2022 CVE Vulnerabilities

27,553 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-1771MEDIUM5.5Uncontrolled Recursion in GitHub repository vim/vim prior to 8.2.4975.
CVE-2022-30600CRITICAL9.8A flaw was found in moodle where logic used to count failed login attempts could result in the account lockout threshold...
CVE-2022-30599CRITICAL9.8A flaw was found in moodle where an SQL injection risk was identified in Badges code relating to configuring criteria.
CVE-2022-30598MEDIUM4.3A flaw was found in moodle where global search results could include author information on some activities where a user ...
CVE-2022-30597MEDIUM5.3A flaw was found in moodle where the description user field was not hidden when being set as a hidden user field.
CVE-2022-30111MEDIUM6.8Due to the use of an insecure algorithm for rolling codes in MCK Smartlock 1.0, allows attackers to unlock the mechanism...
CVE-2022-28921MEDIUM6.5A Cross-Site Request Forgery (CSRF) vulnerability discovered in BlogEngine.Net v3.3.8.0 allows unauthenticated attackers...
CVE-2022-25617MEDIUM6.1Reflected Cross-Site Scripting (XSS) vulnerability in Code Snippets plugin <= 2.14.3 at WordPress via &orderby vulnerabl...
CVE-2022-30596MEDIUM5.4A flaw was found in moodle where ID numbers displayed when bulk allocating markers to assignments required additional sa...
CVE-2022-29445HIGH7.2Authenticated (administrator or higher role) Local File Inclusion (LFI) vulnerability in Wow-Company's Popup Box plugin ...
CVE-2022-28924MEDIUM6.5An information disclosure vulnerability in UniverSIS-Students before v1.5.0 allows attackers to obtain sensitive informa...
CVE-2022-25162MEDIUM5.3Improper Input Validation vulnerability in Mitsubishi Electric MELSEC iQ-F series FX5U-xMy/z(x=32,64,80, y=T,R, z=ES,DS,...
CVE-2022-25161HIGH8.6Improper Input Validation vulnerability in Mitsubishi Electric MELSEC iQ-F series FX5U-xMy/z(x=32,64,80, y=T,R, z=ES,DS,...
CVE-2022-22787HIGH7.5The Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.10.0 fails to properly valid...
CVE-2022-22778HIGH8.8The Web Server component of TIBCO Software Inc.'s TIBCO BusinessConnect Trading Community Management contains an easily ...
CVE-2022-22777MEDIUM6.1The Web Server component of TIBCO Software Inc.'s TIBCO BusinessConnect Trading Community Management contains easily exp...
CVE-2022-22776MEDIUM5.4The Web Server component of TIBCO Software Inc.'s TIBCO BusinessConnect Trading Community Management contains easily exp...
CVE-2022-1734HIGH7A flaw in Linux Kernel found in nfcmrvl_nci_unregister_dev() in drivers/nfc/nfcmrvl/main.c can lead to use after free bo...
CVE-2022-0883HIGH7.8SLM has an issue with Windows Unquoted/Trusted Service Paths Security Issue. All installations version 9.x.x prior to 9....
CVE-2022-30105CRITICAL9.8In Belkin N300 Firmware 1.00.08, the script located at /setting_hidden.asp, which is accessible before and after configu...
CVE-2022-28917HIGH7.5Tenda AX12 v22.03.01.21_cn was discovered to contain a stack overflow via the lanIp parameter in /goform/AdvSetLanIp.
CVE-2022-22786HIGH8.8The Zoom Client for Meetings for Windows before version 5.10.0 and Zoom Rooms for Conference Room for Windows before ver...
CVE-2022-22785CRITICAL9.1The Zoom Client for Meetings (for Android, iOS, Linux, MacOS, and Windows) before version 5.10.0 failed to properly cons...
CVE-2022-22784HIGH8.1The Zoom Client for Meetings (for Android, iOS, Linux, MacOS, and Windows) before version 5.10.0 failed to properly pars...
CVE-2022-1767HIGH7.5Server-Side Request Forgery (SSRF) in GitHub repository jgraph/drawio prior to 18.0.7.

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now