2022 CVE Vulnerabilities

27,528 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-41878CRITICAL9.8Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. In versions prio...
CVE-2022-42460MEDIUM5.4Broken Access Control vulnerability leading to Stored Cross-Site Scripting (XSS) in Traffic Manager plugin <= 1.4.5 on W...
CVE-2022-41607HIGH7.5All versions of ETIC Telecom Remote Access Server (RAS) 4.5.0 and prior’s application programmable interface (API) is vu...
CVE-2022-40981CRITICAL10All versions of ETIC Telecom Remote Access Server (RAS) 4.5.0 and prior is vulnerable to malicious file upload. An attac...
CVE-2022-40225HIGH7.5A vulnerability has been identified in SIPLUS TIM 1531 IRC (6AG1543-1MX00-7XE0) (All versions < V2.4.8), TIM 1531 IRC (6...
CVE-2022-3703CRITICAL10All versions of ETIC Telecom Remote Access Server (RAS) 4.5.0 and prior’s web portal is vulnerable to accepting maliciou...
CVE-2022-28748Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2022-2964. Reason: This candidate is a reservation du...
CVE-2022-43679MEDIUM5.3The Docker image of ownCloud Server through 10.11 contains a misconfiguration that renders the trusted_domains config us...
CVE-2022-41879CRITICAL9.8Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. In versions prio...
CVE-2022-41876MEDIUM5.3ezplatform-graphql is a GraphQL server implementation for Ibexa DXP and Ibexa Open Source. Versions prior to 2.3.12 and ...
CVE-2022-41874MEDIUM4.7Tauri is a framework for building binaries for all major desktop platforms. In versions prior to 1.0.7 and 1.1.2, Tauri ...
CVE-2022-35740MEDIUM6.1dotCMS before 22.06 allows remote attackers to bypass intended access control and obtain sensitive information by using ...
CVE-2022-26088MEDIUM5.4An issue was discovered in BMC Remedy before 22.1. Email-based Incident Forwarding allows remote authenticated users to ...
CVE-2022-43074CRITICAL9.8AyaCMS v3.1.2 was discovered to contain an arbitrary file upload vulnerability via the component /admin/fst_upload.inc.p...
CVE-2022-41719HIGH7.5Unmarshal can panic on some inputs, possibly allowing for denial of service attacks.
CVE-2022-39394CRITICAL9.8Wasmtime is a standalone runtime for WebAssembly. Prior to version 2.0.2, there is a bug in Wasmtime's C API implementat...
CVE-2022-39393HIGH8.6Wasmtime is a standalone runtime for WebAssembly. Prior to versions 2.0.2 and 1.0.2, there is a bug in Wasmtime's implem...
CVE-2022-39392HIGH7.4Wasmtime is a standalone runtime for WebAssembly. Prior to version 2.0.2, there is a bug in Wasmtime's implementation of...
CVE-2022-39388LOW3.5Istio is an open platform to connect, manage, and secure microservices. In versions on the 1.15.x branch prior to 1.15.3...
CVE-2022-39395CRITICAL9.9Vela is a Pipeline Automation (CI/CD) framework built on Linux container technology written in Golang. In Vela Server an...
CVE-2022-36022MEDIUM5.3Deeplearning4J is a suite of tools for deploying and training deep learning models using the JVM. Packages org.deeplearn...
CVE-2022-44727CRITICAL9.1The EU Cookie Law GDPR (Banner + Blocker) module before 2.1.3 for PrestaShop allows SQL Injection via a cookie ( lgcooki...
CVE-2022-45063CRITICAL9.8xterm before 375 allows code execution via font ops, e.g., because an OSC 50 response may have Ctrl-g and therefore lead...
CVE-2022-34666MEDIUM5.5NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where a local user wi...
CVE-2022-44089CRITICAL9.8ESPCMS P8.21120101 was discovered to contain a remote code execution (RCE) vulnerability in the component IS_GETCACHE.

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now