2022 CVE Vulnerabilities

27,525 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-50927HIGH8.5Cyclades Serial Console Server 3.3.0 contains a local privilege escalation vulnerability due to overly permissive sudo p...
CVE-2022-50926CRITICAL9.8WAGO 750-8212 PFC200 G2 2ETH RS firmware contains a privilege escalation vulnerability that allows attackers to manipula...
CVE-2022-50925CRITICAL9.8Prowise Reflect version 1.0.9 contains a remote keystroke injection vulnerability that allows attackers to send keyboard...
CVE-2022-50924HIGH8.5Private Internet Access 3.3 contains an unquoted service path vulnerability that allows local users to potentially execu...
CVE-2022-50923HIGH8.5Cobian Backup 0.9 contains an unquoted service path vulnerability that allows local users to execute arbitrary code with...
CVE-2022-50922CRITICAL9.8Audio Conversion Wizard v2.01 contains a buffer overflow vulnerability that allows attackers to execute arbitrary code b...
CVE-2022-50921HIGH8.5WOW21 5.0.1.9 contains an unquoted service path vulnerability that allows local attackers to potentially execute arbitra...
CVE-2022-50920HIGH8.5Sandboxie-Plus 5.50.2 contains an unquoted service path vulnerability in the SbieSvc Windows service that allows local a...
CVE-2022-50919CRITICAL9.8Tdarr 2.00.15 contains an unauthenticated remote code execution vulnerability in its Help terminal that allows attackers...
CVE-2022-50918HIGH8.5VIVE Runtime Service 1.0.0.4 contains an unquoted service path vulnerability that allows local users to execute arbitrar...
CVE-2022-50917HIGH8.5ProtonVPN 1.26.0 contains an unquoted service path vulnerability in its WireGuard service configuration that allows loca...
CVE-2022-50916HIGH8.7e107 CMS version 3.2.1 contains a file upload vulnerability that allows authenticated administrators to override server ...
CVE-2022-50915HIGH8.5PTPublisher 2.3.4 contains an unquoted service path vulnerability in the PTProtect service that allows local attackers t...
CVE-2022-50914HIGH8.5EaseUS Data Recovery 15.1.0.0 contains an unquoted service path vulnerability in the EaseUS UPDATE SERVICE executable. A...
CVE-2022-50913HIGH8.5ITeC ITeCProteccioAppServer contains an unquoted service path vulnerability that allows local attackers to execute code ...
CVE-2022-50912CRITICAL9.8ImpressCMS 1.4.4 contains a file upload vulnerability with weak extension sanitization that allows attackers to upload p...
CVE-2022-50911Rejected reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue.
CVE-2022-50910CRITICAL9.8Beehive Forum 1.5.2 contains a host header injection vulnerability in the forgot password functionality that allows atta...
CVE-2022-50909HIGH8.8Algo 8028 Control Panel version 3.3.3 contains a command injection vulnerability in the fm-data.lua endpoint that allows...
CVE-2022-50908HIGH7.2Mailhog 1.0.1 contains a stored cross-site scripting vulnerability that allows attackers to inject malicious scripts thr...
CVE-2022-50907HIGH8.6e107 CMS version 3.2.1 contains a file upload vulnerability that allows authenticated administrative users to bypass upl...
CVE-2022-50906MEDIUM4.8e107 CMS 3.2.1 contains an upload restriction bypass vulnerability that allows authenticated administrators to upload ma...
CVE-2022-50905MEDIUM6.1e107 CMS version 3.2.1 contains multiple vulnerabilities that allow cross-site scripting (XSS) attacks. The first vulner...
CVE-2022-50904HIGH8.5Wondershare UBackit 2.0.5 contains an unquoted service path vulnerability that allows local users to potentially execute...
CVE-2022-50903HIGH7.8Wondershare MobileTrans 3.5.9 contains an unquoted service path vulnerability in the ElevationService that allows local ...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now