2022 CVE Vulnerabilities

27,538 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-37021CRITICAL9.8Apache Geode versions up to 1.12.5, 1.13.4 and 1.14.0 are vulnerable to a deserialization of untrusted data flaw when us...
CVE-2022-39047HIGH8.8Freeciv before 2.6.7 and before 3.0.3 is prone to a buffer overflow vulnerability in the Modpack Installer utility's han...
CVE-2022-39046MEDIUM5.3An issue was discovered in the GNU C Library (glibc) 2.36. When the syslog function is passed a crafted input string lar...
CVE-2022-36749CRITICAL9.8RPi-Jukebox-RFID v2.3.0 was discovered to contain a command injection vulnerability via the component /htdocs/utils/File...
CVE-2022-36748MEDIUM6.1PicUploader v2.6.3 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /master/index....
CVE-2022-36747MEDIUM6.1Razor v0.8.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the function uploadchannel().
CVE-2022-36746MEDIUM6.1LibreNMS v22.6.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component oxidized-cfg-che...
CVE-2022-36745MEDIUM6.1LibreNMS v22.6.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component print-customoid....
CVE-2022-27563HIGH7.5An unauthenticated user can overload a part of HCL VersionVault Express and cause a denial of service.
CVE-2022-27560MEDIUM6.5HCL VersionVault Express exposes administrator credentials.
CVE-2022-3037HIGH7.8Use After Free in GitHub repository vim/vim prior to 9.0.0322.
CVE-2022-37173HIGH7.8An issue in the installer of gvim 9.0.0000 allows authenticated attackers to execute arbitrary code via a binary hijacki...
CVE-2022-37172HIGH7.8Incorrect access control in the install directory (C:\msys64) of Msys2 v20220603 and below allows authenticated attacker...
CVE-2022-36735CRITICAL9.8Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the bookId parameter at /admi...
CVE-2022-36734CRITICAL9.8Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the RollNo parameter at /admi...
CVE-2022-36733CRITICAL9.8Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the M_Id parameter at /admin/...
CVE-2022-36732CRITICAL9.8Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /libraria...
CVE-2022-36731CRITICAL9.8Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the RollNo parameter at /libr...
CVE-2022-36730CRITICAL9.8Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the bookId parameter at /libr...
CVE-2022-36657MEDIUM4.8Library Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /l...
CVE-2022-36565HIGH8.8Incorrect access control in the install directory (C:\Wamp64) of Wamp v3.2.6 and below allows authenticated attackers to...
CVE-2022-36564HIGH8.8Incorrect access control in the install directory (C:\Strawberry) of StrawberryPerl v5.32.1.1 and below allows authentic...
CVE-2022-36563HIGH8.8Incorrect access control in the install directory (C:\RailsInstaller) of Rubyinstaller2 v3.1.2 and below allows authenti...
CVE-2022-36562HIGH8.8Incorrect access control in the install directory (C:\Ruby31-x64) of Rubyinstaller2 v3.1.2 and below allows authenticate...
CVE-2022-36561MEDIUM5.5XPDF v4.0.4 was discovered to contain a segmentation violation via the component /xpdf/AcroForm.cc:538.

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now