2022 CVE Vulnerabilities

27,541 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-31197HIGH8PostgreSQL JDBC Driver (PgJDBC for short) allows Java programs to connect to a PostgreSQL database using standard, datab...
CVE-2022-31175MEDIUM4.7CKEditor 5 is a JavaScript rich text editor. A cross-site scripting vulnerability has been discovered affecting three op...
CVE-2022-34992HIGH7.8Luadec v0.9.9 was discovered to contain a heap-buffer overflow via the function UnsetPending.
CVE-2022-37396HIGH7.8In JetBrains Rider before 2022.2 Trust and Open Project dialog could be bypassed, leading to local code execution
CVE-2022-35867MEDIUM6.7This vulnerability allows local attackers to escalate privileges on affected installations of xhyve. An attacker must fi...
CVE-2022-35866CRITICAL9.8This vulnerability allows remote attackers to bypass authentication on affected installations of Vinchin Backup and Reco...
CVE-2022-35865CRITICAL9.8This vulnerability allows remote attackers to execute arbitrary code on affected installations of BMC Track-It! 20.21.2....
CVE-2022-35864MEDIUM6.5This vulnerability allows remote attackers to disclose sensitive information on affected installations of BMC Track-It! ...
CVE-2022-34872MEDIUM6.5This vulnerability allows remote attackers to disclose sensitive information on affected installations of Centreon. Auth...
CVE-2022-34871HIGH7.2This vulnerability allows remote attackers to escalate privileges on affected installations of Centreon. Authentication ...
CVE-2022-2272CRITICAL9.8This vulnerability allows remote attackers to bypass authentication on affected installations of Sante PACS Server 3.0.4...
CVE-2022-28684HIGH8.8This vulnerability allows remote attackers to execute arbitrary code on affected installations of DevExpress. Authentica...
CVE-2022-28668HIGH7.8This vulnerability allows remote attackers to execute arbitrary code on affected installations of Sante DICOM Viewer Pro...
CVE-2022-35620CRITICAL9.8D-LINK DIR-818LW A1:DIR818L_FW105b01 was discovered to contain a remote code execution (RCE) vulnerability via the funct...
CVE-2022-35619CRITICAL9.8D-LINK DIR-818LW A1:DIR818L_FW105b01 was discovered to contain a remote code execution (RCE) vulnerability via the funct...
CVE-2022-34974CRITICAL9.8D-Link DIR810LA1_FW102B22 was discovered to contain a command injection vulnerability via the Ping_addr function.
CVE-2022-34973HIGH7.5D-Link DIR820LA1_FW106B02 was discovered to contain a buffer overflow via the nextPage parameter at ping.ccp.
CVE-2022-36359HIGH8.8An issue was discovered in the HTTP FileResponse class in Django 3.2 before 3.2.15 and 4.0 before 4.0.7. An application ...
CVE-2022-32293HIGH8.1In ConnMan through 1.41, a man-in-the-middle attack against a WISPR HTTP query could be used to trigger a use-after-free...
CVE-2022-32292CRITICAL9.8In ConnMan through 1.41, remote attackers able to send HTTP requests to the gweb component are able to exploit a heap-ba...
CVE-2022-27484MEDIUM4.3A unverified password change in Fortinet FortiADC version 6.2.0 through 6.2.3, 6.1.x, 6.0.x, 5.x.x allows an authenticat...
CVE-2022-23442MEDIUM4.3An improper access control vulnerability [CWE-284] in FortiOS versions 6.2.0 through 6.2.11, 6.4.0 through 6.4.8 and 7.0...
CVE-2022-37394LOW3.3An issue was discovered in OpenStack Nova before 23.2.2, 24.x before 24.1.2, and 25.x before 25.0.2. By creating a neutr...
CVE-2022-35737HIGH7.5SQLite 1.0.12 through 3.39.x before 3.39.2 sometimes allows an array-bounds overflow if billions of bytes are used in a ...
CVE-2022-27621LOW3.8Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in webapi component in Syno...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now