2022 CVE Vulnerabilities

27,525 CVEs published in 2022.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2022-2486CRITICAL9.8A vulnerability, which was classified as critical, was found in WAVLINK WN535K2 and WN535K3. This affects an unknown par...
CVE-2022-32456CRITICAL9.8Digiwin BPM’s function has insufficient validation for user input. An unauthenticated remote attacker can inject arbitra...
CVE-2022-21543CRITICAL9.8Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Mgmt...
CVE-2022-34023CRITICAL9.8Barangay Management System v1.0 was discovered to contain a SQL injection vulnerability via the hidden_id parameter at /...
CVE-2022-35912CRITICAL9.8In grails-databinding in Grails before 3.3.15, 4.x before 4.1.1, 5.x before 5.1.9, and 5.2.x before 5.2.1 (at least when...
CVE-2022-35405CRITICAL9.8Zoho ManageEngine Password Manager Pro before 12101 and PAM360 before 5510 are vulnerable to unauthenticated remote code...
CVE-2022-24082CRITICAL9.8If an on-premise installation of the Pega Platform is configured with the port for the JMX interface exposed to the Inte...
CVE-2022-2467CRITICAL9.8A vulnerability has been found in SourceCodester Garage Management System 1.0 and classified as critical. This vulnerabi...
CVE-2022-34635CRITICAL9.8The mstatus.sd field in CVA6 commit d315ddd0f1be27c1b3f27eb0b8daf471a952299a does not update when the mstatus.fs field i...
CVE-2022-34632CRITICAL9.1Rocket-Chip commit 4f8114374d8824dfdec03f576a8cd68bebce4e56 was discovered to contain insufficient cryptography via the ...
CVE-2022-34029CRITICAL9.1Nginx NJS v0.7.4 was discovered to contain an out-of-bounds read via njs_scope_value at njs_scope.h.
CVE-2022-2437CRITICAL9.8The Feed Them Social – for Twitter feed, Youtube and more plugin for WordPress is vulnerable to deserialization of untru...
CVE-2022-35741CRITICAL9.8Apache CloudStack version 4.5.0 and later has a SAML 2.0 authentication Service Provider plugin which is found to be vul...
CVE-2022-30623CRITICAL9.8The server checks the user's cookie in a non-standard way, and a value is entered in the cookie value name of the status...
CVE-2022-27434CRITICAL9.8UNIT4 TETA Mobile Edition (ME) before 29.5.HF17 was discovered to contain a SQL injection vulnerability via the ProfileN...
CVE-2022-32985CRITICAL9.8libnx_apl.so on Nexans FTTO GigaSwitch before 6.02N and 7.x before 7.02 implements a Backdoor Account for SSH logins on ...
CVE-2022-31211CRITICAL9.8An issue was discovered in Infiray IRAY-A8Z3 1.0.957. There is a blank root password for TELNET by default.
CVE-2022-31210CRITICAL9.8An issue was discovered in Infiray IRAY-A8Z3 1.0.957. The binary file /usr/local/sbin/webproject/set_param.cgi contains ...
CVE-2022-31209CRITICAL9.8An issue was discovered in Infiray IRAY-A8Z3 1.0.957. The firmware contains a potential buffer overflow by calling strcp...
CVE-2022-26479CRITICAL9.8An issue was discovered in Poly EagleEye Director II before 2.2.2.1. Existence of a certain file (which can be created v...
CVE-2022-26352CRITICAL9.8An issue was discovered in the ContentResource API in dotCMS 3.0 through 22.02. Attackers can craft a multipart form req...
CVE-2022-35890CRITICAL9.8An issue was discovered in Inductive Automation Ignition before 7.9.20 and 8.x before 8.1.17. Designer and Vision Client...
CVE-2022-31161CRITICAL9.8Roxy-WI is a Web interface for managing HAProxy, Nginx and Keepalived servers. Prior to version 6.1.1.0, the system comm...
CVE-2022-35409CRITICAL9.1An issue was discovered in Mbed TLS before 2.28.1 and 3.x before 3.2.0. In some configurations, an unauthenticated attac...
CVE-2022-32417CRITICAL9.8PbootCMS v3.1.2 was discovered to contain a remote code execution (RCE) vulnerability via the function parserIfLabel at ...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now