2022 CVE Vulnerabilities

27,525 CVEs published in 2022.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2022-45786HIGH8.1There are issues with the AGE drivers for Golang and Python that enable SQL injections to occur. This impacts AGE for Po...
CVE-2022-24895HIGH8.8Symfony is a PHP framework for web and console applications and a set of reusable PHP components. When authenticating us...
CVE-2022-24894HIGH8.8Symfony is a PHP framework for web and console applications and a set of reusable PHP components. The Symfony HTTP cache...
CVE-2022-23498HIGH8.8Grafana is an open-source platform for monitoring and observability. When datasource query caching is enabled, Grafana c...
CVE-2022-48165HIGH7.5An access control issue in the component /cgi-bin/ExportLogs.sh of Wavlink WL-WN530H4 M30H4.V5030.210121 allows unauthen...
CVE-2022-47762HIGH7.5In gin-vue-admin < 2.5.5, the download module has a Path Traversal vulnerability.
CVE-2022-47070HIGH7.5NVS365 V01 is vulnerable to Incorrect Access Control. After entering a wrong password, the url will be sent to the serve...
CVE-2022-45588HIGH7.8All versions before R2022-09 of Talend's Remote Engine Gen 2 are potentially vulnerable to XML External Entity (XXE) typ...
CVE-2022-45496HIGH7.8Buffer overflow vulnerability in function json_parse_string in sheredom json.h before commit 0825301a07cbf51653882bf2b15...
CVE-2022-45493HIGH7.8Buffer overflow vulnerability in function json_parse_key in sheredom json.h before commit 0825301a07cbf51653882bf2b153cc...
CVE-2022-45492HIGH7.8Buffer overflow vulnerability in function json_parse_number in sheredom json.h before commit 0825301a07cbf51653882bf2b15...
CVE-2022-45491HIGH7.8Buffer overflow vulnerability in function json_parse_value in sheredom json.h before commit 0825301a07cbf51653882bf2b153...
CVE-2022-34138HIGH7.5Insecure direct object references (IDOR) in the web server of Biltema IP and Baby Camera Software v124 allows attackers ...
CVE-2022-4634HIGH7.8All versions prior to Delta Electronic’s CNCSoft version 1.01.34 (running ScreenEditor versions 1.01.5 and prior) are vu...
CVE-2022-47132HIGH8.8A Cross-Site Request Forgery (CSRF) in Academy LMS before v5.10 allows attackers to arbitrarily add Administrator users.
CVE-2022-46842HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in JS Help Desk plugin <= 2.7.1 versions.
CVE-2022-46815HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Lauri Karisola / WP Trio Conditional Shipping for WooCommerce plugin ...
CVE-2022-45807HIGH8.8Cross-Site Request Forgery (CSRF) in WPVibes WP Mail Log plugin <= 1.0.1 versions.
CVE-2022-45067HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in DevsCred Exclusive Addons Elementor plugin <= 2.6.1 versions.
CVE-2022-44585HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Magneticlab Sàrl Homepage Pop-up plugin <= 1.2.5 versions.
CVE-2022-40692HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in WP Sunshine Sunshine Photo Cart plugin <= 2.9.13 versions.
CVE-2022-36401HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in TeraWallet – For WooCommerce plugin <= 1.3.24 versions.
CVE-2022-46604HIGH8.8An issue in Tecrail Responsive FileManager v9.9.5 and below allows attackers to bypass the file extension check mechanis...
CVE-2022-46552HIGH8.8D-Link DIR-846 Firmware FW100A53DBR was discovered to contain a remote command execution (RCE) vulnerability via the lan...
CVE-2022-46965HIGH8.8PrestaShop module, totadministrativemandate before v1.7.1 was discovered to contain a SQL injection vulnerability.

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now