2022 CVE Vulnerabilities

27,525 CVEs published in 2022.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2022-25916HIGH7.8Versions of the package mt7688-wiscan before 0.8.3 are vulnerable to Command Injection due to improper input sanitizatio...
CVE-2022-25906HIGH7.8All versions of the package is-http2 are vulnerable to Command Injection due to missing input sanitization or other chec...
CVE-2022-4062HIGH7.8A CWE-285: Improper Authorization vulnerability exists that could cause unauthorized access to certain software function...
CVE-2022-42973HIGH7.8A CWE-798: Use of Hard-coded Credentials vulnerability exists that could cause local privilege escalation when local att...
CVE-2022-42972HIGH7.8A CWE-732: Incorrect Permission Assignment for Critical Resource vulnerability exists that could cause local privilege e...
CVE-2022-47768HIGH7.5Serenissima Informatica Fast Checkin 1.0 is vulnerable to Directory Traversal.
CVE-2022-48161HIGH7.5Easy Images v2.0 was discovered to contain an arbitrary file download vulnerability via the component /application/down....
CVE-2022-45494HIGH7.8Buffer overflow vulnerability in function json_parse_object in sheredom json.h before commit 0825301a07cbf51653882bf2b15...
CVE-2022-32984HIGH7.5BTCPay Server 1.3.0 through 1.5.3 allows a remote attacker to obtain sensitive information when a public Point of Sale a...
CVE-2022-47700HIGH7.5COMFAST (Shenzhen Sihai Zhonglian Network Technology Co., Ltd) CF-WR623N Router firmware V2.3.0.1 and before is vulnerab...
CVE-2022-46835HIGH7.5IdentityIQ 8.3 and all 8.3 patch levels prior to 8.3p2, IdentityIQ 8.2 and all 8.2 patch levels prior to 8.2p5, Identity...
CVE-2022-44645HIGH8.8In Apache Linkis <=1.3.0 when used with the MySQL Connector/J, a deserialization vulnerability with possible remote code...
CVE-2022-39059HIGH7.5ChangingTech MegaServiSignAdapter component has a path traversal vulnerability within its file reading function. An unau...
CVE-2022-25881HIGH7.5This affects versions of the package http-cache-semantics before 4.1.1. The issue can be exploited via malicious request...
CVE-2022-4441HIGH8.8Incorrect Privilege Assignment vulnerability in Hitachi Storage Plug-in for VMware vCenter allows remote authenticated u...
CVE-2022-4041HIGH8.8Incorrect Privilege Assignment vulnerability in Hitachi Storage Plug-in for VMware vCenter allows remote authenticated u...
CVE-2022-30421HIGH7.8Improper Authentication vulnerability in Toshiba Storage Security Software V1.2.0.7413 is that allows for sensitive info...
CVE-2022-48176HIGH7.8Netgear routers R7000P before v1.3.3.154, R6900P before v1.3.3.154, R7960P before v1.4.4.94, and R8000P before v1.4.4.94...
CVE-2022-32748HIGH8.3A CWE-295: Improper Certificate Validation vulnerability exists that could cause the CAE software to give wrong data to ...
CVE-2022-32747HIGH8.1A CWE-290: Authentication Bypass by Spoofing vulnerability exists that could cause legitimate users to be locked out of ...
CVE-2022-32521HIGH8.8A CWE 502: Deserialization of Untrusted Data vulnerability exists that could allow code to be remotely executed on the s...
CVE-2022-32512HIGH7.8A CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists that could cause...
CVE-2022-22732HIGH7.5A CWE-668: Exposure of Resource to Wrong Sphere vulnerability exists that could cause all remote domains to access the r...
CVE-2022-4794HIGH7.5The AAWP WordPress plugin before 3.12.3 can be used to abuse trusted domains to load malware or other files through it (...
CVE-2022-4680HIGH7.2The Revive Old Posts WordPress plugin before 9.0.11 unserializes user input provided via the settings, which could allow...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now