966HIGH7.5A vulnerability, which was classified as critical, has been found in Ultimate Member Plugin up to 2.5.0. This issue affe...
CVE-2022-3965HIGH8.1A vulnerability classified as problematic was found in ffmpeg. This vulnerability affects the function smc_encode_stream...
CVE-2022-3964HIGH8.1A vulnerability classified as problematic has been found in ffmpeg. This affects an unknown part of the file libavcodec/...
CVE-2022-3963MEDIUM5.4A vulnerability was found in gnuboard5. It has been classified as problematic. Affected is an unknown function of the fi...
CVE-2022-45196HIGH7.5Hyperledger Fabric 2.3 allows attackers to cause a denial of service (orderer crash) by repeatedly sending a crafted cha...
CVE-2022-45195MEDIUM5.3SimpleXMQ before 3.4.0, as used in SimpleX Chat before 4.2, does not apply a key derivation function to intended data, w...
CVE-2022-45188HIGH7.8Netatalk through 3.1.13 has an afp_getappl heap-based buffer overflow resulting in code execution via a crafted .appl fi...
CVE-2022-38652CRITICAL9.9A remote insecure deserialization vulnerability exixsts in VMWare Hyperic Agent 5.8.6. Exploitation of this vulnerabilit...
CVE-2022-38651CRITICAL9.8A security filter misconfiguration exists in VMware Hyperic Server 5.8.6. Exploitation of this vulnerability enables a m...
CVE-2022-38650CRITICAL10A remote unauthenticated insecure deserialization vulnerability exists in VMware Hyperic Server 5.8.6. Exploitation of t...
CVE-2022-43672CRITICAL9.8Zoho ManageEngine Password Manager Pro before 12122, PAM360 before 5711, and Access Manager Plus before 4306 allow SQL I...
CVE-2022-43671CRITICAL9.8Zoho ManageEngine Password Manager Pro before 12122, PAM360 before 5711, and Access Manager Plus before 4306 allow SQL I...
CVE-2022-41339HIGH7.8In Zoho ManageEngine Mobile Device Manager Plus before 10.1.2207.5, the User Administration module allows privilege esca...
CVE-2022-40773HIGH8.8Zoho ManageEngine ServiceDesk Plus MSP before 10609 and SupportCenter Plus before 11025 are vulnerable to privilege esca...
CVE-2022-45194MEDIUM4.7CBRN-Analysis before 22 allows XXE attacks via am mws XML document, leading to NTLMv2-SSP hash disclosure.
CVE-2022-45193HIGH8.8CBRN-Analysis before 22 has weak file permissions under Public Profile, leading to disclosure of file contents or privil...
CVE-2022-41905MEDIUM6.1WsgiDAV is a generic and extendable WebDAV server based on WSGI. Implementations using this library with directory brows...
CVE-2022-45182CRITICAL9.8Pi-Star_DV_Dash (for Pi-Star DV) before 5aa194d mishandles the module parameter.
CVE-2022-41906HIGH8.7OpenSearch Notifications is a notifications plugin for OpenSearch that enables other plugins to send notifications via E...
CVE-2022-41904MEDIUM6.5Element iOS is an iOS Matrix client provided by Element. It is based on MatrixSDK. Prior to version 1.9.7, events encryp...
CVE-2022-41882HIGH7.8The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server with your computer. In version 3.6.0, ...
CVE-2022-40750MEDIUM5.4IBM WebSphere Application Server 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to ...
CVE-2022-38387HIGH8.8IBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.2.0 could allow a remote authenticated attacker to execute arbit...
CVE-2022-36776MEDIUM5.4IBM Cloud Pak for Security (CP4S) 1.10.0.0 79and 1.10.2.0 is vulnerable to cross-site scripting. This vulnerability allo...
CVE-2022-31772MEDIUM6.5 IBM MQ 8.0, 9.0 LTS, 9.1 CD, 9.1 LTS, 9.2 CD, and 9.2 LTS could allow an authenticated and authorized user to cause a d...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now