2022 CVE Vulnerabilities

27,552 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-26026HIGH7.5A denial of service vulnerability exists in the OAS Engine SecureConfigValues functionality of Open Automation Software ...
CVE-2022-29402MEDIUM6.8TP-Link TL-WR840N EU v6.20 was discovered to contain insecure protections for its UART console. This vulnerability allow...
CVE-2022-29248HIGH8.1Guzzle is a PHP HTTP client. Guzzle prior to versions 6.5.6 and 7.4.3 contains a vulnerability with the cookie middlewar...
CVE-2022-30428HIGH7.5In ginadmin through 05-10-2022, the incoming path value is not filtered, resulting in arbitrary file reading.
CVE-2022-30427HIGH7.5In ginadmin through 05-10-2022 the incoming path value is not filtered, resulting in directory traversal.
CVE-2022-29408MEDIUM6.1Persistent Cross-Site Scripting (XSS) vulnerability in Vsourz Digital's Advanced Contact form 7 DB plugin <= 1.8.7 at Wo...
CVE-2022-28875MEDIUM6.5A Denial-of-Service (DoS) vulnerability was discovered in F-Secure Atlant and in certain WithSecure products whereby the...
CVE-2022-27305HIGH8.8Gibbon v23 does not generate a new session ID cookie after a user authenticates, making the application vulnerable to se...
CVE-2022-23775CRITICAL9.8TrueStack Direct Connect 1.4.7 has Incorrect Access Control.
CVE-2022-1348MEDIUM6.5A vulnerability was found in logrotate in how the state file is created. The state file is used to prevent parallel exec...
CVE-2022-1678HIGH7.5An issue was discovered in the Linux Kernel from 4.18 to 4.19, an improper update of sock reference in TCP pacing can le...
CVE-2022-29380MEDIUM4.8Academy-LMS v4.3 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the SEO panel.
CVE-2022-22127HIGH7.2Tableau is aware of a broken access control vulnerability present in Tableau Server affecting Tableau Server customers u...
CVE-2022-29651HIGH7.2An arbitrary file upload vulnerability in the Select Image function of Online Food Ordering System v1.0 allows attackers...
CVE-2022-29650CRITICAL9.8Online Food Ordering System v1.0 was discovered to contain a SQL injection vulnerability via the Search parameter at /on...
CVE-2022-29379CRITICAL9.8Nginx NJS v0.7.3 was discovered to contain a stack overflow in the function njs_default_module_loader at /src/njs/src/nj...
CVE-2022-1851HIGH7.8Out-of-bounds Read in GitHub repository vim/vim prior to 8.2.
CVE-2022-30595CRITICAL9.8libImaging/TgaRleDecode.c in Pillow 9.1.0 has a heap buffer overflow in the processing of invalid TGA image files.
CVE-2022-30323HIGH8.6go-getter up to 1.5.11 and 2.0.2 panicked when processing password-protected ZIP files. Fixed in 1.6.1 and 2.1.0.
CVE-2022-30322HIGH8.6go-getter up to 1.5.11 and 2.0.2 allowed asymmetric resource exhaustion when go-getter processed malicious HTTP response...
CVE-2022-30321HIGH8.6go-getter up to 1.5.11 and 2.0.2 allowed arbitrary host access via go-getter path traversal, symlink processing, and com...
CVE-2022-28862CRITICAL9.8In Archibus Web Central before 26.2, multiple SQL Injection vulnerabilities occur in dwr/call/plaincall/workflow.runWork...
CVE-2022-26945CRITICAL9.8go-getter up to 1.5.11 and 2.0.2 allowed protocol switching, endless redirect, and configuration bypass via abuse of cus...
CVE-2022-21951MEDIUM6.8A Cleartext Transmission of Sensitive Information vulnerability in SUSE Rancher, Rancher allows attackers on the network...
CVE-2022-1883HIGH8.8SQL Injection in GitHub repository camptocamp/terraboard prior to 2.2.0.

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now