2022 CVE Vulnerabilities

27,553 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-0943HIGH7.8Heap-based Buffer Overflow occurs in vim in GitHub repository vim/vim prior to 8.2.4563.
CVE-2022-24742MEDIUM5.5Sylius is an open source eCommerce platform. Prior to versions 1.9.10, 1.10.11, and 1.11.2, any other user can view the ...
CVE-2022-24733MEDIUM6.1Sylius is an open source eCommerce platform. Prior to versions 1.9.10, 1.10.11, and 1.11.2, it is possible for a page co...
CVE-2022-24578HIGH7.8GPAC 1.0.1 is affected by a heap-based buffer overflow in SFS_AddString () at bifs/script_dec.c.
CVE-2022-20001HIGH7.8fish is a command line shell. fish version 3.1.0 through version 3.3.1 is vulnerable to arbitrary code execution. git re...
CVE-2022-26351Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2022-26320. Reason: This candidate is a reservation d...
CVE-2022-26320CRITICAL9.1The Rambus SafeZone Basic Crypto Module before 10.4.0, as used in certain Fujifilm (formerly Fuji Xerox) devices before ...
CVE-2022-21187CRITICAL9.8The package libvcs before 0.11.1 are vulnerable to Command Injection via argument injection. When calling the update_rep...
CVE-2022-22354HIGH7.5IBM Spectrum Protect Plus 10.1.0.0 through 10.1.9.2 and IBM Spectrum Copy Data Management 2.2.0.0 through 2.2.14.3 do no...
CVE-2022-22353MEDIUM6.5IBM Big SQL on IBM Cloud Pak for Data 7.1.0, 7.1.1, 7.2.0, and 7.2.3 could allow an authenticated user with appropriate ...
CVE-2022-22348LOW2.4IBM Spectrum Protect Operations Center 8.1.0.000 through 8.1.13.xxx is vulnerable to reverse tabnabbing where it could a...
CVE-2022-22346HIGH8.8IBM Spectrum Protect Operations Center 8.1.0.000 through 8.1.13.xxx is vulnerable to cross-site request forgery which co...
CVE-2022-22344MEDIUM6.1IBM Spectrum Copy Data Management 2.2.0.0 through 2.2.14.3 is vulnerable to HTTP header injection, caused by improper va...
CVE-2022-0962MEDIUM5.4Stored XSS viva .webma file upload in GitHub repository star7th/showdoc prior to 2.10.4.
CVE-2022-24577HIGH7.8GPAC 1.0.1 is affected by a NULL pointer dereference in gf_utf8_wcslen. (gf_utf8_wcslen is a renamed Unicode utf8_wcslen...
CVE-2022-22735HIGH8.8The Simple Quotation WordPress plugin through 1.3.2 does not have authorisation (and CSRF) checks in various of its AJAX...
CVE-2022-22734MEDIUM6.1The Simple Quotation WordPress plugin through 1.3.2 does not have CSRF check when creating or editing a quote and does n...
CVE-2022-0960MEDIUM5.4Stored XSS viva .properties file upload in GitHub repository star7th/showdoc prior to 2.10.4.
CVE-2022-0703MEDIUM4.8The GD Mylist WordPress plugin through 1.1.1 does not sanitise and escape some of its settings, allowing high privilege ...
CVE-2022-0702MEDIUM4.8The Petfinder Listings WordPress plugin through 1.0.18 does not escape its settings, allowing high privilege users such ...
CVE-2022-0701MEDIUM4.8The SEO 301 Meta WordPress plugin through 1.9.1 does not escape its Request and Destination settings, allowing high priv...
CVE-2022-0700MEDIUM4.8The Simple Tracking WordPress plugin before 1.7 does not sanitise and escape its settings, allowing high privilege users...
CVE-2022-0684MEDIUM4.8The WP Home Page Menu WordPress plugin before 3.1 does not sanitise and escape its settings, allowing high privilege use...
CVE-2022-0674MEDIUM4.8The Kunze Law WordPress plugin before 2.1 does not escape its 'E-Mail Error "From" Address' settings, allowing high priv...
CVE-2022-0659MEDIUM4.8The Sync QCloud COS WordPress plugin before 2.0.1 does not escape some of its settings, allowing high privilege users su...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now