2022 CVE Vulnerabilities

27,525 CVEs published in 2022.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2022-3703CRITICAL10All versions of ETIC Telecom Remote Access Server (RAS) 4.5.0 and prior’s web portal is vulnerable to accepting maliciou...
CVE-2022-41879CRITICAL9.8Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. In versions prio...
CVE-2022-43074CRITICAL9.8AyaCMS v3.1.2 was discovered to contain an arbitrary file upload vulnerability via the component /admin/fst_upload.inc.p...
CVE-2022-39394CRITICAL9.8Wasmtime is a standalone runtime for WebAssembly. Prior to version 2.0.2, there is a bug in Wasmtime's C API implementat...
CVE-2022-39395CRITICAL9.9Vela is a Pipeline Automation (CI/CD) framework built on Linux container technology written in Golang. In Vela Server an...
CVE-2022-44727CRITICAL9.1The EU Cookie Law GDPR (Banner + Blocker) module before 2.1.3 for PrestaShop allows SQL Injection via a cookie ( lgcooki...
CVE-2022-45063CRITICAL9.8xterm before 375 allows code execution via font ops, e.g., because an OSC 50 response may have Ctrl-g and therefore lead...
CVE-2022-44089CRITICAL9.8ESPCMS P8.21120101 was discovered to contain a remote code execution (RCE) vulnerability in the component IS_GETCACHE.
CVE-2022-44088CRITICAL9.8ESPCMS P8.21120101 was discovered to contain a remote code execution (RCE) vulnerability in the component INPUT_ISDESCRI...
CVE-2022-44087CRITICAL9.8ESPCMS P8.21120101 was discovered to contain a remote code execution (RCE) vulnerability in the component UPFILE_PIC_ZOO...
CVE-2022-39036CRITICAL9.8The file upload function of Agentflow BPM has insufficient filtering for special characters in URLs. An unauthenticated ...
CVE-2022-38119CRITICAL9.8UPSMON Pro login function has insufficient authentication. An unauthenticated remote attacker can exploit this vulnerabi...
CVE-2022-39396CRITICAL9.8Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Versions prior t...
CVE-2022-3726CRITICAL9Lack of sand-boxing of OpenAPI documents in GitLab CE/EE affecting all versions from 12.6 prior to 15.3.5, 15.4 prior to...
CVE-2022-39892CRITICAL9.8Improper access control in Samsung Pass prior to version 4.0.05.1 allows attackers to unauthenticated access via keep op...
CVE-2022-39881CRITICAL9.1Improper input validation vulnerability for processing SIB12 PDU in Exynos modems prior to SMR Sep-2022 Release allows r...
CVE-2022-44562CRITICAL9.8The system framework layer has a vulnerability of serialization/deserialization mismatch. Successful exploitation of thi...
CVE-2022-44559CRITICAL9.8The AMS module has a vulnerability of serialization/deserialization mismatch. Successful exploitation of this vulnerabil...
CVE-2022-44558CRITICAL9.8The AMS module has a vulnerability of serialization/deserialization mismatch. Successful exploitation of this vulnerabil...
CVE-2022-44551CRITICAL9.8The iaware module has a vulnerability in thread security. Successful exploitation of this vulnerability will affect conf...
CVE-2022-43058CRITICAL9.8Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id paramete...
CVE-2022-31689CRITICAL9.8VMware Workspace ONE Assist prior to 22.10 contains a Session fixation vulnerability. A malicious actor who obtains a va...
CVE-2022-31687CRITICAL9.8VMware Workspace ONE Assist prior to 22.10 contains a Broken Access Control vulnerability. A malicious actor with networ...
CVE-2022-31686CRITICAL9.8VMware Workspace ONE Assist prior to 22.10 contains a Broken Authentication Method vulnerability. A malicious actor with...
CVE-2022-31685CRITICAL9.8VMware Workspace ONE Assist prior to 22.10 contains an Authentication Bypass vulnerability. A malicious actor with netwo...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now