2022 CVE Vulnerabilities

27,525 CVEs published in 2022.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2022-34292HIGH7.1Docker Desktop for Windows before 4.6.0 allows attackers to overwrite any file through a symlink attack on the hyperv/cr...
CVE-2022-31647HIGH7.1Docker Desktop before 4.6.0 on Windows allows attackers to delete any file through the hyperv/destroy dockerBackendV2 AP...
CVE-2022-45456HIGH7.5Denial of service due to unauthenticated API endpoint. The following products are affected: Acronis Agent (Windows, macO...
CVE-2022-44232HIGH7.5libming 0.4.8 0.4.8 is vulnerable to Buffer Overflow. In getInt() in decompile.c unknown type may lead to denial of serv...
CVE-2022-27978HIGH7.5Tooljet v1.6 does not properly handle missing values in the API, allowing attackers to arbitrarily reset passwords via a...
CVE-2022-25277HIGH7.2Drupal core sanitizes filenames with dangerous extensions upon upload (reference: SA-CORE-2020-012) and strips leading a...
CVE-2022-25275HIGH7.5In some situations, the Image module does not correctly check access to image files not stored in the standard public fi...
CVE-2022-25273HIGH7.5Drupal core's form API has a vulnerability where certain contributed or custom modules' forms may be vulnerable to impro...
CVE-2022-41739HIGH8.4 IBM Spectrum Scale (IBM Spectrum Scale Container Native Storage Access 5.1.2.1 through 5.1.6.0) could allow programs ru...
CVE-2022-36769HIGH7.2 IBM Cloud Pak for Data 4.5 and 4.6 could allow a privileged user to upload malicious files of dangerous types that can ...
CVE-2022-45291HIGH7.2PWS Personal Weather Station Dashboard (PWS_Dashboard) LTS December 2020 (2012_lts) allows remote code execution by inje...
CVE-2022-40724HIGH8.8The PingFederate Local Identity Profiles '/pf/idprofile.ping' endpoint is vulnerable to Cross-Site Request Forgery (CSRF...
CVE-2022-31244HIGH7.8Nokia OneNDS 17r2 has Insecure Permissions vulnerability that allows for privilege escalation.
CVE-2022-42335HIGH7.8x86 shadow paging arbitrary pointer dereference In environments where host assisted address translation is necessary but...
CVE-2022-48476HIGH7.5In JetBrains Ktor before 2.3.0 path traversal in the `resolveResource` method was possible
CVE-2022-45080HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in KrishaWeb Add Multiple Marker plugin <= 1.2 versions.
CVE-2022-45074HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Paramveer Singh for Arete IT Private Limited Activity Reactions For B...
CVE-2022-4944HIGH8.8A vulnerability, which was classified as problematic, has been found in kalcaddle KodExplorer up to 4.49. Affected by th...
CVE-2022-47505HIGH7.8The SolarWinds Platform was susceptible to the Local Privilege Escalation Vulnerability. This vulnerability allows a loc...
CVE-2022-36963HIGH7.2The SolarWinds Platform was susceptible to the Command Injection Vulnerability. This vulnerability allows a remote adver...
CVE-2022-36788HIGH7.8A heap-based buffer overflow vulnerability exists in the TriangleMesh clone functionality of Slic3r libslic3r 1.3.0 and ...
CVE-2022-46302HIGH8.8Broad access controls could allow site users to directly interact with the system Apache installation when providing the...
CVE-2022-29608HIGH7.5An issue was discovered in ONOS 2.5.1. An intent with a port that is an intermediate point of its path installs an inval...
CVE-2022-29607HIGH7.5An issue was discovered in ONOS 2.5.1. Modification of an existing intent to have the same source and destination shows ...
CVE-2022-29605HIGH7.5An issue was discovered in ONOS 2.5.1. IntentManager attempts to install the IPv6 flow rules of an intent into an OpenFl...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now