2022 CVE Vulnerabilities

27,552 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-31032MEDIUM4.3Tuleap is a Free & Open Source Suite to improve management of software developments and collaboration. In versions prior...
CVE-2022-33639HIGH8.3Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
CVE-2022-33638HIGH8.3Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
CVE-2022-33042HIGH7.2Online Railway Reservation System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /...
CVE-2022-30192HIGH8.3Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
CVE-2022-2252MEDIUM6.1Open Redirect in GitHub repository microweber/microweber prior to 1.2.19.
CVE-2022-32969MEDIUM5.9MetaMask before 10.11.3 might allow an attacker to access a user's secret recovery phrase because an input field is used...
CVE-2022-34043HIGH7.3Incorrect permissions for the folder C:\ProgramData\NoMachine\var\uninstall of Nomachine v7.9.2 allows attackers to perf...
CVE-2022-33037HIGH7.8A binary hijack in Orwell-Dev-Cpp v5.11 allows attackers to execute arbitrary code via a crafted .exe file.
CVE-2022-33036HIGH7.8A binary hijack in Embarcadero Dev-CPP v6.3 allows attackers to execute arbitrary code via a crafted .exe file.
CVE-2022-33035HIGH7.8XLPD v7.0.0094 and below contains an unquoted service path vulnerability which allows local users to launch processes wi...
CVE-2022-33107CRITICAL9.8ThinkPHP v6.0.12 was discovered to contain a deserialization vulnerability via the component vendor\league\flysystem-cac...
CVE-2022-33023HIGH7.5CVA6 commit 909d85a gives incorrect permission to use special multiplication units when the format of instructions is wr...
CVE-2022-33021HIGH7.5CVA6 commit 909d85a accesses invalid memory when reading the value of MHPMCOUNTER30.
CVE-2022-31897MEDIUM6.1SourceCodester Zoo Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via public_html/register_visitor?ms...
CVE-2022-31266MEDIUM4.3In ILIAS through 7.10, lack of verification when changing an email address (on the Profile Page) allows remote attackers...
CVE-2022-29272MEDIUM6.1In Nagios XI through 5.8.5, an open redirect vulnerability exists in the login function that could lead to spoofing.
CVE-2022-29271MEDIUM6.5In Nagios XI through 5.8.5, a read-only Nagios user (due to an incorrect permission check) is able to schedule downtime ...
CVE-2022-29270MEDIUM4.3In Nagios XI through 5.8.5, it is possible for a user without password verification to change his e-mail address.
CVE-2022-29269MEDIUM6.5In Nagios XI through 5.8.5, in the schedule report function, an authenticated attacker is able to inject HTML tags that ...
CVE-2022-28803MEDIUM5.4In SilverStripe Framework through 2022-04-07, Stored XSS can occur in javascript link tags added via XMLHttpRequest (XHR...
CVE-2022-32532CRITICAL9.8Apache Shiro before 1.9.1, A RegexRequestMatcher can be misconfigured to be bypassed on some servlet containers. Applica...
CVE-2022-31887CRITICAL9.8Marval MSM v14.19.0.12476 has a 0-Click Account Takeover vulnerability which allows an attacker to change any user's pas...
CVE-2022-31884MEDIUM6.5Marval MSM v14.19.0.12476 has an Improper Access Control vulnerability which allows a low privilege user to delete other...
CVE-2022-29858MEDIUM4.3Silverstripe silverstripe/assets through 1.10 is vulnerable to improper access control that allows protected images to b...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now