2022 CVE Vulnerabilities

27,552 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-25872MEDIUM5.3All versions of package fast-string-search are vulnerable to Out-of-bounds Read due to incorrect memory freeing and leng...
CVE-2022-25871HIGH7.5All versions of package querymen are vulnerable to Prototype Pollution if the parameters of exported function handler(ty...
CVE-2022-25856HIGH7.5The package github.com/argoproj/argo-events/sensors/artifacts before 1.7.1 are vulnerable to Directory Traversal in the ...
CVE-2022-25852HIGH7.5All versions of package pg-native; all versions of package libpq are vulnerable to Denial of Service (DoS) when the addo...
CVE-2022-25345HIGH7.5All versions of package @discordjs/opus are vulnerable to Denial of Service (DoS) when trying to encode using an encoder...
CVE-2022-22138HIGH7.5All versions of package fast-string-search are vulnerable to Denial of Service (DoS) when computations are incorrect for...
CVE-2022-21213HIGH7.5This affects all versions of package mout. The deepFillIn function can be used to 'fill missing properties recursively',...
CVE-2022-31941CRITICAL9.8Rescue Dispatch Management System v1.0 is vulnerable to SQL Injection via \rdms\admin?page=user\manage_user&id=.
CVE-2022-31083HIGH7.5Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version...
CVE-2022-29496CRITICAL9.8A stack-based buffer overflow vulnerability exists in the BlynkConsole.h runCommand functionality of Blynk -Library v1.0...
CVE-2022-21806CRITICAL9.8A use-after-free vulnerability exists in the mips_collector appsrv_server functionality of Anker Eufy Homebase 2 2.1.8.5...
CVE-2022-21184MEDIUM5.9An information disclosure vulnerability exists in the License registration functionality of Bachmann Visutec GmbH Atvise...
CVE-2022-30422CRITICAL9.8Proietti Tech srl Planet Time Enterprise 4.2.0.1,4.2.0.0,4.1.0.0,4.0.0.0,3.3.1.0,3.3.0.0 is vulnerable to Remote code ex...
CVE-2022-32444MEDIUM6.1An issue was discovered in u5cms verion 8.3.5 There is a URL redirection vulnerability that can cause a user's browser t...
CVE-2022-32442MEDIUM6.1u5cms version 8.3.5 is vulnerable to Cross Site Scripting (XSS). When a user accesses the default home page if the param...
CVE-2022-30607MEDIUM6.5IBM Robotic Process Automation 20.10.0, 20.12.5, 21.0.0, 21.0.1, and 21.0.2 contains a vulnerability that could allow a ...
CVE-2022-22485CRITICAL9.8In some cases, an unsuccessful attempt to log into IBM Spectrum Protect Operations Center 8.1.0.000 through 8.1.14.000 d...
CVE-2022-31357CRITICAL9.8Online Ordering System v2.3.2 was discovered to contain a SQL injection vulnerability via /ordering/admin/inventory/inde...
CVE-2022-31356CRITICAL9.8Online Ordering System v2.3.2 was discovered to contain a SQL injection vulnerability via /ordering/admin/store/index.ph...
CVE-2022-31355CRITICAL9.8Online Ordering System v2.3.2 was discovered to contain a SQL injection vulnerability via /ordering/index.php?q=category...
CVE-2022-31246MEDIUM5.5paymentrequest.py in Electrum before 4.2.2 allows a file:// URL in the r parameter of a payment request (e.g., within QR...
CVE-2022-33915HIGH7Versions of the Amazon AWS Apache Log4j hotpatch package before log4j-cve-2021-44228-hotpatch-1.3.5 are affected by a ra...
CVE-2022-33912HIGH7.8A permission issue affects users that deployed the shipped version of the Checkmk Debian package. Packages created by th...
CVE-2022-32276HIGH7.5Grafana 8.4.3 allows unauthenticated access via (for example) a /dashboard/snapshot/*?orgId=0 URI. NOTE: the vendor cons...
CVE-2022-31784CRITICAL9.8A vulnerability in the management interface of MiVoice Business through 9.3 PR1 and MiVoice Business Express through 8.0...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now