2022 CVE Vulnerabilities

27,525 CVEs published in 2022.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2022-3269CRITICAL9.8Session Fixation in GitHub repository ikus060/rdiffweb prior to 2.4.7.
CVE-2022-26112CRITICAL9.8In 0.10.0 or older versions of Apache Pinot, Pinot query endpoint and realtime ingestion layer has a vulnerability in un...
CVE-2022-39227CRITICAL9.1python-jwt is a module for generating and verifying JSON Web Tokens. Versions prior to 3.3.4 are subject to Authenticati...
CVE-2022-35951CRITICAL9.8Redis is an in-memory database that persists on disk. Versions 7.0.0 and above, prior to 7.0.5 are vulnerable to an Inte...
CVE-2022-37235CRITICAL9.8Netgear Nighthawk AC1900 Smart WiFi Dual Band Gigabit Router R7000-V1.0.11.134_10.2.119 is vulnerable to Buffer Overflow...
CVE-2022-37232CRITICAL9.8Netgear N300 wireless router wnr2000v4-V1.0.0.70 is vulnerable to Buffer Overflow via uhttpd. There is a stack overflow ...
CVE-2022-38573CRITICAL9.810-Strike Network Inventory Explorer v9.3 was discovered to contain a buffer overflow via the Add Computers function.
CVE-2022-40089CRITICAL9.8A remote file inclusion (RFI) vulnerability in Simple College Website v1.0 allows attackers to execute arbitrary code vi...
CVE-2022-40087CRITICAL9.8Simple College Website v1.0 was discovered to contain an arbitrary file write vulnerability via the function file_put_co...
CVE-2022-36934CRITICAL9.8An integer overflow in WhatsApp could result in remote code execution in an established video call.
CVE-2022-31937CRITICAL9.8Netgear N300 wireless router wnr2000v4-V1.0.0.70 was discovered to contain a stack overflow via strcpy in uhttpd.
CVE-2022-3268CRITICAL9.8Weak Password Requirements in GitHub repository ikus060/minarca prior to 4.2.2.
CVE-2022-40186CRITICAL9.1An issue was discovered in HashiCorp Vault and Vault Enterprise before 1.11.3. A vulnerability in the Identity Engine wa...
CVE-2022-28802CRITICAL9.9Code by Zapier before 2022-08-17 allowed intra-account privilege escalation that included execution of Python or JavaScr...
CVE-2022-40030CRITICAL9.8SourceCodester Simple Task Managing System v1.0 was discovered to contain a SQL injection vulnerability via the bookId p...
CVE-2022-30578CRITICAL9The Web Server component of TIBCO Software Inc.'s TIBCO EBX Add-ons contains an easily exploitable vulnerability that al...
CVE-2022-30577CRITICAL9The Web Server component of TIBCO Software Inc.'s TIBCO EBX contains an easily exploitable vulnerability that allows a l...
CVE-2022-41241CRITICAL9.1Jenkins RQM Plugin 2.8 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
CVE-2022-41238CRITICAL9.8A missing permission check in Jenkins DotCi Plugin 2.40.00 and earlier allows unauthenticated attackers to trigger build...
CVE-2022-41237CRITICAL9.8Jenkins DotCi Plugin 2.40.00 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary ty...
CVE-2022-41226CRITICAL9.8Jenkins Compuware Common Configuration Plugin 1.0.14 and earlier does not configure its XML parser to prevent XML extern...
CVE-2022-37026CRITICAL9.8In Erlang/OTP before 23.3.4.15, 24.x before 24.3.4.2, and 25.x before 25.0.2, there is a Client Authentication Bypass in...
CVE-2022-0495CRITICAL9.4The library automation system product KOHA developed by Parantez Teknoloji before version 19.05.03 has an unauthenticate...
CVE-2022-2315CRITICAL9.4Database Software Accreditation Tracking/Presentation Module product before version 2 has an unauthenticated SQL Injecti...
CVE-2022-41220CRITICAL9.8md2roff 1.9 has a stack-based buffer overflow via a Markdown file, a different vulnerability than CVE-2022-34913. NOTE: ...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now