2022 CVE Vulnerabilities

27,525 CVEs published in 2022.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2022-39989CRITICAL9.8An issue was discovered in Fighting Cock Information System 1.0, which uses default credentials, but does not force nor ...
CVE-2022-48477CRITICAL9.8In JetBrains Hub before 2023.1.15725 SSRF protection in Auth Module integration was missing
CVE-2022-29606CRITICAL9.8An issue was discovered in ONOS 2.5.1. An intent with a large port number shows the CORRUPT state, which is misleading t...
CVE-2022-29604CRITICAL9.8An issue was discovered in ONOS 2.5.1. An intent with an uppercase letter in a device ID shows the CORRUPT state, which ...
CVE-2022-46640CRITICAL9.8Nanoleaf Desktop App before v1.3.1 was discovered to contain a command injection vulnerability which is exploited via a ...
CVE-2022-48312CRITICAL9.1The HwPCAssistant module has the out-of-bounds read/write vulnerability. Successful exploitation of this vulnerability m...
CVE-2022-34128CRITICAL9.8The Cartography (aka positions) plugin before 6.0.1 for GLPI allows remote code execution via PHP code in the POST data ...
CVE-2022-2525CRITICAL9.8Improper Restriction of Excessive Authentication Attempts in GitHub repository janeczku/calibre-web prior to 0.6.20.
CVE-2022-3748CRITICAL9.8Improper Authorization vulnerability in ForgeRock Inc. Access Management allows Authentication Bypass. This issue affect...
CVE-2022-45174CRITICAL9.8An issue was discovered in LIVEBOX Collaboration vDesk through v018. A Bypass of Two-Factor Authentication for SAML User...
CVE-2022-45173CRITICAL9.8An issue was discovered in LIVEBOX Collaboration vDesk through v018. A Bypass of Two-Factor Authentication can occur und...
CVE-2022-47027CRITICAL9.8Timmystudios Fast Typing Keyboard v1.275.1.162 allows unauthorized apps to overwrite arbitrary files in its internal sto...
CVE-2022-45064CRITICAL9The SlingRequestDispatcher doesn't correctly implement the RequestDispatcher API resulting in a generic type of include-...
CVE-2022-33259CRITICAL9.8Memory corruption due to buffer copy without checking the size of input in modem while decoding raw SMS received.
CVE-2022-33211CRITICAL9.8memory corruption in modem due to improper check while calculating size of serialized CoAP message
CVE-2022-25745CRITICAL9.8Memory corruption in modem due to improper input validation while handling the incoming CoAP message
CVE-2022-25740CRITICAL9.8Memory corruption in modem due to buffer overwrite while building an IPv6 multicast address based on the MAC address of ...
CVE-2022-25678CRITICAL9.8Memory correction in modem due to buffer overwrite during coap connection
CVE-2022-41331CRITICAL9.8A missing authentication for critical function vulnerability [CWE-306] in FortiPresence infrastructure server before ver...
CVE-2022-46709CRITICAL9.8A memory corruption issue was addressed with improved state management. This issue is fixed in macOS Ventura 13, iOS 16....
CVE-2022-31890CRITICAL9.8SQL Injection vulnerability in audit/class.audit.php in osTicket osTicket-plugins before commit a7842d494889fd5533d13deb...
CVE-2022-4939CRITICAL9.8THe WCFM Membership plugin for WordPress is vulnerable to privilege escalation in versions up to, and including 2.10.0, ...
CVE-2022-43939CRITICAL9.8Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.1 and 9.3.0.2, including 8.3.x contain security ...
CVE-2022-38923CRITICAL9.8BluePage CMS thru v3.9 processes an insufficiently sanitized HTTP Header allowing MySQL Injection in the 'User-Agent' fi...
CVE-2022-38922CRITICAL9.8BluePage CMS thru 3.9 processes an insufficiently sanitized HTTP Header Cookie value allowing MySQL Injection in the 'us...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now