2022 CVE Vulnerabilities

27,525 CVEs published in 2022.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2022-41953HIGH7.8Git GUI is a convenient graphical tool that comes with Git for Windows. Its target audience is users who are uncomfortab...
CVE-2022-43975HIGH7.5An issue was discovered in FC46-WebBridge on GE Grid Solutions MS3000 devices before 3.7.6.25p0_3.2.2.17p0_4.7p0. A vuln...
CVE-2022-40319HIGH7.5The LISTSERV 17 web interface allows remote attackers to conduct Insecure Direct Object References (IDOR) attacks via a ...
CVE-2022-2251HIGH8Improper sanitization of branch names in GitLab Runner affecting all versions prior to 15.3.5, 15.4 prior to 15.4.4, and...
CVE-2022-23538HIGH7.6github.com/sylabs/scs-library-client is the Go client for the Singularity Container Services (SCS) Container Library Ser...
CVE-2022-4891HIGH7.5A vulnerability has been found in Sisimai up to 4.25.14p11 and classified as problematic. This vulnerability affects the...
CVE-2022-3650HIGH7.8A privilege escalation flaw was found in Ceph. Ceph-crash.service allows a local attacker to escalate privileges to root...
CVE-2022-41860HIGH7.5In freeradius, when an EAP-SIM supplicant sends an unknown SIM option, the server will try to look that option up in the...
CVE-2022-41859HIGH7.5In freeradius, the EAP-PWD function compute_password_element() leaks information about the password which allows an atta...
CVE-2022-41858HIGH7.1A flaw was found in the Linux kernel. A NULL pointer dereference may occur while a slip driver is in progress to detach ...
CVE-2022-4621HIGH8.8Panasonic Sanyo CCTV Network Cameras versions 1.02-05 and 2.03-0x are vulnerable to CSRFs that can be exploited to allo...
CVE-2022-3091HIGH7.5RONDS EPM version 1.19.5 has a vulnerability in which a function could allow unauthenticated users to leak credentials....
CVE-2022-47318HIGH8ruby-git versions prior to v1.13.0 allows a remote authenticated attacker to execute an arbitrary ruby code by having a ...
CVE-2022-46648HIGH8ruby-git versions prior to v1.13.0 allows a remote authenticated attacker to execute an arbitrary ruby code by having a ...
CVE-2022-46891HIGH8.8An issue was discovered in the Arm Mali GPU Kernel Driver. There is a use-after-free. A non-privileged user can make imp...
CVE-2022-43462HIGH7.2Auth. SQL Injection (SQLi) vulnerability in Adeel Ahmed's IP Blacklist Cloud plugin <= 5.00 versions.
CVE-2022-30544HIGH8.8Cross-Site Request Forgery (CSRF) in MiKa's OSM – OpenStreetMap plugin <= 6.0.1 versions.
CVE-2022-3087HIGH7.8 Fuji Electric Tellus Lite V-Simulator versions 4.0.12.0 and prior are vulnerable to an out-of-bounds write which may al...
CVE-2022-4547HIGH7.2The Conditional Payment Methods for WooCommerce WordPress plugin through 1.0 does not properly sanitise and escape a par...
CVE-2022-47630HIGH7.4Trusted Firmware-A through 2.8 has an out-of-bounds read in the X.509 parser for parsing boot certificates. This affects...
CVE-2022-43719HIGH8.8Two legacy REST API endpoints for approval and request access are vulnerable to cross site request forgery. This issue a...
CVE-2022-4258HIGH7.8In multiple versions of HIMA PC based Software an unquoted Windows search path vulnerability might allow local users to ...
CVE-2022-45353HIGH8.1Broken Access Control in Betheme theme <= 26.6.1 on WordPress.
CVE-2022-41955HIGH8.8Autolab is a course management service, initially developed by a team of students at Carnegie Mellon University, that en...
CVE-2022-41721HIGH7.5A request smuggling attack is possible when using MaxBytesHandler. When using MaxBytesHandler, the body of an HTTP reque...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now