2022 CVE Vulnerabilities

27,525 CVEs published in 2022.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2022-31179CRITICAL9.8Shescape is a simple shell escape package for JavaScript. Versions prior to 1.5.8 were found to be subject to code injec...
CVE-2022-2595CRITICAL10Improper Authorization in GitHub repository kromitgmbh/titra prior to 0.79.1.
CVE-2022-26437CRITICAL9.8In httpclient, there is a possible out of bounds write due to uninitialized data. This could lead to remote escalation o...
CVE-2022-2317CRITICAL9.8The Simple Membership WordPress plugin before 4.1.3 allows user to change their membership at the registration stage due...
CVE-2022-1950CRITICAL9.8The Youzify WordPress plugin before 1.2.0 does not sanitise and escape a parameter before using it in a SQL statement vi...
CVE-2022-27255CRITICAL9.8In Realtek eCos RSDK 1.5.7p1 and MSDK 4.9.4p1, the SIP ALG function that rewrites SDP data has a stack-based buffer over...
CVE-2022-31775CRITICAL9.1IBM DataPower Gateway 10.0.2.0 through 10.0.4.0, 10.0.1.0 through 10.0.1.8, 10.5.0.0, and 2018.4.1.0 through 2018.4.1.21...
CVE-2022-30083CRITICAL9.8EllieGrid Android Application version 3.4.1 is vulnerable to Code Injection. The application appears to evaluate user in...
CVE-2022-34531CRITICAL9.8DedeCMS v5.7.95 was discovered to contain a remote code execution (RCE) vulnerability via the component mytag_ main.php.
CVE-2022-34496CRITICAL9.8Hiby R3 PRO firmware v1.5 to v1.7 was discovered to contain a file upload vulnerability via the file upload feature.
CVE-2022-22280CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command leading to Unauthenticated SQL Injection vulnerabilit...
CVE-2022-2578CRITICAL9.8A vulnerability, which was classified as critical, has been found in SourceCodester Garage Management System 1.0. This i...
CVE-2022-35643CRITICAL9.1IBM PowerVM VIOS 3.1 could allow a remote attacker to tamper with system configuration or cause a denial of service. IBM...
CVE-2022-1277CRITICAL9.4Inavitas Solar Log product has an unauthenticated SQL Injection vulnerability.
CVE-2022-1799CRITICAL9.8Incorrect signature trust exists within Google Play services SDK play-services-basement. A debug version of Google Play ...
CVE-2022-34558CRITICAL9.8WMAgent v1.3.3rc2 and 1.3.3rc1, reqmgr 2 1.4.1rc5 and 1.4.0rc2, reqmon 1.4.1rc5, and global-workqueue 1.4.1rc5 allows at...
CVE-2022-34555CRITICAL9.8TP-LINK TL-R473G 2.0.1 Build 220529 Rel.65574n was discovered to contain a remote code execution vulnerability which is ...
CVE-2022-2564CRITICAL9.8Prototype Pollution in GitHub repository automattic/mongoose prior to 6.4.6.
CVE-2022-30315CRITICAL9.8Honeywell Experion PKS Safety Manager (SM and FSC) through 2022-05-06 has Insufficient Verification of Data Authenticity...
CVE-2022-27612CRITICAL9.8Buffer copy without checking size of input ('Classic Buffer Overflow') vulnerability in cgi component in Synology Audio ...
CVE-2022-22683CRITICAL9.8Buffer copy without checking size of input ('Classic Buffer Overflow') vulnerability in cgi component in Synology Media ...
CVE-2022-31627CRITICAL9.8In PHP versions 8.1.x below 8.1.8, when fileinfo functions, such as finfo_buffer, due to incorrect patch applied to the ...
CVE-2022-36986CRITICAL9.8An issue was discovered in Veritas NetBackup 8.1.x through 8.1.2, 8.2, 8.3.x through 8.3.0.2, 9.x through 9.0.0.1, and 9...
CVE-2022-2010CRITICAL9.3Out of bounds read in compositing in Google Chrome prior to 102.0.5005.115 allowed a remote attacker who had compromised...
CVE-2022-1853CRITICAL9.6Use after free in Indexed DB in Google Chrome prior to 102.0.5005.61 allowed a remote attacker to potentially perform a ...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now