2022 CVE Vulnerabilities

27,552 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-32311CRITICAL9.8Ingredient Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at ...
CVE-2022-32310CRITICAL9.8An access control issue in Ingredient Stock Management System v1.0 allows attackers to take over user accounts via a cra...
CVE-2022-31856CRITICAL9.8Newsletter Module v3.x was discovered to contain a SQL injection vulnerability via the zemez_newsletter_email parameter ...
CVE-2022-2321CRITICAL9.8Improper Restriction of Excessive Authentication Attempts in GitHub repository heroiclabs/nakama prior to 3.13.0. This r...
CVE-2022-33075MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in the Add Classification function of Zoo Management System v1.0 allow...
CVE-2022-31117MEDIUM5.9UltraJSON is a fast JSON encoder and decoder written in pure C with bindings for Python 3.7+. In versions prior to 5.4.0...
CVE-2022-31116HIGH7.5UltraJSON is a fast JSON encoder and decoder written in pure C with bindings for Python 3.7+. Affected versions were fou...
CVE-2022-31014LOW3.5Nextcloud server is an open source personal cloud server. Affected versions were found to be vulnerable to SMTP command ...
CVE-2022-34879MEDIUM6.1Reflected Cross Site Scripting (XSS) vulnerabilities in AST Agent Time Sheet interface (/vicidial/AST_agent_time_sheet.p...
CVE-2022-34878HIGH8.8SQL Injection vulnerability in User Stats interface (/vicidial/user_stats.php) of VICIdial via the file_download paramet...
CVE-2022-34877HIGH8.8SQL Injection vulnerability in AST Agent Time Sheet interface ((/vicidial/AST_agent_time_sheet.php) of VICIdial via the ...
CVE-2022-34876HIGH8.8SQL Injection vulnerability in admin interface (/vicidial/admin.php) of VICIdial via modify_email_accounts, access_recor...
CVE-2022-31770MEDIUM4.9IBM App Connect Enterprise Certified Container 4.2 could allow a user from the administration console to cause a denial ...
CVE-2022-31836CRITICAL9.8The leafInfo.match() function in Beego v2.0.3 and below uses path.join() to deal with wildcardvalues which can lead to c...
CVE-2022-33744MEDIUM4.7Arm guests can cause Dom0 DoS via PV devices When mapping pages of guests on Arm, dom0 is using an rbtree to keep track ...
CVE-2022-33743HIGH7.8network backend may cause Linux netfront to use freed SKBs While adding logic to support XDP (eXpress Data Path), a code...
CVE-2022-33742HIGH7.1Linux disk/nic frontends data leaks T[his CNA information record relates to multiple CVEs; the text explains which aspec...
CVE-2022-33741HIGH7.1Linux disk/nic frontends data leaks T[his CNA information record relates to multiple CVEs; the text explains which aspec...
CVE-2022-33740HIGH7.1Linux disk/nic frontends data leaks T[his CNA information record relates to multiple CVEs; the text explains which aspec...
CVE-2022-30290HIGH7.5In OpenCTI through 5.2.4, a broken access control vulnerability has been identified in the profile endpoint. An attacker...
CVE-2022-2304HIGH7.8Stack-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.
CVE-2022-26365HIGH7.1Linux disk/nic frontends data leaks T[his CNA information record relates to multiple CVEs; the text explains which aspec...
CVE-2022-30289MEDIUM5.4A stored Cross-site Scripting (XSS) vulnerability was identified in the Data Import functionality of OpenCTI through 5.2...
CVE-2022-2097MEDIUM5.3AES OCB mode for 32-bit x86 platforms using the AES-NI assembly optimised implementation will not encrypt the entirety o...
CVE-2022-2309HIGH7.5NULL Pointer Dereference allows attackers to cause a denial of service (or application crash). This only applies when lx...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now