2022 CVE Vulnerabilities

27,541 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-30616HIGH7.2IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 could allow a privileged user to elevate their privilege to pl...
CVE-2022-2591HIGH7.5A vulnerability classified as critical has been found in TEM FLEX-1085 1.6.0. Affected is an unknown function of the fil...
CVE-2022-22505HIGH7.5IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 contains a vulnerability that could allow IBM tenant credentia...
CVE-2022-22334MEDIUM4.3IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 could allow a user to access information from a tenant of whic...
CVE-2022-22326LOW3.3IBM Datapower Gateway 10.0.2.0 through 10.0.4.0, 10.0.1.0 through 10.0.1.5, and 2018.4.1.0 through 2018.4.1.18 could all...
CVE-2022-33994LOW3The Gutenberg plugin through 13.7.3 for WordPress allows stored XSS by the Contributor role via an SVG document to the "...
CVE-2022-36336HIGH7.8A link following vulnerability in the scanning function of Trend Micro Apex One and Worry-Free Business Security agents ...
CVE-2022-35234HIGH7.1Trend Micro Security 2021 and 2022 (Consumer) is vulnerable to an Out-Of-Bounds Read Information Disclosure Vulnerabilit...
CVE-2022-33158HIGH7.8Trend Micro VPN Proxy Pro version 5.2.1026 and below contains a vulnerability involving some overly permissive folders i...
CVE-2022-30083CRITICAL9.8EllieGrid Android Application version 3.4.1 is vulnerable to Code Injection. The application appears to evaluate user in...
CVE-2022-34531CRITICAL9.8DedeCMS v5.7.95 was discovered to contain a remote code execution (RCE) vulnerability via the component mytag_ main.php.
CVE-2022-34528HIGH8.8D-Link DSL-3782 v1.03 and below was discovered to contain a stack overflow via the function getAttrValue.
CVE-2022-34527HIGH8.8D-Link DSL-3782 v1.03 and below was discovered to contain a command injection vulnerability via the function byte_4C0160...
CVE-2022-34526MEDIUM6.5A stack overflow was discovered in the _TIFFVGetField function of Tiffsplit v4.4.0. This vulnerability allows attackers ...
CVE-2022-34496CRITICAL9.8Hiby R3 PRO firmware v1.5 to v1.7 was discovered to contain a file upload vulnerability via the file upload feature.
CVE-2022-36447HIGH7.5An inflation issue was discovered in Chia Network CAT1 Standard 1.0.0. Previously minted tokens minted on the Chia block...
CVE-2022-2324HIGH7.5Improperly Implemented Security Check vulnerability in the SonicWall Hosted Email Security leads to bypass of Capture AT...
CVE-2022-22280CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command leading to Unauthenticated SQL Injection vulnerabilit...
CVE-2022-2323HIGH8.8Improper neutralization of special elements used in a user input allows an authenticated malicious user to perform remot...
CVE-2022-27866HIGH7.8A maliciously crafted TIFF file when consumed through DesignReview.exe application can be forced to read beyond allocate...
CVE-2022-27865HIGH7.8A maliciously crafted TGA or PCX file may be used to write beyond the allocated buffer through DesignReview.exe applicat...
CVE-2022-27864HIGH8.8A Double Free vulnerability allows remote attackers to execute arbitrary code through DesignReview.exe application on PD...
CVE-2022-36378MEDIUM4.8Authenticated (author or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in PluginlySpeaking Floating ...
CVE-2022-2414HIGH7.5Access to external entities when parsing XML documents can lead to XML external entity (XXE) attacks. This flaw allows a...
CVE-2022-23004MEDIUM5.3When computing a shared secret or point multiplication on the NIST P-256 curve using a public key with an X coordinate o...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now