2022 CVE Vulnerabilities

27,538 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-39809MEDIUM6.1An issue was discovered in WSO2 Enterprise Integrator 6.4.0. A Reflected Cross-Site Scripting (XSS) vulnerability has be...
CVE-2022-38615HIGH8.8SmartVista SVFE2 v2.2.22 was discovered to contain multiple SQL injection vulnerabilities via the UserForm:j_id88, UserF...
CVE-2022-38614HIGH7.5An issue in the IGB Files and OutfileService features of SmartVista Cardgen v3.28.0 allows attackers to list and downloa...
CVE-2022-38613MEDIUM6.5A Path Traversal vulnerability in SmartVista Cardgen v3.28.0 allows authenticated attackers to read arbitrary files in t...
CVE-2022-36617MEDIUM4.9Arq Backup 7.19.5.0 and below stores backup encryption passwords using reversible encryption. This issue allows attacker...
CVE-2022-34165MEDIUM5.4IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 and IBM WebSphere Application Server Liberty 17.0.0.3 through 22...
CVE-2022-28742HIGH7.5aEnrich eHRD Learning Management Key Performance Indicator System 5+ has Improper Access Control. The web application do...
CVE-2022-28741HIGH8.1aEnrich a+HRD 5.x Learning Management Key Performance Indicator System has a local file inclusion (LFI) vulnerability th...
CVE-2022-28740HIGH7.5aEnrich eHRD Learning Management Key Performance Indicator System 5+ exposes Sensitive Information to an Unauthorized Ac...
CVE-2022-40191MEDIUM5.4Authenticated (subscriber+) Stored Cross-Site Scripting (XSS) vulnerability in Ali Khallad's Contact Form By Mega Forms ...
CVE-2022-40133MEDIUM5.5A use-after-free(UAF) vulnerability was found in function 'vmw_execbuf_tie_context' in drivers/gpu/vmxgfx/vmxgfx_execbuf...
CVE-2022-3169MEDIUM5.5A flaw was found in the Linux kernel. A denial of service flaw may occur if there is a consecutive request of the NVME_I...
CVE-2022-3147MEDIUM6.5Mattermost version 7.0.x and earlier fails to sufficiently limit the in-memory sizes of concurrently uploaded JPEG image...
CVE-2022-3077MEDIUM5.5A buffer overflow vulnerability was found in the Linux kernel Intel’s iSMT SMBus host controller driver in the way it ha...
CVE-2022-39846HIGH7.8DLL hijacking vulnerability in Smart Switch PC prior to version 4.3.22083_3 allows attacker to execute arbitrary code.
CVE-2022-39845HIGH7.1Improper validation of integrity check vulnerability in Samsung Kies prior to version 2.6.4.22074 allows local attackers...
CVE-2022-39844HIGH7.1Improper validation of integrity check vulnerability in Smart Switch PC prior to version 4.3.22083 allows local attacker...
CVE-2022-39119HIGH7.8In network service, there is a missing permission check. This could lead to local escalation of privilege with no additi...
CVE-2022-38701LOW3.3OpenHarmony-v3.1.2 and prior versions have a heap overflow vulnerability. Local attackers can trigger a heap overflow an...
CVE-2022-38700HIGH8.8OpenHarmony-v3.1.1 and prior versions have a permission bypass vulnerability. LAN attackers can bypass permission contro...
CVE-2022-38457MEDIUM5.5A use-after-free(UAF) vulnerability was found in function 'vmw_cmd_res_check' in drivers/gpu/vmxgfx/vmxgfx_execbuf.c in ...
CVE-2022-38144HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in gVectors Team wpForo Forum plugin <= 2.0.5 at WordPress.
CVE-2022-38096MEDIUM5.5A NULL pointer dereference vulnerability was found in vmwgfx driver in drivers/gpu/vmxgfx/vmxgfx_execbuf.c in GPU compon...
CVE-2022-38093HIGH8.8Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in All in One SEO plugin <= 4.2.3.1 at WordPress.
CVE-2022-38081MEDIUM5.5OpenHarmony-v3.1.2 and prior versions have a permission bypass vulnerability. LAN attackers can bypass the distributed p...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now