2022 CVE Vulnerabilities

27,525 CVEs published in 2022.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2022-35976CRITICAL9.8The GitOps Tools Extension for VSCode relies on kubeconfigs in order to communicate with Kubernetes clusters. A speciall...
CVE-2022-37061CRITICAL9.8All FLIR AX8 thermal sensor cameras version up to and including 1.46.16 are vulnerable to Remote Command Injection. This...
CVE-2022-35975CRITICAL9.8The GitOps Tools Extension for VSCode can make it easier to manage Flux objects. A specially crafted Flux object may all...
CVE-2022-35175CRITICAL9.8Barangay Management System v1.0 was discovered to contain a SQL injection vulnerability via the hidden_id parameter at /...
CVE-2022-2876CRITICAL9.8A vulnerability, which was classified as critical, was found in SourceCodester Student Management System. Affected is an...
CVE-2022-35164CRITICAL9.8LibreDWG v0.12.4.4608 & commit f2dea29 was discovered to contain a heap use-after-free via bit_copy_chain.
CVE-2022-35154CRITICAL9.8Shopro Mall System v1.3.8 was discovered to contain a SQL injection vulnerability via the value parameter.
CVE-2022-35153CRITICAL9.8FusionPBX 5.0.1 was discovered to contain a command injection vulnerability via /fax/fax_send.php.
CVE-2022-35606CRITICAL9.8A SQL injection vulnerability in CustomerDAO.java in sazanrjb InventoryManagementSystem 1.0 allows attackers to execute ...
CVE-2022-35605CRITICAL9.8A SQL injection vulnerability in UserDAO.java in sazanrjb InventoryManagementSystem 1.0 allows attackers to execute arbi...
CVE-2022-35603CRITICAL9.8A SQL injection vulnerability in CustomerDAO.java in sazanrjb InventoryManagementSystem 1.0 allows attackers to execute ...
CVE-2022-35602CRITICAL9.8A SQL injection vulnerability in UserDAO.java in sazanrjb InventoryManagementSystem 1.0 allows attackers to execute arbi...
CVE-2022-35601CRITICAL9.8A SQL injection vulnerability in SupplierDAO.java in sazanrjb InventoryManagementSystem 1.0 allows attackers to execute ...
CVE-2022-35599CRITICAL9.8A SQL injection vulnerability in Stocks.java in sazanrjb InventoryManagementSystem 1.0 allows attackers to execute arbit...
CVE-2022-35598CRITICAL9.8A SQL injection vulnerability in ConnectionFactoryDAO.java in sazanrjb InventoryManagementSystem 1.0 allows attackers to...
CVE-2022-35147CRITICAL9.8DoraCMS v2.18 and earlier allows attackers to bypass login authentication via a crafted HTTP request.
CVE-2022-35122CRITICAL9.1An access control issue in Ecowitt GW1100 Series Weather Stations <=GW1100B_v2.1.5 allows unauthenticated attackers to a...
CVE-2022-2336CRITICAL9.8Softing Secure Integration Server, edgeConnector, and edgeAggregator software ships with the default administrator crede...
CVE-2022-23764CRITICAL9.8The vulnerability causing from insufficient verification procedures for downloaded files during WebCube update. Remote a...
CVE-2022-23747CRITICAL9.8In Sony Xperia series 1, 5, and Pro, an out of bound memory access can occur due to lack of validation of the number of ...
CVE-2022-35516CRITICAL9.8DedeCMS v5.7.93 - v5.7.96 was discovered to contain a remote code execution vulnerability in login.php.
CVE-2022-35121CRITICAL9.8Novel-Plus v3.6.1 was discovered to contain a SQL injection vulnerability via the keyword parameter at /service/impl/Boo...
CVE-2022-2870CRITICAL9.8A vulnerability was found in laravel 5.1 and classified as problematic. This issue affects some unknown processing. The ...
CVE-2022-22455CRITICAL9.8IBM Security Verify Governance Identity Manager 10.0 virtual appliance component performs an operation at a privilege le...
CVE-2022-36190CRITICAL9.8GPAC mp4box 2.1-DEV-revUNKNOWN-master has a use-after-free vulnerability in function gf_isom_dovi_config_get. This vulne...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now