2022 CVE Vulnerabilities

27,525 CVEs published in 2022.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2022-25657CRITICAL9.8Memory corruption due to buffer overflow occurs while processing invalid MKV clip which has invalid seek header in Snapd...
CVE-2022-22096CRITICAL9.8Memory corruption in Bluetooth HOST due to stack-based buffer overflow when when extracting data using command length pa...
CVE-2022-22062CRITICAL9.1An out-of-bounds read can occur while parsing a server certificate due to improper length check in Snapdragon Auto, Snap...
CVE-2022-38054CRITICAL9.8In Apache Airflow versions 2.2.4 through 2.3.3, the `database` webserver session backend was susceptible to session fixa...
CVE-2022-29063CRITICAL9.8The Solr plugin of Apache OFBiz is configured by default to automatically make a RMI request on localhost, port 1099. In...
CVE-2022-25371CRITICAL9.8Apache OFBiz uses the Birt project plugin (https://eclipse.github.io/birt-website/) to create data visualizations and re...
CVE-2022-36609CRITICAL9.8Clinic's Patient Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at ...
CVE-2022-36594CRITICAL9.8Mapper v4.0.0 to v4.2.0 was discovered to contain a SQL injection vulnerability via the ids parameter at the selectByIds...
CVE-2022-36759CRITICAL9.8Online Food Ordering System v1.0 was discovered to contain a SQL injection vulnerability via the component /dishes.php?r...
CVE-2022-36601CRITICAL9.8The Eclipse TCF debug interface in JasMiner-X4-Server-20220621-090907 and below is open on port 1534. This issue allows ...
CVE-2022-34379CRITICAL9.8Dell EMC CloudLink 7.1.2 and all prior versions contain an Authentication Bypass Vulnerability. A remote attacker, with ...
CVE-2022-34372CRITICAL9.1Dell PowerProtect Cyber Recovery versions before 19.11.0.2 contain an authentication bypass vulnerability. A remote unau...
CVE-2022-36672CRITICAL9.8Novel-Plus v3.6.2 was discovered to contain a hard-coded JWT key located in the project config file. This vulnerability ...
CVE-2022-36130CRITICAL9.9HashiCorp Boundary up to 0.10.1 did not properly perform data integrity checks to ensure the resources were associated w...
CVE-2022-37130CRITICAL9.8In D-Link DIR-816 A2_v1.10CNB04, DIR-878 DIR_878_FW1.30B08.img a command injection vulnerability occurs in /goform/Diagn...
CVE-2022-37125CRITICAL9.8D-link DIR-816 A2_v1.10CNB04.img is vulnerable to Command injection via /goform/NTPSyncWithHost.
CVE-2022-36202CRITICAL9.8Doctor's Appointment System1.0 is vulnerable to Incorrect Access Control via edoc/patient/settings.php. The settings.php...
CVE-2022-36201CRITICAL9.8Doctor’s Appointment System v1.0 is vulnerable to Blind SQLi via settings.php.
CVE-2022-37128CRITICAL9.8In D-Link DIR-816 A2_v1.10CNB04.img the network can be initialized without authentication via /goform/wizard_end.
CVE-2022-36566CRITICAL9.8Rengine v1.3.0 was discovered to contain a command injection vulnerability via the scan engine function.
CVE-2022-30318CRITICAL9.8Honeywell ControlEdge through R151.1 uses Hard-coded Credentials. According to FSCT-2022-0056, there is a Honeywell Cont...
CVE-2022-30317CRITICAL9.1Honeywell Experion LX through 2022-05-06 has Missing Authentication for a Critical Function. According to FSCT-2022-0055...
CVE-2022-2466CRITICAL9.8It was found that Quarkus 2.10.x does not terminate HTTP requests header context which may lead to unpredictable behavio...
CVE-2022-2003CRITICAL9.1AutomationDirect DirectLOGIC is vulnerable to a specifically crafted serial message to the CPU serial port that will cau...
CVE-2022-21941CRITICAL9.8All versions of iSTAR Ultra prior to version 6.8.9.CU01 are vulnerable to a command injection that could allow an unauth...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now