2022 CVE Vulnerabilities

27,525 CVEs published in 2022.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2022-38619CRITICAL9.8SmartVista SVFE2 v2.2.22 was discovered to contain a SQL injection vulnerability via the UserForm:j_id90 parameter at /S...
CVE-2022-40357CRITICAL9.8A security issue was discovered in Z-BlogPHP <= 1.7.2. A Server-Side Request Forgery (SSRF) vulnerability in the zb_user...
CVE-2022-32882CRITICAL9.8This issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.4, macOS Big Sur 11.6.6. An app ...
CVE-2022-32863CRITICAL9.8A memory corruption issue was addressed with improved state management. This issue is fixed in Safari 15.6, macOS Monter...
CVE-2022-32788CRITICAL9.8A buffer overflow was addressed with improved bounds checking. This issue is fixed in watchOS 8.7, tvOS 15.6, iOS 15.6 a...
CVE-2022-40009CRITICAL9.8SWFTools commit 772e55a was discovered to contain a heap-use-after-free via the function grow_unicode at /lib/ttf.c.
CVE-2022-40008CRITICAL9.8SWFTools commit 772e55a was discovered to contain a heap-buffer overflow via the function readU8 at /lib/ttf.c.
CVE-2022-41138CRITICAL9.8In Zutty before 0.13, DECRQSS in text written to the terminal can achieve arbitrary code execution.
CVE-2022-37265CRITICAL9.8Prototype pollution vulnerability in stealjs steal 2.2.4 via the alias variable in babel.js.
CVE-2022-38916CRITICAL9.8A file upload vulnerability exists in the storage feature of pagekit 1.0.18, which allows an attacker to upload maliciou...
CVE-2022-37204CRITICAL9.8Final CMS 5.1.0 is vulnerable to SQL Injection.
CVE-2022-2177CRITICAL9.4Kayrasoft product before version 2 has an unauthenticated SQL Injection vulnerability. This is fixed in version 2.
CVE-2022-39956CRITICAL9.8The OWASP ModSecurity Core Rule Set (CRS) is affected by a partial rule set bypass for HTTP multipart requests by submit...
CVE-2022-39955CRITICAL9.8The OWASP ModSecurity Core Rule Set (CRS) is affected by a partial rule set bypass by submitting a specially crafted HTT...
CVE-2022-38545CRITICAL9.6Valine v1.4.18 was discovered to contain a remote code execution (RCE) vulnerability which allows attackers to execute a...
CVE-2022-38509CRITICAL9.8Wedding Planner v1.0 was discovered to contain a SQL injection vulnerability via the booking_id parameter at /admin/budg...
CVE-2022-37032CRITICAL9.1An out-of-bounds read in the BGP daemon of FRRouting FRR before 8.4 may lead to a segmentation fault and denial of servi...
CVE-2022-28321CRITICAL9.8The Linux-PAM package before 1.5.2-6.1 for openSUSE Tumbleweed allows authentication bypass for SSH logins. The pam_acce...
CVE-2022-0143CRITICAL9.8When the LDAP connector is started with StartTLS configured, unauthenticated access is granted. This issue affects: all ...
CVE-2022-23768CRITICAL9.8This Vulnerability in NIS-HAP11AC is caused by an exposed external port for the telnet service. Remote attackers use thi...
CVE-2022-23767CRITICAL9.8This vulnerability of SecureGate is SQL-Injection using login without password. A path traversal vulnerability is also i...
CVE-2022-40980CRITICAL9.1A potential unathenticated file deletion vulnerabilty on Trend Micro Mobile Security for Enterprise 9.8 SP5 could allow ...
CVE-2022-40144CRITICAL9.8A vulnerability in Trend Micro Apex One and Trend Micro Apex One as a Service could allow an attacker to bypass the prod...
CVE-2022-3218CRITICAL9.8Due to a reliance on client-side authentication, the WiFi Mouse (Mouse Server) from Necta LLC's authentication mechanism...
CVE-2022-40812CRITICAL9.8The d8s-pdfs for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party....

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now