2022 CVE Vulnerabilities

27,552 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-30661HIGH7.8Adobe InDesign versions 17.2.1 (and earlier) and 16.4.1 (and earlier) are affected by a Heap-based Buffer Overflow vulne...
CVE-2022-30660HIGH7.8Adobe InDesign versions 17.2.1 (and earlier) and 16.4.1 (and earlier) are affected by an out-of-bounds write vulnerabili...
CVE-2022-30659HIGH7.8Adobe InDesign versions 17.2.1 (and earlier) and 16.4.1 (and earlier) are affected by an out-of-bounds write vulnerabili...
CVE-2022-30658HIGH7.8Adobe InDesign versions 17.2.1 (and earlier) and 16.4.1 (and earlier) are affected by a Heap-based Buffer Overflow vulne...
CVE-2022-29865HIGH7.5OPC UA .NET Standard Stack allows a remote attacker to bypass the application authentication check via crafted fake cred...
CVE-2022-29862HIGH7.5An infinite loop in OPC UA .NET Standard Stack 1.04.368 allows a remote attackers to cause the application to hang via a...
CVE-2022-1642HIGH7.5A program using swift-corelibs-foundation is vulnerable to a denial of service attack caused by a potentially malicious ...
CVE-2022-31914MEDIUM5.4Zoo Management System v1.0 is vulnerable to Cross Site Scripting (XSS) via zms/admin/public_html/save_animal?an_id=24.
CVE-2022-31291HIGH7.5An issue in dlt_config_file_parser.c of dlt-daemon v2.18.8 allows attackers to cause a double free via crafted TCP packe...
CVE-2022-27532HIGH7.8A maliciously crafted TIF file in Autodesk 3ds Max 2022 and 2021 can be used to write beyond the allocated buffer while ...
CVE-2022-27531HIGH7.8A maliciously crafted TIF file can be forced to read beyond allocated boundaries in Autodesk 3ds Max 2022, and 2021 when...
CVE-2022-22953MEDIUM6.5VMware HCX update addresses an information disclosure vulnerability. A malicious actor with network user access to the V...
CVE-2022-31913MEDIUM4.8Online Discussion Forum Site v1.0 is vulnerable to Cross Site Scripting (XSS) via /odfs/classes/Master.php?f=save_catego...
CVE-2022-31912HIGH7.2Online Tutor Portal Site v1.0 is vulnerable to SQL Injection via /otps/classes/Master.php?f=delete_team.
CVE-2022-31911HIGH7.2Online Discussion Forum Site v1.0 is vulnerable to SQL Injection via /odfs/classes/Master.php?f=delete_team.
CVE-2022-31910MEDIUM4.8Online Tutor Portal Site v1.0 is vulnerable to Cross Site Scripting (XSS). via /otps/classes/Master.php.
CVE-2022-31908HIGH7.2Student Registration and Fee Payment System v1.0 is vulnerable to SQL Injection via /scms/student.php.
CVE-2022-31906MEDIUM4.8Online Fire Reporting System v1.0 is vulnerable to Cross Site Scripting (XSS) via /ofrs/classes/Master.php.
CVE-2022-31849HIGH8.8MERCURY MIPC451-4 1.0.22 Build 220105 Rel.55642n was discovered to contain a remote code execution (RCE) vulnerability w...
CVE-2022-31300MEDIUM5.4A cross-site scripting vulnerability in the DM Section component of Haraj v3.7 allows attackers to execute arbitrary web...
CVE-2022-31277HIGH8.8Xiaomi Lamp 1 v2.0.4_0066 was discovered to be vulnerable to replay attacks. This allows attackers to to bypass the expe...
CVE-2022-30023HIGH8.8Tenda ONT GPON AC1200 Dual band WiFi HG9 v1.0.1 is vulnerable to Command Injection via the Ping function.
CVE-2022-31372HIGH7.5Wiris Mathtype v7.28.0 was discovered to contain a path traversal vulnerability in the resourceFile parameter. This vuln...
CVE-2022-2098CRITICAL9.8Weak Password Requirements in GitHub repository kromitgmbh/titra prior to 0.78.1.
CVE-2022-31626HIGH8.8In PHP versions 7.4.x below 7.4.30, 8.0.x below 8.0.20, and 8.1.x below 8.1.7, when pdo_mysql extension with mysqlnd dri...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now