2022 CVE Vulnerabilities

27,538 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-20919HIGH7.5A vulnerability in the processing of malformed Common Industrial Protocol (CIP) packets that are sent to Cisco IOS Softw...
CVE-2022-20856HIGH7.5A vulnerability in the processing of Control and Provisioning of Wireless Access Points (CAPWAP) Mobility messages in Ci...
CVE-2022-20855MEDIUM6.7A vulnerability in the self-healing functionality of Cisco IOS XE Software for Embedded Wireless Controllers on Catalyst...
CVE-2022-20851HIGH7.2A vulnerability in the web UI feature of Cisco IOS XE Software could allow an authenticated, remote attacker to perform ...
CVE-2022-20850HIGH7.1A vulnerability in the CLI of stand-alone Cisco IOS XE SD-WAN Software and Cisco SD-WAN Software could allow an authenti...
CVE-2022-20848HIGH7.5A vulnerability in the UDP processing functionality of Cisco IOS XE Software for Embedded Wireless Controllers on Cataly...
CVE-2022-20847HIGH7.5A vulnerability in the DHCP processing functionality of Cisco IOS XE Wireless Controller Software for the Catalyst 9000 ...
CVE-2022-20844MEDIUM5.3A vulnerability in authentication mechanism of Cisco Software-Defined Application Visibility and Control (SD-AVC) on Cis...
CVE-2022-20818HIGH7.8Multiple vulnerabilities in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to gain elevat...
CVE-2022-20810MEDIUM6.5A vulnerability in the Simple Network Management Protocol (SNMP) of Cisco IOS XE Wireless Controller Software for the Ca...
CVE-2022-20775HIGH7.8A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to gain elevated privil...
CVE-2022-20769MEDIUM6.5A vulnerability in the authentication functionality of Cisco Wireless LAN Controller (WLC) AireOS Software could allow a...
CVE-2022-20728MEDIUM4.7A vulnerability in the client forwarding code of multiple Cisco Access Points (APs) could allow an unauthenticated, adja...
CVE-2022-20662MEDIUM6.8A vulnerability in the smart card login authentication of Cisco Duo for macOS could allow an unauthenticated attacker wi...
CVE-2022-41975HIGH7.8RealVNC VNC Server before 6.11.0 and VNC Viewer before 6.22.826 on Windows allow local privilege escalation via MSI inst...
CVE-2022-41870HIGH7.2AP Manager in Innovaphone before 13r2 Service Release 17 allows command injection via a modified service ID during app u...
CVE-2022-40944CRITICAL9.8Dairy Farm Shop Management System 1.0 is vulnerable to SQL Injection via sales-report-ds.php file.
CVE-2022-40316MEDIUM4.3The H5P activity attempts report did not filter by groups, which in separate groups mode could reveal information to non...
CVE-2022-40315CRITICAL9.8A limited SQL injection risk was identified in the "browse list of users" site administration page.
CVE-2022-40314CRITICAL9.8A remote code execution risk when restoring backup files originating from Moodle 1.9 was identified.
CVE-2022-40313HIGH7.1Recursive rendering of Mustache template helpers containing user input could, in some cases, result in an XSS risk or a ...
CVE-2022-40277HIGH7.8Joplin version 2.8.8 allows an external attacker to execute arbitrary commands remotely on any client that opens a link ...
CVE-2022-40274HIGH7.8Gridea version 0.9.3 allows an external attacker to execute arbitrary code remotely on any client attempting to view a m...
CVE-2022-36965MEDIUM6.1Insufficient sanitization of inputs in QoE application input field could lead to stored and Dom based XSS attack. This i...
CVE-2022-36961HIGH8.8A vulnerable component of Orion Platform was vulnerable to SQL Injection, an authenticated attacker could leverage this ...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now