2022 CVE Vulnerabilities

27,541 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-34568HIGH7.5SDL v1.2 was discovered to contain a use-after-free via the XFree function at /src/video/x11/SDL_x11yuv.c.
CVE-2022-30287HIGH8Horde Groupware Webmail Edition through 5.2.22 allows a reflection injection attack through which an attacker can instan...
CVE-2022-2399HIGH8.8Use after free in WebGPU in Google Chrome prior to 100.0.4896.88 allowed a remote attacker to potentially exploit heap c...
CVE-2022-29558HIGH8.8Realtek rtl819x-SDK before v3.6.1 allows command injection over the web interface.
CVE-2022-29360MEDIUM5.4The Email Viewer in RainLoop through 1.6.0 allows XSS via a crafted email message.
CVE-2022-34593HIGH7.5DPTech VPN v8.1.28.0 was discovered to contain an arbitrary file read vulnerability.
CVE-2022-34578HIGH7.2Open Source Point of Sale v3.3.7 was discovered to contain an arbitrary file upload vulnerability via the Update Brandin...
CVE-2022-2564CRITICAL9.8Prototype Pollution in GitHub repository automattic/mongoose prior to 6.4.6.
CVE-2022-30320MEDIUM4.3Saia Burgess Controls (SBC) PCD through 2022-05-06 uses a Broken or Risky Cryptographic Algorithm. According to FSCT-202...
CVE-2022-30319HIGH8.1Saia Burgess Controls (SBC) PCD through 2022-05-06 allows Authentication bypass. According to FSCT-2022-0062, there is a...
CVE-2022-30316MEDIUM6.8Honeywell Experion PKS Safety Manager 5.02 has Insufficient Verification of Data Authenticity. According to FSCT-2022-00...
CVE-2022-30315CRITICAL9.8Honeywell Experion PKS Safety Manager (SM and FSC) through 2022-05-06 has Insufficient Verification of Data Authenticity...
CVE-2022-30314MEDIUM4.6Honeywell Experion PKS Safety Manager 5.02 uses Hard-coded Credentials. According to FSCT-2022-0052, there is a Honeywel...
CVE-2022-30313HIGH7.5Honeywell Experion PKS Safety Manager through 2022-05-06 has Missing Authentication for a Critical Function. According t...
CVE-2022-35882MEDIUM4.8Authenticated (author or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in GS Plugins GS Testimonial ...
CVE-2022-2553MEDIUM6.5The authfile directive in the booth config file is ignored, preventing use of authentication in communications from node...
CVE-2022-1948MEDIUM5.4An issue has been discovered in GitLab affecting all versions starting from 15.0 before 15.0.1. Missing validation of in...
CVE-2022-1805HIGH8.1When connecting to Amazon Workspaces, the SHA256 presented by AWS connection provisioner is not fully verified by Zero C...
CVE-2022-27509MEDIUM6.1Unauthenticated redirection to a malicious website
CVE-2022-37010LOW3.3In JetBrains IntelliJ IDEA before 2022.2 email address validation in the "Git User Name Is Not Defined" dialog was misse...
CVE-2022-37009HIGH7.8In JetBrains IntelliJ IDEA before 2022.2 local code execution via a Vagrant executable was possible
CVE-2022-36364HIGH8.8Apache Calcite Avatica JDBC driver creates HTTP client instances based on class names provided via `httpclient_impl` con...
CVE-2022-27611HIGH8.1Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in webapi component in Syno...
CVE-2022-27614HIGH7.5Exposure of sensitive information to an unauthorized actor vulnerability in web server in Synology Media Server before 1...
CVE-2022-27613HIGH8.8Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in webapi component i...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now