2022 CVE Vulnerabilities

27,541 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-36800MEDIUM4.3Affected versions of Atlassian Jira Service Management Server and Data Center allow remote attackers without the "Browse...
CVE-2022-27620MEDIUM4.9Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in webapi component in Syno...
CVE-2022-27619MEDIUM5.9Cleartext transmission of sensitive information vulnerability in authentication management in Synology Note Station Clie...
CVE-2022-27618MEDIUM6.5Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in webapi component in Syno...
CVE-2022-27617MEDIUM4.3Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in webapi component in Syno...
CVE-2022-34969HIGH7.5PingCAP TiDB v6.1.0 was discovered to contain a NULL pointer dereference.
CVE-2022-34968HIGH7.5An issue in the fetch_step function in Percona Server for MySQL v8.0.28-19 allows attackers to cause a Denial of Service...
CVE-2022-34967HIGH7.5The assertion `stmt->Dbc->FirstStmt' failed in MonetDB Database Server v11.43.13.
CVE-2022-34943Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2022-27616HIGH7.2Improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in webapi compo...
CVE-2022-36197MEDIUM5.4BigTree CMS 4.4.16 was discovered to contain an arbitrary file upload vulnerability which allows attackers to execute ar...
CVE-2022-34937HIGH8.8Yuba u5cms v8.3.5 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component savepage.php. This vul...
CVE-2022-34928HIGH8.8JFinal CMS v5.1.0 was discovered to contain a SQL injection vulnerability via /system/user.
CVE-2022-34927HIGH7.8MilkyTracker v1.03.00 was discovered to contain a stack overflow via the component LoaderXM::load. This vulnerability is...
CVE-2022-37035HIGH8.1An issue was discovered in bgpd in FRRouting (FRR) 8.3. In bgp_notify_send_with_data() and bgp_process_packet() in bgp_p...
CVE-2022-33917MEDIUM5.5An issue was discovered in the Arm Mali GPU Kernel Driver (Valhall r29p0 through r38p0). A non-privileged user can make ...
CVE-2022-36968MEDIUM4.3In Progress WS_FTP Server prior to version 8.7.3, forms within the administrative interface did not include a nonce to m...
CVE-2022-36967MEDIUM6.1In Progress WS_FTP Server prior to version 8.7.3, multiple reflected cross-site scripting (XSS) vulnerabilities exist in...
CVE-2022-34619MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in Mealie v0.5.5 allows attackers to execute arbitrary web scripts or ...
CVE-2022-30285CRITICAL9.8In Quest KACE Systems Management Appliance (SMA) through 12.0, a hash collision is possible during authentication. This ...
CVE-2022-29808HIGH7.5In Quest KACE Systems Management Appliance (SMA) through 12.0, predictable token generation occurs when appliance linkin...
CVE-2022-29807CRITICAL9.8A SQL injection vulnerability exists within Quest KACE Systems Management Appliance (SMA) through 12.0 that can allow fo...
CVE-2022-35925CRITICAL9.8BookWyrm is a social network for tracking reading. Versions prior to 0.4.5 were found to lack rate limiting on authentic...
CVE-2022-35923HIGH7.5v8n is a javascript validation library. Versions of v8n prior to 1.5.1 were found to have an inefficient regular express...
CVE-2022-34924HIGH7.5Lanling OA Landray Office Automation (OA) internal patch number #133383/#137780 contains an arbitrary file read vulnerab...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now