2022 CVE Vulnerabilities

27,538 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-36536CRITICAL9.8An issue in the component post_applogin.php of Super Flexible Software GmbH & Co. KG Syncovery 9 for Linux v9.47x and be...
CVE-2022-36534HIGH8.8Super Flexible Software GmbH & Co. KG Syncovery 9 for Linux v9.47x and below was discovered to contain multiple remote c...
CVE-2022-36533MEDIUM5.4Super Flexible Software GmbH & Co. KG Syncovery 9 for Linux v9.47x and below was discovered to contain a cross-site scri...
CVE-2022-36532HIGH8.8Bolt CMS contains a vulnerability in version 5.1.12 and below that allows an authenticated user with the ROLE_EDITOR pri...
CVE-2022-35415HIGH7.8An improper input validation in NI System Configuration Manager before 22.5 may allow a privileged user to potentially e...
CVE-2022-34002MEDIUM6.5The ‘document’ parameter of PDS Vista 7’s /application/documents/display.aspx page is vulnerable to a Local File Inclusi...
CVE-2022-26959CRITICAL9.8There are two full (read/write) Blind/Time-based SQL injection vulnerabilities in the Northstar Club Management version ...
CVE-2022-39215MEDIUM5.8Tauri is a framework for building binaries for all major desktop platforms. Due to missing canonicalization when `readDi...
CVE-2022-39213HIGH7.5go-cvss is a Go module to manipulate Common Vulnerability Scoring System (CVSS). In affected versions when a full CVSS v...
CVE-2022-36075MEDIUM4.3Nextcloud files access control is a nextcloud app to manage access control for files. Users with limited access can see ...
CVE-2022-36074HIGH7.5Nextcloud server is an open source personal cloud product. Affected versions of this package are vulnerable to Informati...
CVE-2022-29240HIGH8.1Scylla is a real-time big data database that is API-compatible with Apache Cassandra and Amazon DynamoDB. When decompres...
CVE-2022-27561MEDIUM4.8There is a reflected Cross-Site Scripting vulnerability in the HCL Traveler web admin (LotusTraveler.nsf).
CVE-2022-38334MEDIUM5.5XPDF v4.04 and earlier was discovered to contain a stack overflow via the function Catalog::countPageTree() at Catalog.c...
CVE-2022-38814MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in the auth_settings component of FiberHome AN5506-02-B vRP2521 allows...
CVE-2022-38326CRITICAL9.8Tenda AC15 WiFi Router V15.03.05.19_multi and AC18 WiFi Router V15.03.05.19_multi were discovered to contain a buffer ov...
CVE-2022-38325CRITICAL9.8Tenda AC15 WiFi Router V15.03.05.19_multi and AC18 WiFi Router V15.03.05.19_multi were discovered to contain a buffer ov...
CVE-2022-37260HIGH7.5A Regular Expression Denial of Service (ReDoS) flaw was found in stealjs steal 2.2.4 via the input variable in main.js.
CVE-2022-39209MEDIUM6.5cmark-gfm is GitHub's fork of cmark, a CommonMark parsing and rendering library and program in C. In versions prior to 0...
CVE-2022-38535HIGH7.2TOTOLINK-720R v4.1.5cu.374 was discovered to contain a remote code execution (RCE) vulnerability via the setTracerouteCf...
CVE-2022-38534HIGH7.2TOTOLINK-720R v4.1.5cu.374 was discovered to contain a remote code execution (RCE) vulnerability via the setdiagnosicfg ...
CVE-2022-40663HIGH7.8This vulnerability allows remote attackers to execute arbitrary code on affected installations of NIKON NIS-Elements Vie...
CVE-2022-40662HIGH7.8This vulnerability allows remote attackers to execute arbitrary code on affected installations of NIKON NIS-Elements Vie...
CVE-2022-40661HIGH7.8This vulnerability allows remote attackers to execute arbitrary code on affected installations of NIKON NIS-Elements Vie...
CVE-2022-40660HIGH7.8This vulnerability allows remote attackers to execute arbitrary code on affected installations of NIKON NIS-Elements Vie...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now