2022 CVE Vulnerabilities

27,525 CVEs published in 2022.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2022-23005HIGH8.7Western Digital has identified a weakness in the UFS standard that could result in a security vulnerability. This vulner...
CVE-2022-37719HIGH8.8A Cross-Site Request Forgery (CSRF) in the management portal of JetNexus/EdgeNexus ADC 4.2.8 allows attackers to escalat...
CVE-2022-37718HIGH8.8The management portal component of JetNexus/EdgeNexus ADC 4.2.8 was discovered to contain a command injection vulnerabil...
CVE-2022-38725HIGH7.5An integer overflow in the RFC3164 parser in One Identity syslog-ng 3.0 through 3.37 allows remote attackers to cause a ...
CVE-2022-4746HIGH7.5The FluentAuth WordPress plugin before 1.0.2 prioritizes getting a visitor's IP address from certain HTTP headers over P...
CVE-2022-4323HIGH7.2The Analyticator WordPress plugin before 6.5.6 unserializes user input provided via the settings, which could allow high...
CVE-2022-4303HIGH7.5The WP Limit Login Attempts WordPress plugin through 2.6.4 prioritizes getting a visitor's IP from certain HTTP headers ...
CVE-2022-4230HIGH8.8The WP Statistics WordPress plugin before 13.2.9 does not escape a parameter, which could allow authenticated users to p...
CVE-2022-4017HIGH8.8The Booster for WooCommerce WordPress plugin before 6.0.1, Booster Plus for WooCommerce WordPress plugin before 6.0.1, B...
CVE-2022-47065HIGH8.8TrendNet Wireless AC Easy-Upgrader TEW-820AP v1.0R, firmware version 1.01.B01 was discovered to contain a stack overflow...
CVE-2022-3425HIGH7.2The Analyticator WordPress plugin before 6.5.6 unserializes user input provided via the settings, which could allow high...
CVE-2022-3918HIGH8.8A program using FoundationNetworking in swift-corelibs-foundation is potentially vulnerable to CRLF ( ) injection in URL...
CVE-2022-1109HIGH7.5An incorrect default permissions vulnerability in Lenovo Leyun cloud music application could allow denial of service.
CVE-2022-48279HIGH7.5In ModSecurity before 2.9.6 and 3.x before 3.0.8, HTTP multipart requests were incorrectly parsed and could bypass the W...
CVE-2022-47024HIGH7.8A null pointer dereference issue was discovered in function gui_x11_create_blank_mouse in gui_x11.c in vim 8.1.2269 thru...
CVE-2022-47021HIGH7.8A null pointer dereference issue was discovered in functions op_get_data and op_open1 in opusfile.c in xiph opusfile 0.9...
CVE-2022-47012HIGH7.5Use of uninitialized variable in function gen_eth_recv in GNS3 dynamips 0.2.21.
CVE-2022-45748HIGH8.8An issue was discovered with assimp 5.1.4, a use after free occurred in function ColladaParser::ExtractDataObjectFromCha...
CVE-2022-38112HIGH7.5In DPA 2022.4 and older releases, generated heap memory dumps contain sensitive information in cleartext.
CVE-2022-47747HIGH7.5kraken <= 0.1.4 has an arbitrary file read vulnerability via the component testfs.
CVE-2022-47732HIGH7.5In Yeastar N412 and N824 Configuration Panel 42.x and 45.x, an unauthenticated attacker can create backup file and downl...
CVE-2022-25631HIGH7.8Symantec Endpoint Protection, prior to 14.3 RU6 (14.3.9210.6000), may be susceptible to a Elevation of Privilege vulnera...
CVE-2022-48191HIGH7A vulnerability exists in Trend Micro Maximum Security 2022 (17.7) wherein a low-privileged user can write a known malic...
CVE-2022-20964HIGH8.8A vulnerability in the web-based management interface of Cisco Identity Services Engine could allow an authenticated, re...
CVE-2022-47766HIGH8.8PopojiCMS v2.0.1 backend plugin function has a file upload vulnerability.

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now