2022 CVE Vulnerabilities

27,538 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-41473MEDIUM6.1RPCMS v3.0.2 was discovered to contain a reflected cross-site scripting (XSS) vulnerability in the Search function.
CVE-2022-42889CRITICAL9.8Apache Commons Text performs variable interpolation, allowing properties to be dynamically evaluated and expanded. The s...
CVE-2022-38902MEDIUM5.4A Cross-site scripting (XSS) vulnerability in the Blog module - add new topic functionality in Liferay Digital Experienc...
CVE-2022-24697CRITICAL9.8Kylin's cube designer function has a command injection vulnerability when overwriting system parameters in the configura...
CVE-2022-37208HIGH8.8JFinal CMS 5.1.0 is vulnerable to SQL Injection. These interfaces do not use the same component, nor do they have filter...
CVE-2022-35081MEDIUM5.5SWFTools commit 772e55a2 was discovered to contain a heap-buffer overflow via png_read_header at /src/png2swf.c.
CVE-2022-35080MEDIUM5.5SWFTools commit 772e55a2 was discovered to contain a heap-buffer overflow via png_load at /lib/png.c.
CVE-2022-2828MEDIUM6.5In affected versions of Octopus Server it is possible to reveal information about teams via the API due to an Insecure D...
CVE-2022-3473MEDIUM6.5A vulnerability classified as critical has been found in SourceCodester Human Resource Management System. This affects a...
CVE-2022-3472MEDIUM4.9A vulnerability was found in SourceCodester Human Resource Management System. It has been rated as critical. Affected by...
CVE-2022-3471MEDIUM4.9A vulnerability was found in SourceCodester Human Resource Management System. It has been declared as critical. Affected...
CVE-2022-3470MEDIUM6.5A vulnerability was found in SourceCodester Human Resource Management System. It has been classified as critical. Affect...
CVE-2022-42906HIGH7.8powerline-gitstatus (aka Powerline Gitstatus) before 1.3.2 allows arbitrary code execution. git repositories can contain...
CVE-2022-42902HIGH8.8In Linaro Automated Validation Architecture (LAVA) before 2022.10, there is dynamic code execution in lava_server/lavata...
CVE-2022-42901HIGH7.8Bentley MicroStation and MicroStation-based applications may be affected by out-of-bounds and stack overflow issues when...
CVE-2022-42900HIGH7.8Bentley MicroStation and MicroStation-based applications may be affected by out-of-bounds read issues when opening craft...
CVE-2022-42899HIGH7.8Bentley MicroStation and MicroStation-based applications may be affected by out-of-bounds read and stack overflow issues...
CVE-2022-40187HIGH8Foresight GC3 Launch Monitor 1.3.15.68 ships with a Target Communication Framework (TCF) service enabled. This service l...
CVE-2022-34020HIGH8.8Cross Site Request Forgery (CSRF) vulnerability in ResIOT ResIOT IOT Platform + LoRaWAN Network Server through 4.1.10001...
CVE-2022-42897CRITICAL9.8Array Networks AG/vxAG with ArrayOS AG before 9.4.0.469 allows unauthenticated command injection that leads to privilege...
CVE-2022-3171HIGH7.5A parsing issue with binary data in protobuf-java core and lite versions prior to 3.21.7, 3.20.3, 3.19.6 and 3.16.3 can ...
CVE-2022-39298CRITICAL9.8MelisFront is the engine that displays website hosted on Melis Platform. It deals with showing pages, plugins, URL rewri...
CVE-2022-39297CRITICAL9.8MelisCms provides a full CMS for Melis Platform, including templating system, drag'n'drop of plugins, SEO and many admin...
CVE-2022-39283HIGH7.5FreeRDP is a free remote desktop protocol library and clients. All FreeRDP based clients when using the `/video` command...
CVE-2022-39282HIGH7.5FreeRDP is a free remote desktop protocol library and clients. FreeRDP based clients on unix systems using `/parallel` c...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now