2022 CVE Vulnerabilities

27,538 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-38932HIGH7.8readelf in ToaruOS 2.0.1 has a global overflow allowing RCE when parsing a crafted ELF file.
CVE-2022-38335MEDIUM5.4Vtiger CRM v7.4.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the e-mail template mo...
CVE-2022-37346CRITICAL9.8EC-CUBE plugin 'Product Image Bulk Upload Plugin' 1.0.0 and 4.1.0 contains an insufficient verification vulnerability wh...
CVE-2022-37209HIGH8.8JFinal CMS 5.1.0 is affected by: SQL Injection. These interfaces do not use the same component, nor do they have filters...
CVE-2022-37193HIGH7.4Chipolo ONE Bluetooth tracker (2020) Chipolo iOS app version 4.13.0 is vulnerable to Incorrect Access Control. Chipolo d...
CVE-2022-37028MEDIUM5.4ISAMS 22.2.3.2 is prone to stored Cross-site Scripting (XSS) attack on the title field for groups, allowing an attacker ...
CVE-2022-34326HIGH7.5In ambiot amb1_sdk (aka SDK for Ameba1) before 2022-06-20 on Realtek RTL8195AM devices before 284241d70308ff2519e40afd7b...
CVE-2022-31367HIGH8.8Strapi before 3.6.10 and 4.x before 4.1.10 mishandles hidden attributes within admin API responses.
CVE-2022-23006MEDIUM6.7A stack-based buffer overflow vulnerability was found on Western Digital My Cloud Home, My Cloud Home Duo, and SanDisk i...
CVE-2022-39258HIGH8.2mailcow is a mailserver suite. A vulnerability innversions prior to 2022-09 allows an attacker to craft a custom Swagger...
CVE-2022-39256HIGH8Orckestra C1 CMS is a .NET based Web Content Management System. A vulnerability in versions prior to 6.13 allows remote ...
CVE-2022-3298HIGH7.5Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.4.8.
CVE-2022-40099HIGH7.2Online Tours & Travels Management System v1.0 was discovered to contain a SQL injection vulnerability via the id paramet...
CVE-2022-40098HIGH7.2Online Tours & Travels Management System v1.0 was discovered to contain a SQL injection vulnerability via the id paramet...
CVE-2022-40097HIGH7.2Online Tours & Travels Management System v1.0 was discovered to contain a SQL injection vulnerability via the id paramet...
CVE-2022-40050CRITICAL9.8ZFile v4.1.1 was discovered to contain an arbitrary file upload vulnerability via the component /file/upload/1.
CVE-2022-30004CRITICAL9.8Sourcecodester Online Market Place Site v1.0 suffers from an unauthenticated blind SQL Injection Vulnerability allowing ...
CVE-2022-3290HIGH7.5Improper Handling of Length Parameter Inconsistency in GitHub repository ikus060/rdiffweb prior to 2.4.8.
CVE-2022-30003MEDIUM5.4Sourcecodester Online Market Place Site 1.0 is vulnerable to Cross Site Scripting (XSS), allowing attackers to register ...
CVE-2022-3272HIGH7.5Improper Handling of Length Parameter Inconsistency in GitHub repository ikus060/rdiffweb prior to 2.4.8.
CVE-2022-22058HIGH7.8Memory corruption due to use after free issue in kernel while processing ION handles in Snapdragon Auto, Snapdragon Comp...
CVE-2022-40784HIGH8.8Unlimited strcpy on user input when setting a locale file leads to stack buffer overflow in mIPC camera firmware 5.3.1.2...
CVE-2022-40044MEDIUM5.4Centreon v20.10.18 was discovered to contain a cross-site scripting (XSS) vulnerability via the esc_name (Escalation Nam...
CVE-2022-40043HIGH8.8Centreon v20.10.18 was discovered to contain a SQL injection vulnerability via the esc_name (Escalation Name) parameter ...
CVE-2022-3201MEDIUM5.4Insufficient validation of untrusted input in DevTools in Google Chrome on Chrome OS prior to 105.0.5195.125 allowed an ...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now