2022 CVE Vulnerabilities

27,525 CVEs published in 2022.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2022-2052CRITICAL9.8Multiple Trumpf Products in multiple versions use default privileged Windows users and passwords. An adversary may use t...
CVE-2022-42980CRITICAL9.8go-admin (aka GO Admin) 2.0.12 uses the string go-admin as a production JWT key.
CVE-2022-42968CRITICAL9.8Gitea before 1.17.3 does not sanitize and escape refs in the git backend. Arguments to git commands are mishandled.
CVE-2022-41436CRITICAL9.1An issue in OXHOO TP50 OXH1.50 allows unauthenticated attackers to access the administrative panel via browsing to the U...
CVE-2022-38418CRITICAL9.8Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by an Improper Limitation of a...
CVE-2022-35712CRITICAL9.8Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by a Heap-based Buffer Overflo...
CVE-2022-35711CRITICAL9.8Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by a Heap-based Buffer Overflo...
CVE-2022-35710CRITICAL9.8Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by a Stack-based Buffer Overfl...
CVE-2022-35690CRITICAL9.8Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by a Stack-based Buffer Overfl...
CVE-2022-41477CRITICAL9.1A security issue was discovered in WeBid <=1.2.2. A Server-Side Request Forgery (SSRF) vulnerability in the admin/theme....
CVE-2022-41581CRITICAL9.1The HW_KEYMASTER module has a vulnerability of not verifying the data read.Successful exploitation of this vulnerability...
CVE-2022-41580CRITICAL9.8The HW_KEYMASTER module has a vulnerability of not verifying the data read.Successful exploitation of this vulnerability...
CVE-2022-41578CRITICAL9.8The MPTCP module has an out-of-bounds write vulnerability.Successful exploitation of this vulnerability may cause root p...
CVE-2022-38986CRITICAL9.1The HIPP module has a vulnerability of bypassing the check of the data transferred in the kernel space.Successful exploi...
CVE-2022-38983CRITICAL9.8The BT Hfp Client module has a Use-After-Free (UAF) vulnerability.Successful exploitation of this vulnerability may resu...
CVE-2022-38982CRITICAL9.8The fingerprint module has service logic errors.Successful exploitation of this vulnerability will cause the phone lock ...
CVE-2022-38980CRITICAL9.8The HwAirlink module has a heap overflow vulnerability in processing data packets of the proprietary protocol.Successful...
CVE-2022-42064CRITICAL9.8Online Diagnostic Lab Management System version 1.0 remote exploit that bypasses login with SQL injection and then uploa...
CVE-2022-3504CRITICAL9.8A vulnerability was found in SourceCodester Sanitization Management System and classified as critical. This issue affect...
CVE-2022-3439CRITICAL9.8Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.5.0.
CVE-2022-37602CRITICAL9.8Prototype pollution vulnerability in karma-runner grunt-karma 4.0.1 via the key variable in grunt-karma.js.
CVE-2022-32177CRITICAL9In "Gin-Vue-Admin", versions v2.5.1 through v2.5.3beta are vulnerable to Unrestricted File Upload that leads to executio...
CVE-2022-41391CRITICAL9.8OcoMon v4.0 was discovered to contain a SQL injection vulnerability via the cod parameter at showImg.php.
CVE-2022-41390CRITICAL9.8OcoMon v4.0 was discovered to contain a SQL injection vulnerability via the cod parameter at download.php.
CVE-2022-39303CRITICAL9.8Ree6 is a moderation bot. This vulnerability allows manipulation of SQL queries. This issue has been patched in version ...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now