2022 CVE Vulnerabilities

27,525 CVEs published in 2022.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2022-36246CRITICAL9.8Shop Beat Solutions (Pty) LTD Shop Beat Media Player 2.5.95 up to 3.2.57 is vulnerable to Insecure Permissions.
CVE-2022-24629CRITICAL9.8An issue was discovered in AudioCodes Device Manager Express through 7.8.20002.47752. Remote code execution can be achie...
CVE-2022-24627CRITICAL9.8An issue was discovered in AudioCodes Device Manager Express through 7.8.20002.47752. It is an unauthenticated SQL injec...
CVE-2022-48479CRITICAL9.8The facial recognition TA of some products has the out-of-bounds memory read vulnerability. Successful exploitation of t...
CVE-2022-48478CRITICAL9.8The facial recognition TA of some products lacks memory length verification. Successful exploitation of this vulnerabili...
CVE-2022-46738CRITICAL9.8The affected product exposes multiple sensitive data fields of the affected product. An attacker can use the SNMP comman...
CVE-2022-46658CRITICAL9.8The affected product is vulnerable to a stack-based buffer overflow which could lead to a denial of service or remote co...
CVE-2022-46680CRITICAL9.8 A CWE-319: Cleartext transmission of sensitive information vulnerability exists that could cause disclosure of sensitiv...
CVE-2022-44739CRITICAL9.8Cross-Site Request Forgery (CSRF) vulnerability in ThingsForRestaurants Quick Restaurant Reservations plugin <= 1.5.4 ve...
CVE-2022-47984CRITICAL9.8IBM InfoSphere Information Server 11.7 is vulnerable to SQL injection. A remote attacker could send specially crafted SQ...
CVE-2022-36327CRITICAL9.8Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could allow an attacke...
CVE-2022-4774CRITICAL9.8The Bit Form WordPress plugin before 1.9 does not validate the file types uploaded via it's file upload form field, allo...
CVE-2022-47937CRITICAL9.8Improper input validation in the Apache Sling Commons JSON bundle allows an attacker to trigger unexpected errors by sup...
CVE-2022-47129CRITICAL9.8PHPOK v6.3 was discovered to contain a remote code execution (RCE) vulnerability.
CVE-2022-29841CRITICAL9.8Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that was caused...
CVE-2022-29842CRITICAL9.8Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability that could allow an at...
CVE-2022-36937CRITICAL9.8HHVM 4.172.0 and all prior versions use TLS 1.0 for secure connections when handling tls:// URLs in the stream extension...
CVE-2022-4118CRITICAL9.8The Bitcoin / AltCoin Payment Gateway for WooCommerce & Multivendor store / shop WordPress plugin through 1.7.1 does not...
CVE-2022-47757CRITICAL9.8In imo.im 2022.11.1051, a path traversal vulnerability delivered via an unsanitized deeplink can force the application t...
CVE-2022-35898CRITICAL9.8OpenText BizManager before 16.6.0.1 does not perform proper validation during the change-password operation. This allows...
CVE-2022-46365CRITICAL9.1Apache StreamPark 1.0.0 before 2.0.0 When the user successfully logs in, to modify his profile, the username will be pas...
CVE-2022-45802CRITICAL9.8Streampark allows any users to upload a jar as application, but there is no mandatory verification of the uploaded file ...
CVE-2022-41400CRITICAL9.8Sage 300 through 2022 uses a hard-coded 40-byte blowfish key to encrypt and decrypt user passwords and SQL connection st...
CVE-2022-41397CRITICAL9.8The optional Web Screens and Global Search features for Sage 300 through version 2022 use a hard-coded 40-byte blowfish ...
CVE-2022-47758CRITICAL9.8Nanoleaf firmware v7.1.1 and below is missing TLS verification, allowing attackers to execute arbitrary code via a DNS h...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now