2022 CVE Vulnerabilities

27,525 CVEs published in 2022.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2022-32409CRITICAL9.8A local file inclusion (LFI) vulnerability in the component codemirror.php of Portal do Software Publico Brasileiro i3ge...
CVE-2022-30113CRITICAL9.8Electronic mall system 1.0_build20200203 is affected vulnerable to SQL Injection.
CVE-2022-28375CRITICAL9.8Verizon 5G Home LVSKIHP OutDoorUnit (ODU) 3.33.101.0 does not property sanitize user-controlled parameters within the cr...
CVE-2022-28373CRITICAL9.8Verizon 5G Home LVSKIHP InDoorUnit (IDU) 3.4.66.162 does not properly sanitize user-controlled parameters within the crt...
CVE-2022-28369CRITICAL9.8Verizon 5G Home LVSKIHP InDoorUnit (IDU) 3.4.66.162 does not validate the user-provided URL within the crtcmode function...
CVE-2022-25801CRITICAL9.1Best Practical RT for Incident Response (RTIR) before 4.0.3 and 5.x before 5.0.3 allows SSRF via Scripted Action tools.
CVE-2022-25800CRITICAL9.1Best Practical RT for Incident Response (RTIR) before 4.0.3 and 5.x before 5.0.3 allows SSRF via the whois lookup tool.
CVE-2022-35857CRITICAL9.8kvf-admin through 2022-02-12 allows remote attackers to execute arbitrary code because deserialization is mishandled. Th...
CVE-2022-34756CRITICAL9.8A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could result in remote code execution or...
CVE-2022-20238CRITICAL9.8'remap_pfn_range' here may map out of size kernel memory (for example, may map the kernel area), and because the 'vma->v...
CVE-2022-20229CRITICAL9.8In bta_hf_client_handle_cind_list_item of bta_hf_client_at.cc, there is a possible out of bounds write due to a missing ...
CVE-2022-20222CRITICAL9.8In read_attr_value of gatt_db.cc, there is a possible out of bounds write due to a missing bounds check. This could lead...
CVE-2022-20216CRITICAL9.8android exported is used to set third-party app access permissions, and the default value of intent-filter is true. com....
CVE-2022-28888CRITICAL9.8Spryker Commerce OS 1.4.2 allows Remote Command Execution.
CVE-2022-32073CRITICAL9.8WolfSSH v1.4.7 was discovered to contain an integer overflow via the function wolfSSH_SFTP_RecvRMDIR.
CVE-2022-35628CRITICAL9.8A SQL injection issue was discovered in the lux extension before 17.6.1, and 18.x through 24.x before 24.0.2, for TYPO3.
CVE-2022-31105CRITICAL9.6Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Argo CD starting with version 0.4.0 and prior ...
CVE-2022-29601CRITICAL9.8The seminars (aka Seminar Manager) extension through 4.1.3 for TYPO3 allows SQL Injection.
CVE-2022-29600CRITICAL9.8The oelib (aka One is Enough Library) extension through 4.1.5 for TYPO3 allows SQL Injection.
CVE-2022-22997CRITICAL9.8Addressed a remote code execution vulnerability by resolving a command injection vulnerability and closing an AWS S3 buc...
CVE-2022-2298CRITICAL9.8A vulnerability has been found in SourceCodester Clinics Patient Management System 2.0 and classified as critical. Affec...
CVE-2022-34737CRITICAL9.1The application security module has a vulnerability in permission assignment. Successful exploitation of this vulnerabil...
CVE-2022-34819CRITICAL10A vulnerability has been identified in SIMATIC CP 1242-7 V2 (All versions < V3.3.46), SIMATIC CP 1243-1 (All versions < ...
CVE-2022-26649CRITICAL9.6A vulnerability has been identified in SCALANCE X200-4P IRT (All versions < V5.5.2), SCALANCE X201-3P IRT (All versions ...
CVE-2022-31140CRITICAL9.1Valinor is a PHP library that helps to map any input into a strongly-typed value object structure. Prior to version 0.12...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now