2022 CVE Vulnerabilities

27,531 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-41680MEDIUM6.5Forma LMS on its 3.1.0 version and earlier is vulnerable to a SQL injection vulnerability. The exploitation of this vuln...
CVE-2022-41679MEDIUM6.1Forma LMS version 3.1.0 and earlier are affected by an Cross-Site scripting vulnerability, that could allow a remote att...
CVE-2022-41657CRITICAL9.8 Delta Electronics InfraSuite Device Master Versions 00.00.01a and prior allow attacker provided data already serialized...
CVE-2022-41644HIGH8.8 Delta Electronics InfraSuite Device Master versions 00.00.01a and prior lacks authentication for a function that chan...
CVE-2022-41629CRITICAL9.1 Delta Electronics InfraSuite Device Master versions 00.00.01a and prior allow unauthenticated users to access the aprun...
CVE-2022-40202CRITICAL9.8 The database backup function in Delta Electronics InfraSuite Device Master Versions 00.00.01a and prior lacks proper au...
CVE-2022-3499MEDIUM6.5An authenticated attacker could utilize the identical agent and cluster node linking keys to potentially allow for a sce...
CVE-2022-38142CRITICAL9.8 Delta Electronics InfraSuite Device Master versions 00.00.01a and prior deserialize user-supplied data provided through...
CVE-2022-31692CRITICAL9.8Spring Security, versions 5.7 prior to 5.7.5 and 5.6 prior to 5.6.9 could be susceptible to authorization rules bypass v...
CVE-2022-31690HIGH8.1Spring Security, versions 5.7 prior to 5.7.5, and 5.6 prior to 5.6.9, and older unsupported versions could be susceptibl...
CVE-2022-28763CRITICAL9.6The Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.12.2 is susceptible to a URL...
CVE-2022-27583CRITICAL9.1A remote unprivileged attacker can interact with the configuration interface of a Flexi-Compact FLX3-CPUC1 or FLX3-CPUC2...
CVE-2022-44081MEDIUM5.5Lodepng v20220717 was discovered to contain a segmentation fault via the function pngdetail.
CVE-2022-44079MEDIUM5.5pycdc commit 44a730f3a889503014fec94ae6e62d8401cb75e5 was discovered to contain a stack overflow via the component __san...
CVE-2022-43152MEDIUM5.5tsMuxer v2.6.16 was discovered to contain a heap overflow via the function BitStreamWriter::flushBits() at /tsMuxer/bitS...
CVE-2022-43151MEDIUM5.5timg v1.4.4 was discovered to contain a memory leak via the function timg::QueryBackgroundColor() at /timg/src/term-quer...
CVE-2022-43148MEDIUM5.5rtf2html v0.2.0 was discovered to contain a heap overflow in the component /rtf2html/./rtf_tools.h.
CVE-2022-39294HIGH7.5conduit-hyper integrates a conduit application with the hyper server. Prior to version 0.4.2, `conduit-hyper` did not ch...
CVE-2022-2741HIGH7.5The denial-of-service can be triggered by transmitting a carefully crafted CAN frame on the same CAN network as the vuln...
CVE-2022-40471CRITICAL9.8Remote Code Execution in Clinic's Patient Management System v 1.0 allows Attacker to Upload arbitrary php webshell via p...
CVE-2022-3774CRITICAL9.1A vulnerability was found in SourceCodester Train Scheduler App 1.0 and classified as critical. Affected by this issue i...
CVE-2022-3773Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2022-3441MEDIUM4.8The Rock Convert WordPress plugin before 2.11.0 does not sanitise and escape some of its settings, which could allow hig...
CVE-2022-3440MEDIUM6.1The Rock Convert WordPress plugin before 2.11.0 does not sanitise and escape an URL before outputting it back in an attr...
CVE-2022-3420MEDIUM4.8The Official Integration for Billingo WordPress plugin before 3.4.0 does not sanitise and escape some of its settings, w...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now