2022 CVE Vulnerabilities

27,525 CVEs published in 2022.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2022-43938HIGH8.8 Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.1 and 9.3.0.2, including 8.3.x cannot allow a...
CVE-2022-43773HIGH8.8 Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.1 and 9.3.0.2, including 8.3.x is installed w...
CVE-2022-43769HIGH7.2Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.1 and 9.3.0.2, including 8.3.x allow certain w...
CVE-2022-38072HIGH8.8An improper array index validation vulnerability exists in the stl_fix_normal_directions functionality of ADMesh Master ...
CVE-2022-36440HIGH7.5A reachable assertion was found in Frrouting frr-bgpd 8.3.0 in the peek_for_as4_capability function. Attackers can malic...
CVE-2022-42447HIGH8.8HCL Compass is vulnerable to Cross-Origin Resource Sharing (CORS). This vulnerability can allow an unprivileged remote a...
CVE-2022-47192HIGH8.8Generex UPS CS141 below 2.06 version, could allow a remote attacker to upload a backup file containing a modified "users...
CVE-2022-47191HIGH8.8Generex UPS CS141 below 2.06 version, could allow a remote attacker to upload a firmware file containing a file with mod...
CVE-2022-47188HIGH7.5There is an arbitrary file reading vulnerability in Generex UPS CS141 below 2.06 version. An attacker, making use of the...
CVE-2022-46021HIGH7.5X-Man 1.0 has a SQL injection vulnerability, which can cause data leakage.
CVE-2022-4899HIGH7.5A vulnerability was found in zstd v1.4.10, where an attacker can supply empty string as an argument to the command line ...
CVE-2022-4744HIGH7.8A double-free flaw was found in the Linux kernel’s TUN/TAP device driver functionality in how a user registers the devic...
CVE-2022-47542HIGH8.8Red Gate SQL Monitor 11.0.14 through 12.1.46 has Incorrect Access Control, exploitable remotely for Escalation of Privil...
CVE-2022-23522HIGH8.8MindsDB is an open source machine learning platform. An unsafe extraction is being performed using `shutil.unpack_archiv...
CVE-2022-30351HIGH7.5PDFZorro PDFZorro Online r20220428 using TCPDF 6.2.5, despite having workflows claiming to correctly remove redacted inf...
CVE-2022-30350HIGH7.5Avanquest Software RAD PDF (PDFEscape Online) 3.19.2.2 is vulnerable to Information Leak / Disclosure. The PDFEscape Onl...
CVE-2022-3787HIGH7.8A vulnerability was found in the device-mapper-multipath. The device-mapper-multipath allows local users to obtain root ...
CVE-2022-44370HIGH7.8NASM v2.16 was discovered to contain a heap buffer overflow in the component quote_for_pmake() asm/nasm.c:856
CVE-2022-45355HIGH7.2Auth. (admin+) SQL Injection (SQLi) vulnerability in ThimPress WP Pipes plugin <= 1.33 versions.
CVE-2022-43650HIGH7.1This vulnerability allows remote attackers to disclose sensitive information on affected installations of RARLAB WinRAR ...
CVE-2022-43649HIGH7.8This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 12.0....
CVE-2022-43648HIGH8.8This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-3...
CVE-2022-43647HIGH8.8This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-8...
CVE-2022-43646HIGH8.8This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-8...
CVE-2022-43645HIGH8.8This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-8...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now