2022 CVE Vulnerabilities

27,538 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-2979HIGH7.8Opening a specially crafted file could cause the affected product to fail to release its memory reference potentially re...
CVE-2022-29490HIGH8.8Improper Authorization vulnerability exists in the Workplace X WebUI of the Hitachi Energy MicroSCADA X SYS600 allows an...
CVE-2022-39200MEDIUM5.3Dendrite is a Matrix homeserver written in Go. In affected versions events retrieved from a remote homeserver using the ...
CVE-2022-36102HIGH7.2Shopware is an open source e-commerce software. In affected versions if backend admin controllers are called with a cert...
CVE-2022-36101MEDIUM5.3Shopware is an open source e-commerce software. In affected versions the request for the customer detail view in the bac...
CVE-2022-31226HIGH7.8Dell BIOS versions contain a Stack-based Buffer Overflow vulnerability. A local authenticated malicious user could poten...
CVE-2022-31225MEDIUM5.1Dell BIOS versions contain an Unchecked Return Value vulnerability. A local authenticated administrator user could poten...
CVE-2022-31224LOW2.4Dell BIOS versions contain an Improper Protection Against Voltage and Clock Glitches vulnerability. An attacker with phy...
CVE-2022-31223LOW2.3Dell BIOS versions contain an Improper Neutralization of Null Byte vulnerability. A local authenticated administrator us...
CVE-2022-31222MEDIUM4.4Dell BIOS versions contain a Missing Release of Resource after Effective Lifetime vulnerability. A local authenticated a...
CVE-2022-31221LOW2.3Dell BIOS versions contain an Information Exposure vulnerability. A local authenticated administrator user could potenti...
CVE-2022-31220MEDIUM5.1Dell BIOS versions contain an Unchecked Return Value vulnerability. A local authenticated administrator user could poten...
CVE-2022-1700CRITICAL9.8Improper Restriction of XML External Entity Reference ('XXE') vulnerability in the Policy Engine of Forcepoint Data Loss...
CVE-2022-37860CRITICAL9.8The web configuration interface of the TP-Link M7350 V3 with firmware version 190531 is affected by a pre-authentication...
CVE-2022-37300CRITICAL9.8A CWE-640: Weak Password Recovery Mechanism for Forgotten Password vulnerability exists that could cause unauthorized ac...
CVE-2022-3178HIGH7.8Buffer Over-read in GitHub repository gpac/gpac prior to 2.1.0-DEV.
CVE-2022-37797HIGH7.5In lighttpd 1.4.65, mod_wstunnel does not initialize a handler function pointer if an invalid HTTP request (websocket ha...
CVE-2022-37767CRITICAL9.8Pebble Templates 3.1.5 allows attackers to bypass a protection mechanism and implement arbitrary code execution with spr...
CVE-2022-37734HIGH7.5graphql-java before19.0 is vulnerable to Denial of Service. An attacker can send a malicious GraphQL query that consumes...
CVE-2022-37835HIGH7.5Torguard VPN 4.8, has a vulnerability that allows an attacker to dump sensitive information, such as credentials and inf...
CVE-2022-36259HIGH7.5A SQL injection vulnerability in ConnectionFactory.java in sazanrjb InventoryManagementSystem 1.0 allows attackers to ex...
CVE-2022-36258HIGH7.5A SQL injection vulnerability in CustomerDAO.java in sazanrjb InventoryManagementSystem 1.0 allows attackers to execute ...
CVE-2022-36257HIGH7.5A SQL injection vulnerability in UserDAO.java in sazanrjb InventoryManagementSystem 1.0 allows attackers to execute arbi...
CVE-2022-36256HIGH7.5A SQL injection vulnerability in Stocks.java in sazanrjb InventoryManagementSystem 1.0 allows attackers to execute arbit...
CVE-2022-36255HIGH7.5A SQL injection vulnerability in SupplierDAO.java in sazanrjb InventoryManagementSystem 1.0 allows attackers to execute ...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now