2022 CVE Vulnerabilities

27,538 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-32590MEDIUM6.7In wlan, there is a possible use after free due to an incorrect status check. This could lead to local escalation of pri...
CVE-2022-32589HIGH7.5In Wi-Fi driver, there is a possible way to disconnect Wi-Fi due to an improper resource release. This could lead to rem...
CVE-2022-26475MEDIUM6.7In wlan, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of p...
CVE-2022-26474MEDIUM6.7In sensorhub, there is a possible out of bounds write due to an incorrect calculation of buffer size. This could lead to...
CVE-2022-26473MEDIUM6.7In vdec fmt, there is a possible use after free due to improper locking. This could lead to local escalation of privileg...
CVE-2022-26472HIGH7.8In ims, there is a possible escalation of privilege due to a parcel format mismatch. This could lead to local escalation...
CVE-2022-26471HIGH7.8In telephony, there is a possible escalation of privilege due to a parcel format mismatch. This could lead to local esca...
CVE-2022-26452MEDIUM6.7In isp, there is a possible use after free due to improper locking. This could lead to local escalation of privilege wit...
CVE-2022-42075CRITICAL9.8Wedding Planner v1.0 is vulnerable to arbitrary code execution.
CVE-2022-42074HIGH7.2Online Diagnostic Lab Management System v1.0 is vulnerable to SQL Injection via /diagnostic/editcategory.php?id=.
CVE-2022-42073HIGH7.2Online Diagnostic Lab Management System v1.0 is vulnerable to SQL Injection via /diagnostic/editclient.php?id=.
CVE-2022-41392MEDIUM5.4A cross-site scripting (XSS) vulnerability in TotalJS commit 8c2c8909 allows attackers to execute arbitrary web scripts ...
CVE-2022-41379HIGH7.2An arbitrary file upload vulnerability in the component /leave_system/classes/Users.php?f=save of Online Leave Managemen...
CVE-2022-41378HIGH7.2Online Pet Shop We App v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /pet_shop/ad...
CVE-2022-41377HIGH7.2Online Pet Shop We App v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /pet_shop/ad...
CVE-2022-37896MEDIUM6.1A vulnerability in the Aruba InstantOS and ArubaOS 10 web management interface could allow a remote attacker to conduct ...
CVE-2022-37895MEDIUM4.9An unauthenticated Denial of Service (DoS) vulnerability exists in the handling of certain SSID strings by Aruba Instant...
CVE-2022-37894MEDIUM6.5An unauthenticated Denial of Service (DoS) vulnerability exists in the handling of certain SSID strings by Aruba Instant...
CVE-2022-37893HIGH7.8An authenticated command injection vulnerability exists in the Aruba InstantOS and ArubaOS 10 command line interface. Su...
CVE-2022-42092HIGH7.2Backdrop CMS 1.22.0 has Unrestricted File Upload vulnerability via 'themes' that allows attackers to Remote Code Executi...
CVE-2022-41515HIGH7.2Open Source SACCO Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at...
CVE-2022-41514HIGH7.2Open Source SACCO Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at...
CVE-2022-41513HIGH7.2Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id paramete...
CVE-2022-41512HIGH7.2An arbitrary file upload vulnerability in the component /php_action/editFile.php of Online Diagnostic Lab Management Sys...
CVE-2022-41414MEDIUM5.3An insecure default in the component auth.login.prompt.enabled of Liferay Portal v7.0.0 through v7.4.2 allows attackers ...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now