2022 CVE Vulnerabilities

27,538 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-41538HIGH8.8Wedding Planner v1.0 was discovered to contain an arbitrary file upload vulnerability in the component /Wedding-Manageme...
CVE-2022-36803HIGH8.8The MasterUserEdit API in Atlassian Jira Align Server before version 10.109.2 allows An authenticated attacker with the ...
CVE-2022-36802MEDIUM4.9The ManageJiraConnectors API in Atlassian Jira Align before version 10.109.2 allows remote attackers to exploit this iss...
CVE-2022-42722MEDIUM5.5In the Linux kernel 5.8 through 5.19.x before 5.19.16, local attackers able to inject WLAN frames into the mac80211 stac...
CVE-2022-42721MEDIUM5.5A list management bug in BSS handling in the mac80211 stack in the Linux kernel 5.1 through 5.19.x before 5.19.16 could ...
CVE-2022-42720HIGH7.8Various refcounting bugs in the multi-BSS handling in the mac80211 stack in the Linux kernel 5.1 through 5.19.x before 5...
CVE-2022-41674HIGH8.1An issue was discovered in the Linux kernel before 5.19.16. Attackers able to inject WLAN frames could cause a buffer ov...
CVE-2022-39302MEDIUM5.4Ree6 is a moderation bot. This vulnerability would allow other server owners to create configurations such as "Better-Au...
CVE-2022-42719HIGH8.8A use-after-free in the mac80211 stack when parsing a multi-BSSID element in the Linux kernel 5.2 through 5.19.x before ...
CVE-2022-41391CRITICAL9.8OcoMon v4.0 was discovered to contain a SQL injection vulnerability via the cod parameter at showImg.php.
CVE-2022-41390CRITICAL9.8OcoMon v4.0 was discovered to contain a SQL injection vulnerability via the cod parameter at download.php.
CVE-2022-39303CRITICAL9.8Ree6 is a moderation bot. This vulnerability allows manipulation of SQL queries. This issue has been patched in version ...
CVE-2022-39295MEDIUM6.1Knowage is an open source suite for modern business analytics alternative over big data systems. KnowageLabs / Knowage-S...
CVE-2022-39278HIGH7.5Istio is an open platform-independent service mesh that provides traffic management, policy enforcement, and telemetry c...
CVE-2022-39229MEDIUM4.3Grafana is an open source data visualization platform for metrics, logs, and traces. Versions prior to 9.1.8 and 8.5.14 ...
CVE-2022-39201HIGH7.5Grafana is an open source observability and data visualization platform. Starting with version 5.0.0-beta1 and prior to ...
CVE-2022-35612MEDIUM5.4A cross-site scripting (XSS) vulnerability in MQTTRoute v3.3 and below allows attackers to execute arbitrary web scripts...
CVE-2022-35611MEDIUM4.3A Cross-Site Request Forgery (CSRF) in MQTTRoute v3.3 and below allows attackers to create and remove dashboards.
CVE-2022-35136MEDIUM6.5Boodskap IoT Platform v4.4.9-02 allows attackers to make unauthenticated API requests.
CVE-2022-35135HIGH8.8Boodskap IoT Platform v4.4.9-02 allows attackers to escalate privileges via a crafted request sent to /api/user/upsert/<...
CVE-2022-35134MEDIUM5.4Boodskap IoT Platform v4.4.9-02 contains a cross-site scripting (XSS) vulnerability.
CVE-2022-34022HIGH7.2SQL injection vulnerability in ResIOT IOT Platform + LoRaWAN Network Server through 4.1.1000114 via a crafted POST reque...
CVE-2022-34021MEDIUM5.4Multiple Cross Site Scripting (XSS) vulnerabilities in ResIOT IOT Platform + LoRaWAN Network Server through 4.1.1000114 ...
CVE-2022-31130HIGH7.5Grafana is an open source observability and data visualization platform. Versions of Grafana for endpoints prior to 9.1....
CVE-2022-39300HIGH8.1node SAML is a SAML 2.0 library based on the SAML implementation of passport-saml. A remote attacker may be able to bypa...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now