2022 CVE Vulnerabilities

27,538 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-39261HIGH7.5Twig is a template language for PHP. Versions 1.x prior to 1.44.7, 2.x prior to 2.15.3, and 3.x prior to 3.4.3 encounter...
CVE-2022-28816MEDIUM6.1In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 the Sentilo Proxy is prone to refl...
CVE-2022-28815LOW2.7In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 the Sentilo Proxy server was disco...
CVE-2022-28814CRITICAL9.8Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 was discovered to be vulnerable to a ...
CVE-2022-28813HIGH7.5In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 a remote, unauthenticated attacker...
CVE-2022-28812CRITICAL9.8In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 a remote, unauthenticated attacker...
CVE-2022-28811CRITICAL9.8In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 a remote, unauthenticated attacker...
CVE-2022-22526CRITICAL9.8In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 a missing authentication allows fo...
CVE-2022-22525HIGH7.2In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 an remote attacker with admin righ...
CVE-2022-22524CRITICAL9.4In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 an unauthenticated remote attacker...
CVE-2022-22523HIGH7.5An improper authentication vulnerability exists in the Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server...
CVE-2022-22522CRITICAL9.8In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 a remote, unauthenticated attacker...
CVE-2022-40486HIGH8.8TP Link Archer AX10 V1 Firmware Version 1.3.1 Build 20220401 Rel. 57450(5553) was discovered to allow authenticated atta...
CVE-2022-3349MEDIUM6.8A vulnerability was found in Sony PS4 and PS5. It has been classified as critical. This affects the function UVFAT_readu...
CVE-2022-2760MEDIUM4.3In affected versions of Octopus Deploy it is possible to reveal the Space ID of spaces that the user does not have acces...
CVE-2022-30935CRITICAL9.1An authorization bypass in b2evolution allows remote, unauthenticated attackers to predict password reset tokens for any...
CVE-2022-32170MEDIUM4.3The “Bytebase” application does not restrict low privilege user to access admin “projects“ for which an unauthorized use...
CVE-2022-32169MEDIUM4.3The “Bytebase” application does not restrict low privilege user to access “admin issues“ for which an unauthorized user ...
CVE-2022-32166MEDIUM6.1In ovs versions v0.90.0 through v2.5.0 are vulnerable to heap buffer over-read in flow.c. An unsafe comparison of “minim...
CVE-2022-3348MEDIUM4.9Just like in the previous report, an attacker could steal the account of different users. But in this case, it's a littl...
CVE-2022-32168HIGH7.8Notepad++ versions 8.4.1 and before are vulnerable to DLL hijacking where an attacker can replace the vulnerable dll (Ux...
CVE-2022-3333MEDIUM5.4A vulnerability, which was classified as problematic, was found in Zephyr Project Manager up to 3.2.4. Affected is an un...
CVE-2022-3332CRITICAL9.8A vulnerability classified as critical has been found in SourceCodester Food Ordering Management System. This affects an...
CVE-2022-39054MEDIUM6.1Cowell enterprise travel management system has insufficient filtering for special characters within web URL. An unauthen...
CVE-2022-39053MEDIUM6.1Heimavista Rpage has insufficient filtering for platform web URL. An unauthenticated remote attacker can inject JavaScri...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now