2022 CVE Vulnerabilities

27,538 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-28883HIGH7.5A Denial-of-Service (DoS) vulnerability was discovered in F-Secure & WithSecure products whereby the aerdl unpack functi...
CVE-2022-28882HIGH7.5A Denial-of-Service (DoS) vulnerability was discovered in F-Secure & WithSecure products whereby the aegen.dll will go i...
CVE-2022-35278MEDIUM6.1In Apache ActiveMQ Artemis prior to 2.24.0, an attacker could show malicious content and/or redirect users to a maliciou...
CVE-2022-37223CRITICAL9.8JFinal CMS 5.1.0 is vulnerable to SQL Injection via /jfinal_cms/system/role/list.
CVE-2022-37199CRITICAL9.8JFinal CMS 5.1.0 is vulnerable to SQL Injection via /jfinal_cms/system/user/list.
CVE-2022-36261CRITICAL9.1An arbitrary file deletion vulnerability was discovered in taocms 3.0.2, that allows attacker to delete file in server w...
CVE-2022-35203HIGH7.2An access control issue in TrendNet TV-IP572PI v1.0 allows unauthenticated attackers to access sensitive system informat...
CVE-2022-2956MEDIUM6.1A vulnerability classified as problematic has been found in ConsoleTVs Noxen. Affected is an unknown function of the fil...
CVE-2022-28817Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: No impact could be verified. Notes: none
CVE-2022-1989MEDIUM5.3All CODESYS Visualization versions before V4.2.0.0 generate a login dialog vulnerable to information exposure allowing a...
CVE-2022-2796MEDIUM4.8Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.5.4.
CVE-2022-36350MEDIUM5.4Stored cross-site scripting vulnerability in PukiWiki versions 1.3.1 to 1.5.3 allows a remote attacker to inject an arbi...
CVE-2022-34486HIGH7.2Path traversal vulnerability in PukiWiki versions 1.4.5 to 1.5.3 allows a remote authenticated attacker with an administ...
CVE-2022-27637MEDIUM6.1Reflected cross-site scripting vulnerability in PukiWiki versions 1.5.1 to 1.5.3 allows a remote attacker to inject an a...
CVE-2022-25888HIGH7.5The package opcua from 0.0.0 are vulnerable to Denial of Service (DoS) due to a missing limitation on the number of rece...
CVE-2022-25761HIGH7.5The package open62541/open62541 before 1.2.5, from 1.3-rc1 and before 1.3.1 are vulnerable to Denial of Service (DoS) du...
CVE-2022-25304HIGH7.5All versions of package opcua; all versions of package asyncua are vulnerable to Denial of Service (DoS) due to a missin...
CVE-2022-25302HIGH7.5All versions of package asneg/opcuastack are vulnerable to Denial of Service (DoS) due to a missing handler for failed c...
CVE-2022-25231HIGH7.5The package node-opcua before 2.74.0 are vulnerable to Denial of Service (DoS) by sending a specifically crafted OPC UA ...
CVE-2022-24381HIGH7.5All versions of package asneg/opcuastack are vulnerable to Denial of Service (DoS) due to a missing limitation on the nu...
CVE-2022-24298HIGH7.5All versions of package freeopcua/freeopcua are vulnerable to Denial of Service (DoS) when bypassing the limitations for...
CVE-2022-21208HIGH7.5The package node-opcua before 2.74.0 are vulnerable to Denial of Service (DoS) due to a missing limitation on the number...
CVE-2022-2829MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0.
CVE-2022-35733CRITICAL9.8Missing authentication for critical function vulnerability in UNIMO Technology digital video recorders (UDR-JA1004/JA100...
CVE-2022-34919CRITICAL9.8The file upload wizard in Zengenti Contensis Classic before 15.2.1.79 does not correctly check that a user has authentic...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now