2022 CVE Vulnerabilities

27,531 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-43286CRITICAL9.8Nginx NJS v0.7.2 was discovered to contain a heap-use-after-free bug caused by illegal memory copy in the function njs_j...
CVE-2022-43285HIGH7.5Nginx NJS v0.7.4 was discovered to contain a segmentation violation in njs_promise_reaction_job. NOTE: the vendor disput...
CVE-2022-43284HIGH7.5Nginx NJS v0.7.2 to v0.7.4 was discovered to contain a segmentation violation via njs_scope_valid_value at njs_scope.h. ...
CVE-2022-43283MEDIUM5.5wasm2c v1.0.29 was discovered to contain an abort in CWriter::Write.
CVE-2022-43282HIGH7.1wasm-interp v1.0.29 was discovered to contain an out-of-bounds read via the component OnReturnCallIndirectExpr->GetRetur...
CVE-2022-43281HIGH7.8wasm-interp v1.0.29 was discovered to contain a heap overflow via the component std::vector<wabt::Type, std::allocator<w...
CVE-2022-43280HIGH7.1wasm-interp v1.0.29 was discovered to contain an out-of-bounds read via the component OnReturnCallExpr->GetReturnCallDro...
CVE-2022-37621CRITICAL9.8Prototype pollution vulnerability in function resolveShims in resolve-shims.js in thlorenz browserify-shim 3.8.15 via th...
CVE-2022-3708HIGH8.1The Web Stories plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including 1.24....
CVE-2022-3402MEDIUM6.1The Log HTTP Requests plugin for WordPress is vulnerable to Stored Cross-Site Scripting via logged HTTP requests in vers...
CVE-2022-3401HIGH8.8The Bricks theme for WordPress is vulnerable to remote code execution due to the theme allowing site editors to include ...
CVE-2022-43233HIGH7.2Canteen Management System v1.0 was discovered to contain a SQL injection vulnerability via the userid parameter at /php_...
CVE-2022-43232HIGH7.2Canteen Management System v1.0 was discovered to contain a SQL injection vulnerability via the userid parameter at /php_...
CVE-2022-43231HIGH7.2Canteen Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via /youthappam/manage_w...
CVE-2022-43230HIGH7.2Simple Cold Storage Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter ...
CVE-2022-43229HIGH7.2Simple Cold Storage Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter ...
CVE-2022-43228HIGH7.2Barangay Management System v1.0 was discovered to contain a SQL injection vulnerability via the hidden_id parameter at /...
CVE-2022-41648CRITICAL9.8The HEIDENHAIN Controller TNC 640 NC software Version 340590 07 SP5, is vulnerable to improper authentication in its DNC...
CVE-2022-41636HIGH7.5Communication traffic involving "Ethernet Q Commands" service of Haas Controller version 100.20.000.1110 is transmitted ...
CVE-2022-3228MEDIUM6.5Using custom code, an attacker can write into name or description fields larger than the appropriate buffer size causing...
CVE-2022-2475HIGH8.8Haas Controller version 100.20.000.1110 has insufficient granularity of access control when using the "Ethernet Q Comman...
CVE-2022-2474HIGH8Authentication is currently unsupported in Haas Controller version 100.20.000.1110 when using the “Ethernet Q Commands” ...
CVE-2022-43170MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in the Dashboard Configuration feature (index.php?module=dashboard_con...
CVE-2022-43169MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in the Users Access Groups feature (/index.php?module=users_groups/use...
CVE-2022-43168CRITICAL9.8Rukovoditel v3.2.1 was discovered to contain a SQL injection vulnerability via the reports_id parameter.

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now