2022 CVE Vulnerabilities

27,538 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-41828HIGH8.1In Amazon AWS Redshift JDBC Driver (aka amazon-redshift-jdbc-driver or redshift-jdbc42) before 2.1.0.8, the Object Facto...
CVE-2022-3364HIGH7.5Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.5.0a3.
CVE-2022-39232MEDIUM4.3Discourse is an open source discussion platform. Starting with version 2.9.0.beta5 and prior to version 2.9.0.beta10, an...
CVE-2022-40472HIGH8ZKTeco Xiamen Information Technology ZKBio Time 8.0.7 Build: 20220721.14829 was discovered to contain a CSV injection vu...
CVE-2022-39226MEDIUM4.3Discourse is an open source discussion platform. In versions prior to 2.8.9 on the `stable` branch and prior to 2.9.0.be...
CVE-2022-36068MEDIUM4.3Discourse is an open source discussion platform. In versions prior to 2.8.9 on the `stable` branch and prior to 2.9.0.be...
CVE-2022-36066HIGH7.2Discourse is an open source discussion platform. In versions prior to 2.8.9 on the `stable` branch and prior to 2.9.0.be...
CVE-2022-35137MEDIUM5.4DGIOT Lightweight industrial IoT v4.5.4 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities.
CVE-2022-33880CRITICAL9.8hms-staff.php in Projectworlds Hospital Management System Mini-Project through 2018-06-17 allows SQL injection via the t...
CVE-2022-39266CRITICAL9.8isolated-vm is a library for nodejs which gives the user access to v8's Isolate interface. In versions 4.3.6 and prior, ...
CVE-2022-40887CRITICAL9.8SourceCodester Best Student Result Management System 1.0 is vulnerable to SQL Injection.
CVE-2022-40879MEDIUM6.1kkFileView v4.1.0 is vulnerable to Cross Site Scripting (XSS) via the parameter 'errorMsg.'
CVE-2022-29504Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this ca...
CVE-2022-29503CRITICAL9.8A memory corruption vulnerability exists in the libpthread linuxthreads functionality of uClibC 0.9.33.2 and uClibC-ng 1...
CVE-2022-40931MEDIUM6.1dutchcoders Transfer.sh 1.4.0 is vulnerable to Cross Site Scripting (XSS).
CVE-2022-39168HIGH7.5IBM Robotic Process Automation Clients are vulnerable to proxy credentials being exposed in upgrade logs. IBM X-Force ID...
CVE-2022-39254MEDIUM6.5matrix-nio is a Python Matrix client library, designed according to sans I/O principles. Prior to version 0.20, when a u...
CVE-2022-39252HIGH7.5matrix-rust-sdk is an implementation of a Matrix client-server library in Rust, and matrix-sdk-crypto is the Matrix encr...
CVE-2022-38732HIGH7.5SnapCenter versions prior to 4.7 shipped without Content Security Policy (CSP) implemented which could allow certain typ...
CVE-2022-40408MEDIUM5.4FeehiCMS v2.1.1 was discovered to contain a cross-site scripting (XSS) vulnerability via a crafted payload injected into...
CVE-2022-40407HIGH8.8A zip slip vulnerability in the file upload function of Chamilo v1.11 allows attackers to execute arbitrary code via a c...
CVE-2022-40890HIGH7.5A vulnerability in /src/amf/amf-context.c in Open5GS 2.4.10 and earlier leads to AMF denial of service.
CVE-2022-40363MEDIUM5.5A buffer overflow in the component nfc_device_load_mifare_ul_data of Flipper Devices Inc., Flipper Zero before v0.65.2 a...
CVE-2022-39250HIGH7.5Matrix JavaScript SDK is the Matrix Client-Server software development kit (SDK) for JavaScript. Prior to version 19.7.0...
CVE-2022-40475CRITICAL9.8TOTOLINK A860R V4.1.2cu.5182_B20201027 was discovered to contain a command injection via the component /cgi-bin/download...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now