2022 CVE Vulnerabilities
27,553 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-25969 | HIGH | 7.8 | 0.8% | Mar 17, 2022 | The installer of WPS Office Version 10.8.0.6186 insecurely load VERSION.DLL (or some other DLLs), allowing an attacker t... |
| CVE-2022-25949 | HIGH | 7.8 | 0.7% | Mar 17, 2022 | The kernel mode driver kwatch3 of KINGSOFT Internet Security 9 Plus Version 2010.06.23.247 fails to properly handle craf... |
| CVE-2022-26503 | HIGH | 7.8 | 0.7% | Mar 17, 2022 | Deserialization of untrusted data in Veeam Agent for Windows 2.0, 2.1, 2.2, 3.0.2, 4.x, and 5.x allows local users to ru... |
| CVE-2022-25364 | HIGH | 8.1 | 1.0% | Mar 17, 2022 | In Gradle Enterprise before 2021.4.2, the default built-in build cache configuration allowed anonymous write access. If ... |
| CVE-2022-24759 | HIGH | 7.4 | 0.5% | Mar 17, 2022 | `@chainsafe/libp2p-noise` contains TypeScript implementation of noise protocol, an encryption protocol used in libp2p. `... |
| CVE-2022-26526 | HIGH | 7.8 | 0.3% | Mar 17, 2022 | Anaconda Anaconda3 (Anaconda Distribution) through 2021.11.0.0 and Miniconda3 through 4.11.0.0 can create a world-writab... |
| CVE-2022-24761 | HIGH | 7.5 | 1.8% | Mar 17, 2022 | Waitress is a Web Server Gateway Interface server for Python 2 and 3. When using Waitress versions 2.1.0 and prior behin... |
| CVE-2022-25760 | CRITICAL | 9.8 | 1.6% | Mar 17, 2022 | All versions of package accesslog are vulnerable to Arbitrary Code Injection due to the usage of the Function constructo... |
| CVE-2022-25354 | CRITICAL | 9.8 | 1.9% | Mar 17, 2022 | The package set-in before 2.0.3 are vulnerable to Prototype Pollution via the setIn method, as it allows an attacker to ... |
| CVE-2022-25352 | CRITICAL | 9.8 | 2.0% | Mar 17, 2022 | The package libnested before 1.5.2 are vulnerable to Prototype Pollution via the set function in index.js. **Note:** Thi... |
| CVE-2022-25296 | HIGH | 7.3 | 1.0% | Mar 17, 2022 | The package bodymen from 0.0.0 are vulnerable to Prototype Pollution via the handler function which could be tricked int... |
| CVE-2022-21221 | HIGH | 7.5 | 2.5% | Mar 17, 2022 | The package github.com/valyala/fasthttp before 1.34.0 are vulnerable to Directory Traversal via the ServeFile function, ... |
| CVE-2022-0749 | CRITICAL | 9.8 | 1.7% | Mar 17, 2022 | This affects all versions of package SinGooCMS.Utility. The socket client in the package can pass in the payload via the... |
| CVE-2022-0748 | CRITICAL | 9.8 | 2.0% | Mar 17, 2022 | The package post-loader from 0.0.0 are vulnerable to Arbitrary Code Execution which uses a markdown parser in an unsafe ... |
| CVE-2022-1000 | CRITICAL | 9.8 | 1.9% | Mar 17, 2022 | Path Traversal in GitHub repository prasathmani/tinyfilemanager prior to 2.4.7. |
| CVE-2022-24075 | MEDIUM | 6.5 | 0.8% | Mar 17, 2022 | Whale browser before 3.12.129.18 allowed extensions to replace JavaScript files of the HWP viewer website which could ac... |
| CVE-2022-24074 | CRITICAL | 9.8 | 1.0% | Mar 17, 2022 | Whale Bridge, a default extension in Whale browser before 3.12.129.18, allowed to receive any SendMessage request from t... |
| CVE-2022-24073 | HIGH | 7.1 | 0.6% | Mar 17, 2022 | The Web Request API in Whale browser before 3.12.129.18 allowed to deny access to the extension store or redirect to any... |
| CVE-2022-24072 | MEDIUM | 6.1 | 0.6% | Mar 17, 2022 | The devtools API in Whale browser before 3.12.129.18 allowed extension developers to inject arbitrary JavaScript into th... |
| CVE-2022-22273 | CRITICAL | 9.8 | 1.9% | Mar 17, 2022 | Improper neutralization of Special Elements leading to OS Command Injection vulnerability impacting end-of-life Secure R... |
| CVE-2022-25516 | MEDIUM | 6.5 | 0.9% | Mar 17, 2022 | stb_truetype.h v1.26 was discovered to contain a heap-buffer-overflow via the function stbtt__find_table at stb_truetype... |
| CVE-2022-25515 | MEDIUM | 6.5 | 0.9% | Mar 17, 2022 | stb_truetype.h v1.26 was discovered to contain a heap-buffer-overflow via the function ttULONG() at stb_truetype.h. NOTE... |
| CVE-2022-25514 | HIGH | 7.5 | 1.0% | Mar 17, 2022 | stb_truetype.h v1.26 was discovered to contain a heap-buffer-overflow via the function ttUSHORT() at stb_truetype.h. NOT... |
| CVE-2022-26534 | HIGH | 7.5 | 1.0% | Mar 17, 2022 | FISCO-BCOS release-3.0.0-rc2 was discovered to contain an issue where a malicious node, via a malicious viewchange packe... |
| CVE-2022-26300 | HIGH | 7.5 | 1.2% | Mar 17, 2022 | EOS v2.1.0 was discovered to contain a heap-buffer-overflow via the function txn_test_gen_plugin. |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now