2022 CVE Vulnerabilities
27,553 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-0941 | MEDIUM | 5.4 | 0.6% | Mar 14, 2022 | Stored XSS due to Unrestricted File Upload in GitHub repository star7th/showdoc prior to v2.10.4. |
| CVE-2022-23943 | CRITICAL | 9.8 | 50.4% | Mar 14, 2022 | Out-of-bounds Write vulnerability in mod_sed of Apache HTTP Server allows an attacker to overwrite heap memory with poss... |
| CVE-2022-22721 | CRITICAL | 9.1 | 41.9% | Mar 14, 2022 | If LimitXMLRequestBody is set to allow request bodies larger than 350MB (defaults to 1M) on 32 bit systems an integer ov... |
| CVE-2022-22720 | CRITICAL | 9.8 | 28.2% | Mar 14, 2022 | Apache HTTP Server 2.4.52 and earlier fails to close inbound connection when errors are encountered discarding the reque... |
| CVE-2022-22719 | HIGH | 7.5 | 69.8% | Mar 14, 2022 | A carefully crafted request body can cause a read to a random memory area which could cause the process to crash. This i... |
| CVE-2022-0940 | MEDIUM | 5.4 | 0.5% | Mar 14, 2022 | Stored XSS due to Unrestricted File Upload in GitHub repository star7th/showdoc prior to v2.10.4. |
| CVE-2022-0938 | MEDIUM | 5.4 | 0.6% | Mar 14, 2022 | Stored XSS via file upload in GitHub repository star7th/showdoc prior to v2.10.4. |
| CVE-2022-0341 | MEDIUM | 5.4 | 0.5% | Mar 14, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository vanessa219/vditor prior to 3.8.12. |
| CVE-2022-0937 | MEDIUM | 5.4 | 0.5% | Mar 14, 2022 | Stored xss in showdoc through file upload in GitHub repository star7th/showdoc prior to 2.10.4. |
| CVE-2022-26981 | HIGH | 7.8 | 1.5% | Mar 13, 2022 | Liblouis through 3.21.0 has a buffer overflow in compilePassOpcode in compileTranslationTable.c (called, indirectly, by ... |
| CVE-2022-24696 | HIGH | 7.8 | 0.2% | Mar 13, 2022 | Mirametrix Glance before 5.1.1.42207 (released on 2018-08-30) allows a local attacker to elevate privileges. NOTE: this ... |
| CVE-2022-24128 | HIGH | 8 | 0.9% | Mar 13, 2022 | Timescale TimescaleDB 1.x and 2.x before 2.5.2 may allow privilege escalation during extension installation. The install... |
| CVE-2022-23960 | MEDIUM | 5.6 | 0.5% | Mar 13, 2022 | Certain Arm Cortex and Neoverse processors through 2022-03-08 do not properly restrict cache speculation, aka Spectre-BH... |
| CVE-2022-26967 | HIGH | 7.8 | 0.9% | Mar 12, 2022 | GPAC 2.0 allows a heap-based buffer overflow in gf_base64_encode. It can be triggered via MP4Box. |
| CVE-2022-26966 | MEDIUM | 5.5 | 0.3% | Mar 12, 2022 | An issue was discovered in the Linux kernel before 5.16.12. drivers/net/usb/sr9700.c allows attackers to obtain sensitiv... |
| CVE-2022-0930 | MEDIUM | 4.8 | 0.9% | Mar 12, 2022 | File upload filter bypass leading to stored XSS in GitHub repository microweber/microweber prior to 1.2.12. |
| CVE-2022-0929 | MEDIUM | 6.1 | 1.1% | Mar 12, 2022 | XSS on dynamic_text module in GitHub repository microweber/microweber prior to 1.2.11. |
| CVE-2022-0926 | MEDIUM | 4.8 | 0.8% | Mar 12, 2022 | File upload filter bypass leading to stored XSS in GitHub repository microweber/microweber prior to 1.2.12. |
| CVE-2022-0880 | MEDIUM | 5.4 | 0.7% | Mar 12, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository star7th/showdoc prior to 2.10.2. |
| CVE-2022-26533 | MEDIUM | 6.1 | 0.7% | Mar 12, 2022 | Alist v2.1.0 and below was discovered to contain a cross-site scripting (XSS) vulnerability via /i/:data/ipa.plist. |
| CVE-2022-26276 | MEDIUM | 5.3 | 1.1% | Mar 12, 2022 | An issue in index.php of OneNav v0.9.14 allows attackers to perform directory traversal. |
| CVE-2022-24760 | CRITICAL | 10 | 49.1% | Mar 12, 2022 | Parse Server is an open source http web server backend. In versions prior to 4.10.7 there is a Remote Code Execution (RC... |
| CVE-2022-24421 | HIGH | 7.8 | 0.3% | Mar 11, 2022 | Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially expl... |
| CVE-2022-24420 | HIGH | 7.8 | 0.3% | Mar 11, 2022 | Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially expl... |
| CVE-2022-24419 | HIGH | 7.8 | 0.3% | Mar 11, 2022 | Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially expl... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now