2022 CVE Vulnerabilities

27,538 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-36362HIGH7.5A vulnerability has been identified in LOGO! 12/24RCE (6ED1052-1MD08-0BA1) (All versions), LOGO! 12/24RCE (6ED1052-1MD08...
CVE-2022-36361CRITICAL9.8A vulnerability has been identified in LOGO! 12/24RCE (6ED1052-1MD08-0BA1) (All versions), LOGO! 12/24RCEo (6ED1052-2MD0...
CVE-2022-36360HIGH7.5A vulnerability has been identified in LOGO! 8 BM (incl. SIPLUS variants) (All versions < V8.3). Affected devices load f...
CVE-2022-31766HIGH8.6A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V7.1.2), RUGGEDC...
CVE-2022-31765HIGH8.8Affected devices do not properly authorize the change password function of the web interface. This could allow low priv...
CVE-2022-37616CRITICAL9.8A prototype pollution vulnerability exists in the function copy in dom.js in the xmldom (published as @xmldom/xmldom) pa...
CVE-2022-40138CRITICAL9.8An integer conversion error in Hermes bytecode generation, prior to commit 6aa825e480d48127b480b08d13adf70033237097, cou...
CVE-2022-35289CRITICAL9.8A write-what-where condition in hermes caused by an integer overflow, prior to commit 5b6255ae049fa4641791e47fad994e8e8c...
CVE-2022-32234CRITICAL9.8An out of bounds write in hermes, while handling large arrays, prior to commit 06eaec767e376bfdb883d912cb15e987ddf2bda1 ...
CVE-2022-3433MEDIUM6.5The aeson library is not safe to use to consume untrusted JSON input. A remote user could abuse this flaw to produce a h...
CVE-2022-41749HIGH7.8An origin validation error vulnerability in Trend Micro Apex One agents could allow a local attacker to escalate privile...
CVE-2022-41748MEDIUM6.7A registry permissions vulnerability in the Trend Micro Apex One Data Loss Prevention (DLP) module could allow a local a...
CVE-2022-41747HIGH7.8An improper certification validation vulnerability in Trend Micro Apex One agents could allow a local attacker to load a...
CVE-2022-41746CRITICAL9.1A forced browsing vulnerability in Trend Micro Apex One could allow an attacker with access to the Apex One console on a...
CVE-2022-41745HIGH7An Out-of-Bounds access vulnerability in Trend Micro Apex One could allow a local attacker to create a specially crafted...
CVE-2022-41744HIGH7A Time-of-Check Time-Of-Use vulnerability in the Trend Micro Apex One Vulnerability Protection integrated component coul...
CVE-2022-3220MEDIUM4.8The Advanced Comment Form WordPress plugin before 1.2.1 does not sanitise and escape its settings, allowing high privile...
CVE-2022-3209MEDIUM6.1The soledad WordPress theme before 8.2.5 does not sanitise the {id,datafilter[type],...} parameters in its penci_more_sl...
CVE-2022-3208MEDIUM6.5The Simple File List WordPress plugin before 4.4.12 does not implement nonce checks, which could allow attackers to make...
CVE-2022-3207MEDIUM4.8The Simple File List WordPress plugin before 4.4.12 does not sanitise and escape some of its settings, which could allow...
CVE-2022-3154HIGH7.1The Woo Billingo Plus WordPress plugin before 4.4.5.4, Integration for Billingo & Gravity Forms WordPress plugin before ...
CVE-2022-3137MEDIUM5.4The Taskbuilder WordPress plugin before 1.0.8 does not validate and sanitise task's attachments, which could allow any a...
CVE-2022-3136MEDIUM4.8The Social Rocket WordPress plugin before 1.3.3 does not sanitise and escape some of its settings, which could allow hig...
CVE-2022-39288HIGH7.5fastify is a fast and low overhead web framework, for Node.js. Affected versions of fastify are subject to a denial of s...
CVE-2022-36063CRITICAL9.8Azure RTOS USBx is a USB host, device, and on-the-go (OTG) embedded stack, fully integrated with Azure RTOS ThreadX and ...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now