2022 CVE Vulnerabilities

27,553 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-22368HIGH7.5IBM Spectrum Scale 5.1.0 through 5.1.3.0 uses weaker than expected cryptographic algorithms that could allow an attacker...
CVE-2022-1331MEDIUM5.5In four instances DMARS (All versions prior to v2.1.10.24) does not properly restrict references of XML external entitie...
CVE-2022-29001HIGH7.2In SpringBootMovie <=1.2, the uploaded file suffix parameter is not filtered, resulting in arbitrary file upload vulnera...
CVE-2022-28599MEDIUM5.4A stored cross-site scripting (XSS) vulnerability exists in FUEL-CMS 1.5.1 that allows an authenticated user to upload a...
CVE-2022-28588MEDIUM5.4In SpringBootMovie <=1.2 when adding movie names, malicious code can be stored because there are no filtering parameters...
CVE-2022-28585CRITICAL9.8EmpireCMS 7.5 has a SQL injection vulnerability in AdClass.php
CVE-2022-28505HIGH7.2Jfinal_cms 5.1.0 is vulnerable to SQL Injection via com.jflyfox.system.log.LogController.java.
CVE-2022-27962CRITICAL9.8Bluecms 1.6 has a SQL injection vulnerability at cooike.
CVE-2022-28561CRITICAL9.8There is a stack overflow vulnerability in the /goform/setMacFilterCfg function in the httpd service of Tenda ax12 22.03...
CVE-2022-28560CRITICAL9.8There is a stack overflow vulnerability in the goform/fast_setting_wifi_set function in the httpd service of Tenda ac9 1...
CVE-2022-23400HIGH7.1A stack-based buffer overflow vulnerability exists in the IGXMPXMLParser::parseDelimiter functionality of Accusoft Image...
CVE-2022-22137MEDIUM6.5A memory corruption vulnerability exists in the ioca_mys_rgb_allocate functionality of Accusoft ImageGear 19.10. A speci...
CVE-2022-1473HIGH7.5The OPENSSL_LH_flush() function, which empties a hash table, contains a bug that breaks reuse of the memory occuppied by...
CVE-2022-1434MEDIUM5.9The OpenSSL 3.0 implementation of the RC4-MD5 ciphersuite incorrectly uses the AAD data as the MAC key. This makes the M...
CVE-2022-1343MEDIUM5.3The function `OCSP_basic_verify` verifies the signer certificate on an OCSP response. In the case where the (non-default...
CVE-2022-1292HIGH7.3The c_rehash script does not properly sanitise shell metacharacters to prevent command injection. This script is distrib...
CVE-2022-0882MEDIUM5.5A bug exists where an attacker can read the kernel log through exposed Zircon kernel addresses without the required capa...
CVE-2022-28590HIGH7.2A Remote Code Execution (RCE) vulnerability exists in Pixelimity 1.0 via admin/admin-ajax.php?action=install_theme.
CVE-2022-28589MEDIUM4.8A stored cross-site scripting (XSS) vulnerability in Pixelimity 1.0 allows attackers to execute arbitrary web scripts or...
CVE-2022-0916HIGH8.8An issue was discovered in Logitech Options. The OAuth 2.0 state parameter was not properly validated. This leaves appli...
CVE-2022-23063HIGH8.8In Shopizer versions 2.3.0 to 3.0.1 are vulnerable to Insufficient Session Expiration. When a password has been changed ...
CVE-2022-1554HIGH7.5Path Traversal due to `send_file` call in GitHub repository clinical-genomics/scout prior to 4.52.
CVE-2022-21949HIGH8.8A Improper Restriction of XML External Entity Reference vulnerability in SUSE Open Build Service allows remote attackers...
CVE-2022-1214Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. Reason: This CVE has been rejected as it was incorrectly assigned. Al...
CVE-2022-20767HIGH7.5A vulnerability in the Snort rule evaluation function of Cisco Firepower Threat Defense (FTD) Software could allow an un...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now