2022 CVE Vulnerabilities

27,538 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-30579HIGH8.4The Web Player component of TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketplace and TIBCO Spotfi...
CVE-2022-41138CRITICAL9.8In Zutty before 0.13, DECRQSS in text written to the terminal can achieve arbitrary code execution.
CVE-2022-40262HIGH8.2A potential attacker can execute an arbitrary code at the time of the PEI phase and influence the subsequent boot stages...
CVE-2022-40261HIGH8.2An attacker can exploit this vulnerability to elevate privileges from ring 0 to ring -2, execute arbitrary code in Syste...
CVE-2022-40250HIGH8.8An attacker can exploit this vulnerability to elevate privileges from ring 0 to ring -2, execute arbitrary code in Syste...
CVE-2022-40246HIGH7.2A potential attacker can write one byte by arbitrary address at the time of the PEI phase (only during S3 resume boot mo...
CVE-2022-39974HIGH7.5WASM3 v0.5.0 was discovered to contain a segmentation fault via the component op_Select_i32_srs in wasm3/source/m3_exec....
CVE-2022-38956MEDIUM5.3An exploitable firmware downgrade vulnerability was discovered on the Netgear WPN824EXT WiFi Range Extender. An attacker...
CVE-2022-38955HIGH7.5An exploitable firmware modification vulnerability was discovered on the Netgear WPN824EXT WiFi Range Extender. An attac...
CVE-2022-38340HIGH7.2Safe Software FME Server v2021.2.5, v2022.0.0.2 and below was discovered to contain a Path Traversal vulnerability via t...
CVE-2022-37265CRITICAL9.8Prototype pollution vulnerability in stealjs steal 2.2.4 via the alias variable in babel.js.
CVE-2022-37259HIGH7.5A Regular Expression Denial of Service (ReDoS) flaw was found in stealjs steal 2.2.4 via the string variable in babel.js...
CVE-2022-37205HIGH8.8JFinal CMS 5.1.0 is affected by: SQL Injection. These interfaces do not use the same component, nor do they have filters...
CVE-2022-2154Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2022-34345. Reason: This candidate is a reservation d...
CVE-2022-26873HIGH8.2A potential attacker can execute an arbitrary code at the time of the PEI phase and influence the subsequent boot stages...
CVE-2022-38916CRITICAL9.8A file upload vulnerability exists in the storage feature of pagekit 1.0.18, which allows an attacker to upload maliciou...
CVE-2022-37204CRITICAL9.8Final CMS 5.1.0 is vulnerable to SQL Injection.
CVE-2022-35196HIGH8.8TestLink v1.9.20 was discovered to contain a Cross-Site Request Forgery (CSRF) via /lib/plan/planView.php.
CVE-2022-32167MEDIUM5.4Cloudreve versions v1.0.0 through v3.5.3 are vulnerable to Stored Cross-Site Scripting (XSS), via the file upload functi...
CVE-2022-40955HIGH8.8In versions of Apache InLong prior to 1.3.0, an attacker with sufficient privileges to specify MySQL JDBC connection URL...
CVE-2022-3245MEDIUM6.1HTML injection attack is closely related to Cross-site Scripting (XSS). HTML injection uses HTML to deface the page. XSS...
CVE-2022-3242MEDIUM6.1Code Injection in GitHub repository microweber/microweber prior to 1.3.2.
CVE-2022-3005MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0.
CVE-2022-2177CRITICAL9.4Kayrasoft product before version 2 has an unauthenticated SQL Injection vulnerability. This is fixed in version 2.
CVE-2022-3079HIGH7.5Festo control block CPX-CEC-C1 and CPX-CMXX in multiple versions allow unauthenticated, remote access to critical webpag...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now