2022 CVE Vulnerabilities

27,525 CVEs published in 2022.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2022-24990HIGH7.5TerraMaster NAS 4.2.29 and earlier allows remote attackers to discover the administrative password by sending "User-Agen...
CVE-2022-40693HIGH7.5A cleartext transmission vulnerability exists in the web application functionality of Moxa SDS-3008 Series Industrial Et...
CVE-2022-40224HIGH7.5A denial of service vulnerability exists in the web server functionality of Moxa SDS-3008 Series Industrial Ethernet Swi...
CVE-2022-45544HIGH8.8Insecure Permission vulnerability in Schlix Web Inc SCHLIX CMS 2.2.7-2 allows attacker to upload arbitrary files and exe...
CVE-2022-43759HIGH8.8A Improper Privilege Management vulnerability in SUSE Rancher, allows users with access to the escalate verb on PRTBs to...
CVE-2022-43757HIGH8.8A Cleartext Storage of Sensitive Information vulnerability in SUSE Rancher allows users on managed clusters to gain acce...
CVE-2022-43756HIGH7.5A Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in SU...
CVE-2022-21953HIGH8.8A Missing Authorization vulnerability in of SUSE Rancher allows authenticated user to create an unauthorized shell pod a...
CVE-2022-31254HIGH7.8A Incorrect Default Permissions vulnerability in rmt-server-regsharing service of SUSE Linux Enterprise Server for SAP 1...
CVE-2022-31611HIGH7.3 NVIDIA GeForce Experience contains an uncontrolled search path vulnerability in all its client installers, where an att...
CVE-2022-38547HIGH7.2A post-authentication command injection vulnerability in the CLI command of Zyxel ZyWALL/USG series firmware versions 4....
CVE-2022-44617HIGH7.5A flaw was found in libXpm. When processing a file with width of 0 and a very large height, some parser functions will b...
CVE-2022-48166HIGH7.5An access control issue in Wavlink WL-WN530HG4 M30HG4.V5030.201217 allows unauthenticated attackers to download configur...
CVE-2022-45589HIGH7.2All versions before 8.0.1-R2022-10-RT and 7.3.1-R2022-09-RT of the Talend ESB Runtime are potentially vulnerable to SQL ...
CVE-2022-42951HIGH8.1An issue was discovered in Couchbase Server 6.5.x and 6.6.x before 6.6.6, 7.x before 7.0.5, and 7.1.x before 7.1.2. Duri...
CVE-2022-4489HIGH7.2The HUSKY WordPress plugin before 1.3.2 unserializes user input provided via the settings, which could allow high privil...
CVE-2022-32663HIGH7.5In Wi-Fi driver, there is a possible system crash due to null pointer dereference. This could lead to remote denial of s...
CVE-2022-41342HIGH7.8Improper buffer restrictions in the Intel(R) C++ Compiler Classic before version 2021.7.1 for some Intel(R) oneAPI Toolk...
CVE-2022-40196HIGH7.8Improper access control in the Intel(R) oneAPI DPC++/C++ Compiler before version 2022.2.1 and Intel C++ Compiler Classic...
CVE-2022-38136HIGH7.3Uncontrolled search path in the Intel(R) oneAPI DPC++/C++ Compiler for Windows and Intel Fortran Compiler for Windows be...
CVE-2022-48019HIGH7.8The components wfshbr64.sys and wfshbr32.sys in Another Eden before v3.0.20 and before v2.14.200 allows attackers to per...
CVE-2022-48164HIGH7.5An access control issue in the component /cgi-bin/ExportLogs.sh of Wavlink WL-WN533A8 M33A8.V5030.190716 allows unauthen...
CVE-2022-44343HIGH7.5CRMEB 4.4.4 is vulnerable to Any File download.
CVE-2022-25855HIGH7.8All versions of the package create-choo-app3 are vulnerable to Command Injection via the devInstall function due to impr...
CVE-2022-25853HIGH7.8All versions of the package semver-tags are vulnerable to Command Injection via the getGitTagsRemote function due to imp...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now