2022 CVE Vulnerabilities

27,525 CVEs published in 2022.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2022-40288CRITICAL9 The application was vulnerable to an authenticated Stored Cross-Site Scripting (XSS) in the user profile data fields, w...
CVE-2022-40287CRITICAL9 The application was found to be vulnerable to an authenticated Stored Cross-Site Scripting (XSS) vulnerability in messa...
CVE-2022-40190CRITICAL9.6SAUTER Controls moduWeb firmware version 2.7.1 is vulnerable to reflective cross-site scripting (XSS). The web applicati...
CVE-2022-41779CRITICAL9.8 Delta Electronics InfraSuite Device Master versions 00.00.01a and prior deserialize network packets without proper veri...
CVE-2022-41772CRITICAL9.8 Delta Electronics InfraSuite Device Master Versions 00.00.01a and prior mishandle .ZIP archives containing characters u...
CVE-2022-41657CRITICAL9.8 Delta Electronics InfraSuite Device Master Versions 00.00.01a and prior allow attacker provided data already serialized...
CVE-2022-41629CRITICAL9.1 Delta Electronics InfraSuite Device Master versions 00.00.01a and prior allow unauthenticated users to access the aprun...
CVE-2022-40202CRITICAL9.8 The database backup function in Delta Electronics InfraSuite Device Master Versions 00.00.01a and prior lacks proper au...
CVE-2022-38142CRITICAL9.8 Delta Electronics InfraSuite Device Master versions 00.00.01a and prior deserialize user-supplied data provided through...
CVE-2022-31692CRITICAL9.8Spring Security, versions 5.7 prior to 5.7.5 and 5.6 prior to 5.6.9 could be susceptible to authorization rules bypass v...
CVE-2022-28763CRITICAL9.6The Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.12.2 is susceptible to a URL...
CVE-2022-27583CRITICAL9.1A remote unprivileged attacker can interact with the configuration interface of a Flexi-Compact FLX3-CPUC1 or FLX3-CPUC2...
CVE-2022-40471CRITICAL9.8Remote Code Execution in Clinic's Patient Management System v 1.0 allows Attacker to Upload arbitrary php webshell via p...
CVE-2022-3774CRITICAL9.1A vulnerability was found in SourceCodester Train Scheduler App 1.0 and classified as critical. Affected by this issue i...
CVE-2022-3254CRITICAL9.8The WordPress Classifieds Plugin WordPress plugin before 4.3 does not properly sanitise and escape some parameters befor...
CVE-2022-3771CRITICAL9.8A vulnerability, which was classified as critical, has been found in easyii CMS. This issue affects the function file of...
CVE-2022-37623CRITICAL9.8Prototype pollution vulnerability in function resolveShims in resolve-shims.js in thlorenz browserify-shim 3.8.15 via th...
CVE-2022-40741CRITICAL9.8Mail SQR Expert’s specific function has insufficient filtering for special characters. An unauthenticated remote attacke...
CVE-2022-3754CRITICAL9.8Weak Password Requirements in GitHub repository thorsten/phpmyfaq prior to 3.1.8.
CVE-2022-2826CRITICAL9.8An issue has been discovered in GitLab affecting all versions starting from 10.0 before 12.9.8, all versions starting fr...
CVE-2022-43286CRITICAL9.8Nginx NJS v0.7.2 was discovered to contain a heap-use-after-free bug caused by illegal memory copy in the function njs_j...
CVE-2022-37621CRITICAL9.8Prototype pollution vulnerability in function resolveShims in resolve-shims.js in thlorenz browserify-shim 3.8.15 via th...
CVE-2022-41648CRITICAL9.8The HEIDENHAIN Controller TNC 640 NC software Version 340590 07 SP5, is vulnerable to improper authentication in its DNC...
CVE-2022-43168CRITICAL9.8Rukovoditel v3.2.1 was discovered to contain a SQL injection vulnerability via the reports_id parameter.
CVE-2022-39366CRITICAL9.8DataHub is an open-source metadata platform. Prior to version 0.8.45, the `StatelessTokenService` of the DataHub metadat...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now