2022 CVE Vulnerabilities

27,553 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-25969HIGH7.8The installer of WPS Office Version 10.8.0.6186 insecurely load VERSION.DLL (or some other DLLs), allowing an attacker t...
CVE-2022-25949HIGH7.8The kernel mode driver kwatch3 of KINGSOFT Internet Security 9 Plus Version 2010.06.23.247 fails to properly handle craf...
CVE-2022-26503HIGH7.8Deserialization of untrusted data in Veeam Agent for Windows 2.0, 2.1, 2.2, 3.0.2, 4.x, and 5.x allows local users to ru...
CVE-2022-25364HIGH8.1In Gradle Enterprise before 2021.4.2, the default built-in build cache configuration allowed anonymous write access. If ...
CVE-2022-24759HIGH7.4`@chainsafe/libp2p-noise` contains TypeScript implementation of noise protocol, an encryption protocol used in libp2p. `...
CVE-2022-26526HIGH7.8Anaconda Anaconda3 (Anaconda Distribution) through 2021.11.0.0 and Miniconda3 through 4.11.0.0 can create a world-writab...
CVE-2022-24761HIGH7.5Waitress is a Web Server Gateway Interface server for Python 2 and 3. When using Waitress versions 2.1.0 and prior behin...
CVE-2022-25760CRITICAL9.8All versions of package accesslog are vulnerable to Arbitrary Code Injection due to the usage of the Function constructo...
CVE-2022-25354CRITICAL9.8The package set-in before 2.0.3 are vulnerable to Prototype Pollution via the setIn method, as it allows an attacker to ...
CVE-2022-25352CRITICAL9.8The package libnested before 1.5.2 are vulnerable to Prototype Pollution via the set function in index.js. **Note:** Thi...
CVE-2022-25296HIGH7.3The package bodymen from 0.0.0 are vulnerable to Prototype Pollution via the handler function which could be tricked int...
CVE-2022-21221HIGH7.5The package github.com/valyala/fasthttp before 1.34.0 are vulnerable to Directory Traversal via the ServeFile function, ...
CVE-2022-0749CRITICAL9.8This affects all versions of package SinGooCMS.Utility. The socket client in the package can pass in the payload via the...
CVE-2022-0748CRITICAL9.8The package post-loader from 0.0.0 are vulnerable to Arbitrary Code Execution which uses a markdown parser in an unsafe ...
CVE-2022-1000CRITICAL9.8Path Traversal in GitHub repository prasathmani/tinyfilemanager prior to 2.4.7.
CVE-2022-24075MEDIUM6.5Whale browser before 3.12.129.18 allowed extensions to replace JavaScript files of the HWP viewer website which could ac...
CVE-2022-24074CRITICAL9.8Whale Bridge, a default extension in Whale browser before 3.12.129.18, allowed to receive any SendMessage request from t...
CVE-2022-24073HIGH7.1The Web Request API in Whale browser before 3.12.129.18 allowed to deny access to the extension store or redirect to any...
CVE-2022-24072MEDIUM6.1The devtools API in Whale browser before 3.12.129.18 allowed extension developers to inject arbitrary JavaScript into th...
CVE-2022-22273CRITICAL9.8Improper neutralization of Special Elements leading to OS Command Injection vulnerability impacting end-of-life Secure R...
CVE-2022-25516MEDIUM6.5stb_truetype.h v1.26 was discovered to contain a heap-buffer-overflow via the function stbtt__find_table at stb_truetype...
CVE-2022-25515MEDIUM6.5stb_truetype.h v1.26 was discovered to contain a heap-buffer-overflow via the function ttULONG() at stb_truetype.h. NOTE...
CVE-2022-25514HIGH7.5stb_truetype.h v1.26 was discovered to contain a heap-buffer-overflow via the function ttUSHORT() at stb_truetype.h. NOT...
CVE-2022-26534HIGH7.5FISCO-BCOS release-3.0.0-rc2 was discovered to contain an issue where a malicious node, via a malicious viewchange packe...
CVE-2022-26300HIGH7.5EOS v2.1.0 was discovered to contain a heap-buffer-overflow via the function txn_test_gen_plugin.

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now