2022 CVE Vulnerabilities

27,553 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-0636MEDIUM5.5A denial of service vulnerability was reported in Lenovo Thin Installer prior to version 1.3.0039 that could trigger a s...
CVE-2022-0354HIGH7.8A vulnerability was reported in Lenovo System Update that could allow a local user with interactive system access the ab...
CVE-2022-0192HIGH7.8A DLL search path vulnerability was reported in Lenovo PCManager prior to version 4.0.40.2175 that could allow privilege...
CVE-2022-27342CRITICAL9.8Link-Admin v0.0.1 was discovered to contain a SQL injection vulnerability via DictRest.ResponseResult().
CVE-2022-27341CRITICAL9.8JFinalCMS v2.0 was discovered to contain a SQL injection vulnerability via the Article Management function.
CVE-2022-27340HIGH8.8MCMS v5.2.7 contains a Cross-Site Request Forgery (CSRF) via /role/saveOrUpdateRole.do. This vulnerability allows attack...
CVE-2022-1440CRITICAL9.8Command Injection vulnerability in git-interface@2.1.1 in GitHub repository yarkeev/git-interface prior to 2.1.2. If bot...
CVE-2022-29589MEDIUM6.1Crypt Server before 3.3.0 allows XSS in the index view. This is related to serial, computername, and username.
CVE-2022-1439MEDIUM6.1Reflected XSS on demo.microweber.org/demo/module/ in GitHub repository microweber/microweber prior to 1.2.15. Execute Ar...
CVE-2022-29583HIGH7.8service_windows.go in the kardianos service package for Go omits quoting that is sometimes needed for execution of a Win...
CVE-2022-29582HIGH7In the Linux kernel before 5.17.3, fs/io_uring.c has a use-after-free due to a race condition in io_uring timeouts. This...
CVE-2022-1437HIGH7.1Heap-based Buffer Overflow in GitHub repository radareorg/radare2 prior to 5.7.0. The bug causes the program reads data ...
CVE-2022-28074MEDIUM4.8Halo-1.5.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via \admin\index.html#/system/too...
CVE-2022-27406HIGH7.5FreeType commit 22a0cccb4d9d002f33c1ba7a4b36812c7d4f46b5 was discovered to contain a segmentation violation via the func...
CVE-2022-27405HIGH7.5FreeType commit 53dfdcd8198d2b3201a23c4bad9190519ba918db was discovered to contain a segmentation violation via the func...
CVE-2022-27404CRITICAL9.8FreeType commit 1e2eb65048f75c64b68708efed6ce904c31f3b2f was discovered to contain a heap buffer overflow via the functi...
CVE-2022-1429HIGH7.5SQL injection in GridHelperService.php in GitHub repository pimcore/pimcore prior to 10.3.6. This vulnerability is capab...
CVE-2022-26674CRITICAL9.8ASUS RT-AX88U has a Format String vulnerability, which allows an unauthenticated remote attacker to write to arbitrary m...
CVE-2022-26673MEDIUM5.4ASUS RT-AX88U has insufficient filtering for special characters in the HTTP header parameter. A remote attacker with gen...
CVE-2022-26672CRITICAL9.8ASUS WebStorage has a hardcoded API Token in the APP source code. An unauthenticated remote attacker can use this token ...
CVE-2022-29577MEDIUM6.1OWASP AntiSamy before 1.6.7 allows XSS via HTML tag smuggling on STYLE content with crafted input. The output serializer...
CVE-2022-28367MEDIUM6.1OWASP AntiSamy before 1.6.6 allows XSS via HTML tag smuggling on STYLE content with crafted input. The output serializer...
CVE-2022-28366HIGH7.5Certain Neko-related HTML parsers allow a denial of service via crafted Processing Instruction (PI) input that causes ex...
CVE-2022-29280Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2022-28366. Reason: This candidate is a reservation d...
CVE-2022-26856HIGH7.8Dell EMC Repository Manager version 3.4.0 contains a plain-text password storage vulnerability. A local attacker could p...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now