2022 CVE Vulnerabilities

27,552 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-32974MEDIUM6.5An authenticated attacker could read arbitrary files from the underlying operating system of the scanner using a custom ...
CVE-2022-32973HIGH8.8An authenticated attacker could create an audit file that bypasses PowerShell cmdlet checks and executes commands with a...
CVE-2022-31786MEDIUM6.1IdeaLMS 2022 allows reflected Cross Site Scripting (XSS) via the IdeaLMS/Class/Assessment/ PATH_INFO.
CVE-2022-30874MEDIUM5.4There is a Cross Site Scripting Stored (XSS) vulnerability in NukeViet CMS before 4.5.02.
CVE-2022-2068HIGH7.3In addition to the c_rehash shell command injection identified in CVE-2022-1292, further circumstances where the c_rehas...
CVE-2022-27872HIGH7.8A maliciously crafted PDF file may be used to dereference a pointer for read or write operation while parsing PDF files ...
CVE-2022-27871HIGH7.8Autodesk AutoCAD product suite, Revit, Design Review and Navisworks releases using PDFTron prior to 9.1.17 version may b...
CVE-2022-27870HIGH7.8A maliciously crafted TGA file in Autodesk AutoCAD 2023 may be used to write beyond the allocated buffer while parsing T...
CVE-2022-27869HIGH7.8A maliciously crafted TIFF file in Autodesk AutoCAD 2023 can be forced to read and write beyond allocated boundaries whe...
CVE-2022-27868HIGH7.8A maliciously crafted CAT file in Autodesk AutoCAD 2023 can be used to trigger use-after-free vulnerability. Exploitatio...
CVE-2022-27867HIGH7.8A maliciously crafted JT file in Autodesk AutoCAD 2022, 2021, 2020, 2019 can be used to trigger use-after-free vulnerabi...
CVE-2022-26147CRITICAL9.8The Quectel RG502Q-EA modem before 2022-02-23 allow OS Command Injection.
CVE-2022-23171HIGH8.8AtlasVPN - Privilege Escalation Lack of proper security controls on named pipe messages can allow an attacker with low p...
CVE-2022-22979HIGH7.5In Spring Cloud Function versions prior to 3.2.6, it is possible for a user who directly interacts with framework provid...
CVE-2022-1833HIGH8.8A flaw was found in AMQ Broker Operator 7.9.4 installed via UI using OperatorHub where a low-privilege user that has acc...
CVE-2022-1665HIGH8.2A set of pre-production kernel packages of Red Hat Enterprise Linux for IBM Power architecture can be booted by the grub...
CVE-2022-1596MEDIUM6.5Incorrect Permission Assignment for Critical Resource vulnerability in ABB REX640 PCL1, REX640 PCL2, REX640 PCL3 allows ...
CVE-2022-33056HIGH7.2Online Railway Reservation System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /...
CVE-2022-33055HIGH7.2Online Railway Reservation System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /...
CVE-2022-33049HIGH7.2Online Railway Reservation System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /...
CVE-2022-33048HIGH7.2Online Railway Reservation System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /...
CVE-2022-31478MEDIUM4.3The UserTakeOver plugin before 4.0.1 for ILIAS allows an attacker to list all users via the search function.
CVE-2022-29775CRITICAL9.8iSpyConnect iSpy v7.2.2.0 allows attackers to bypass authentication via a crafted URL.
CVE-2022-29774CRITICAL9.8iSpy v7.2.2.0 is vulnerable to remote command execution via path traversal.
CVE-2022-25585MEDIUM5.4Unioncms v1.0.13 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Default settings.

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now