2022 CVE Vulnerabilities

27,538 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-34258MEDIUM4.8Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by a stored ...
CVE-2022-34257MEDIUM6.1Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by a stored ...
CVE-2022-34256CRITICAL9.8Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by an Improp...
CVE-2022-34255HIGH8.8Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by an Improp...
CVE-2022-34254HIGH8.8Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by an Improp...
CVE-2022-34253HIGH7.2Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by an XML In...
CVE-2022-2833HIGH7.5Endless Infinite loop in Blender-thumnailing due to logical bugs.
CVE-2022-2832HIGH7.5A flaw was found in Blender 3.3.0. A null pointer dereference exists in source/blender/gpu/opengl/gl_backend.cc that may...
CVE-2022-2831HIGH7.5A flaw was found in Blender 3.3.0. An interger overflow in source/blender/blendthumb/src/blendthumb_extract.cc may lead ...
CVE-2022-2662CRITICAL9.8Sequi PortBloque S has a improper authentication issues which may allow an attacker to bypass the authentication process...
CVE-2022-2661HIGH8.8Sequi PortBloque S has an improper authorization vulnerability, which may allow a low-privileged user to perform adminis...
CVE-2022-37393HIGH7.8Zimbra's sudo configuration permits the zimbra user to execute the zmslapd binary as root with arbitrary parameters. As ...
CVE-2022-2847CRITICAL9.8A vulnerability, which was classified as critical, has been found in SourceCodester Guest Management System. This issue ...
CVE-2022-2846MEDIUM4.3The Calendar Event Multi View WordPress plugin before 1.4.07 does not have any authorisation and CSRF checks in place wh...
CVE-2022-2844MEDIUM6.1A vulnerability classified as problematic has been found in MotoPress Timetable and Event Schedule up to 1.4.06. This af...
CVE-2022-2843MEDIUM6.1A vulnerability was found in MotoPress Timetable and Event Schedule. It has been rated as problematic. Affected by this ...
CVE-2022-38189MEDIUM5.4A stored Cross Site Scripting (XSS) vulnerability in Esri Portal for ArcGIS may allow a remote, authenticated attacker t...
CVE-2022-38184HIGH7.5There is an improper access control vulnerability in Portal for ArcGIS versions 10.8.1 and below which could allow a rem...
CVE-2022-36242CRITICAL9.8Clinic's Patient Management System v1.0 is vulnerable to SQL Injection via /pms/update_medicine.php?id=.
CVE-2022-30576MEDIUM5.4The Web Console component of TIBCO Software Inc.'s TIBCO Data Science - Workbench, TIBCO Statistica, TIBCO Statistica - ...
CVE-2022-30575MEDIUM5.4The Web Console component of TIBCO Software Inc.'s TIBCO Data Science - Workbench, TIBCO Statistica, TIBCO Statistica - ...
CVE-2022-38194MEDIUM5.5In Esri Portal for ArcGIS versions 10.8.1, a system property is not properly encrypted. This may lead to a local user re...
CVE-2022-38193CRITICAL9.6There is a code injection vulnerability in Esri Portal for ArcGIS versions 10.8.1 and below that may allow a remote, una...
CVE-2022-38192MEDIUM5.4A stored Cross Site Scripting (XSS) vulnerability in Esri Portal for ArcGIS may allow a remote, authenticated attacker t...
CVE-2022-38362HIGH8.8Apache Airflow Docker's Provider prior to 3.0.0 shipped with an example DAG that was vulnerable to (authenticated) remot...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now