2022 CVE Vulnerabilities

27,531 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-37454CRITICAL9.8The Keccak XKCP SHA-3 reference implementation before fdc6fef has an integer overflow and resultant buffer overflow that...
CVE-2022-39823HIGH7.5An issue was discovered in Softing OPC UA C++ SDK 5.66 through 6.x before 6.10. An OPC/UA browse request exceeding the s...
CVE-2022-38108HIGH7.2SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversa...
CVE-2022-37453HIGH7.5An issue was discovered in Softing OPC UA C++ SDK before 6.10. A buffer overflow or an excess allocation happens due to ...
CVE-2022-36966MEDIUM5.4Users with Node Management rights were able to view and edit all nodes due to Insufficient control on URL parameter caus...
CVE-2022-36958HIGH8.8SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversa...
CVE-2022-36957HIGH7.2SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversa...
CVE-2022-3623HIGH7.5A vulnerability was found in Linux Kernel. It has been declared as problematic. Affected by this vulnerability is the fu...
CVE-2022-3621MEDIUM6.5A vulnerability was found in Linux Kernel. It has been classified as problematic. Affected is the function nilfs_bmap_lo...
CVE-2022-3620CRITICAL9.8A vulnerability was found in Exim and classified as problematic. This issue affects the function dmarc_dns_lookup of the...
CVE-2022-3619MEDIUM4.3A vulnerability has been found in Linux Kernel and classified as problematic. This vulnerability affects the function l2...
CVE-2022-42344HIGH8.8Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by an Incorr...
CVE-2022-42233CRITICAL9.8Tenda 11N with firmware version V5.07.33_cn suffers from an Authentication Bypass vulnerability.
CVE-2022-3577HIGH7.8An out-of-bounds memory write flaw was found in the Linux kernel’s Kid-friendly Wired Controller driver. This flaw allow...
CVE-2022-2069HIGH7.8The APDFL.dll in Siemens JT2Go prior to V13.3.0.5 and Siemens Teamcenter Visualization prior to V14.0.0.2 contains an ou...
CVE-2022-42176HIGH7.8In PCTechSoft PCSecure V5.0.8.xw, use of Hard-coded Credentials in configuration files leads to admin panel access.
CVE-2022-42021CRITICAL9.8Best Student Result Management System v1.0 is vulnerable to SQL Injection via /upresult/upresult/notice-details.php?nid=...
CVE-2022-40084MEDIUM5.3OpenCRX before v5.2.2 was discovered to be vulnerable to password enumeration due to the difference in error messages re...
CVE-2022-42201HIGH7.2Simple Exam Reviewer Management System v1.0 is vulnerable to Insecure file upload.
CVE-2022-42200MEDIUM5.4Simple Exam Reviewer Management System v1.0 is vulnerable to Stored Cross Site Scripting (XSS) via the Exam List.
CVE-2022-42199HIGH8.8Simple Exam Reviewer Management System v1.0 is vulnerable to Cross Site Request Forgery (CSRF) via the Exam List.
CVE-2022-42198HIGH8.8In Simple Exam Reviewer Management System v1.0 the User List function suffers from insecure file upload.
CVE-2022-42197MEDIUM6.5In Simple Exam Reviewer Management System v1.0 the User List function has improper access control that allows low privil...
CVE-2022-31366HIGH7.2An arbitrary file upload vulnerability in the apiImportLabs function in api_labs.php of EVE-NG 2.0.3-112 Community allow...
CVE-2022-37598CRITICAL9.8Prototype pollution vulnerability in function DEFNODE in ast.js in mishoo UglifyJS 3.13.2 via the name variable in ast.j...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now