2022 CVE Vulnerabilities

27,543 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-34902HIGH7.8This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Access 6.5.4 (39...
CVE-2022-34901HIGH7.8This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Access 6.5.4 (39...
CVE-2022-34900HIGH7.8This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Access 6.5.3 (39...
CVE-2022-34899HIGH7.8This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Access 6.5.4 (39...
CVE-2022-34892HIGH7.8This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop Parallel...
CVE-2022-34891HIGH7.8This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop Parallel...
CVE-2022-34890HIGH8.8This vulnerability allows local attackers to disclose sensitive information on affected installations of Parallels Deskt...
CVE-2022-34889HIGH8.2This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 17.1.1 (...
CVE-2022-2400MEDIUM5.3External Control of File Name or Path in GitHub repository dompdf/dompdf prior to 2.0.0.
CVE-2022-23142MEDIUM5.3ZXEN CG200 has a DoS vulnerability. An attacker could construct and send a large number of HTTP GET requests in a short ...
CVE-2022-35404HIGH8.2ManageEngine Password Manager Pro 12100 and prior and OPManager 126100 and prior are vulnerable to unauthorized file and...
CVE-2022-32450HIGH7.1AnyDesk 7.0.9 allows a local user to gain SYSTEM privileges via a symbolic link because the user can write to their own ...
CVE-2022-30627HIGH7.5This vulnerability affects all of the company's products that also include the FW versions: update_i90_cv2.021_b20210104...
CVE-2022-30626HIGH7.5Browsing the path: http://ip/wifi_ap_pata_get.cmd, will show in the name of the existing access point on the component, ...
CVE-2022-30625MEDIUM5.3Directory listing is a web server function that displays the directory contents when there is no index file in a specifi...
CVE-2022-30624HIGH7.5Browsing the admin.html page allows the user to reset the admin password. Also appears in the JS code for the password.
CVE-2022-30623CRITICAL9.8The server checks the user's cookie in a non-standard way, and a value is entered in the cookie value name of the status...
CVE-2022-30621MEDIUM6.5Allows a remote user to read files on the camera's OS "GetFileContent.cgi". Reading arbitrary files on the camera's OS a...
CVE-2022-30620HIGH8.8On Cellinx Camera with guest enabled, attacker with web access can elevate privileges to administrative: "1" to "0" priv...
CVE-2022-24692MEDIUM5.4An issue was discovered in DSK DSKNet 2.16.136.0 and 2.17.136.5. The new menu option within the general Parameters page ...
CVE-2022-24691HIGH7.1An issue was discovered in DSK DSKNet 2.16.136.0 and 2.17.136.5. A SQL Injection vulnerability allows authenticated user...
CVE-2022-24690HIGH8.2An issue was discovered in DSK DSKNet 2.16.136.0 and 2.17.136.5. A PresAbs.php SQL Injection vulnerability allows unauth...
CVE-2022-24689MEDIUM5.3An issue was discovered in DSK DSKNet 2.16.136.0 and 2.17.136.5. It mishandles access control. This allows a remote atta...
CVE-2022-24688HIGH8.8An issue was discovered in DSK DSKNet 2.16.136.0 and 2.17.136.5. The Touch settings allow unrestricted file upload (and ...
CVE-2022-36127HIGH7.5A vulnerability in Apache SkyWalking NodeJS Agent prior to 0.5.1. The vulnerability will cause NodeJS services that has ...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now