2022 CVE Vulnerabilities

27,531 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-21593HIGH7.1Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: OHS Config MBeans). Supported ve...
CVE-2022-21592MEDIUM4.3Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Encryption). Supported versions ...
CVE-2022-21591MEDIUM5.4Vulnerability in the Oracle Transportation Management product of Oracle Supply Chain (component: UI Infrastructure). Sup...
CVE-2022-21590HIGH7.6Vulnerability in the Oracle BI Publisher product of Oracle Fusion Middleware (component: Core Formatting API). Supported...
CVE-2022-21589MEDIUM4.3Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Privileges). Supported versions ...
CVE-2022-21587CRITICAL9.8Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: Upload). ...
CVE-2022-3595MEDIUM5.5A vulnerability was found in Linux Kernel. It has been rated as problematic. Affected by this issue is the function sess...
CVE-2022-3594MEDIUM5.3A vulnerability was found in Linux Kernel. It has been declared as problematic. Affected by this vulnerability is the fu...
CVE-2022-3593Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2022-42188HIGH7.5In Lavalite 9.0.0, the XSRF-TOKEN cookie is vulnerable to path traversal attacks, enabling read access to arbitrary file...
CVE-2022-39198CRITICAL9.8A deserialization vulnerability existed in dubbo hessian-lite 3.2.12 and its earlier versions, which could lead to malic...
CVE-2022-43260CRITICAL9.8Tenda AC18 V15.03.05.19(6318) was discovered to contain a stack overflow via the time parameter in the fromSetSysTime fu...
CVE-2022-43259HIGH7.5Tenda AC15 V15.03.05.18 was discovered to contain a stack overflow via the timeZone parameter in the form_fast_setting_w...
CVE-2022-41547HIGH7.5Mobile Security Framework (MobSF) v0.9.2 and below was discovered to contain a local file inclusion (LFI) vulnerability ...
CVE-2022-41544CRITICAL9.8GetSimple CMS v3.3.16 was discovered to contain a remote code execution (RCE) vulnerability via the edited_file paramete...
CVE-2022-41541HIGH8.1TP-Link AX10v1 V1_211117 allows attackers to execute a replay attack by using a previously transmitted encrypted authent...
CVE-2022-41540MEDIUM5.9The web app client of TP-Link AX10v1 V1_211117 uses hard-coded cryptographic keys when communicating with the router. At...
CVE-2022-41537HIGH7.2Online Tours & Travels Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via the c...
CVE-2022-33874CRITICAL9.8An improper neutralization of special elements used in an OS Command ('OS Command Injection') vulnerabilities [CWE-78] i...
CVE-2022-33873CRITICAL9.8An improper neutralization of special elements used in an OS Command ('OS Command Injection') vulnerabilities [CWE-78] i...
CVE-2022-33872CRITICAL9.8An improper neutralization of special elements used in an OS Command ('OS Command Injection') vulnerabilities [CWE-78] i...
CVE-2022-29055HIGH7.5A access of uninitialized pointer in Fortinet FortiOS version 7.2.0, 7.0.0 through 7.0.5, 6.4.0 through 6.4.8, 6.2.0 thr...
CVE-2022-41504HIGH7.2An arbitrary file upload vulnerability in the component /php_action/editProductImage.php of Billing System Project v1.0 ...
CVE-2022-41479HIGH7.5The DevExpress Resource Handler (ASPxHttpHandlerModule) in DevExpress ASP.NET Web Forms Build v19.2.3 does not verify th...
CVE-2022-40684CRITICAL9.8An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 an...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now