2022 CVE Vulnerabilities

27,553 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-0941MEDIUM5.4Stored XSS due to Unrestricted File Upload in GitHub repository star7th/showdoc prior to v2.10.4.
CVE-2022-23943CRITICAL9.8Out-of-bounds Write vulnerability in mod_sed of Apache HTTP Server allows an attacker to overwrite heap memory with poss...
CVE-2022-22721CRITICAL9.1If LimitXMLRequestBody is set to allow request bodies larger than 350MB (defaults to 1M) on 32 bit systems an integer ov...
CVE-2022-22720CRITICAL9.8Apache HTTP Server 2.4.52 and earlier fails to close inbound connection when errors are encountered discarding the reque...
CVE-2022-22719HIGH7.5A carefully crafted request body can cause a read to a random memory area which could cause the process to crash. This i...
CVE-2022-0940MEDIUM5.4Stored XSS due to Unrestricted File Upload in GitHub repository star7th/showdoc prior to v2.10.4.
CVE-2022-0938MEDIUM5.4Stored XSS via file upload in GitHub repository star7th/showdoc prior to v2.10.4.
CVE-2022-0341MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository vanessa219/vditor prior to 3.8.12.
CVE-2022-0937MEDIUM5.4Stored xss in showdoc through file upload in GitHub repository star7th/showdoc prior to 2.10.4.
CVE-2022-26981HIGH7.8Liblouis through 3.21.0 has a buffer overflow in compilePassOpcode in compileTranslationTable.c (called, indirectly, by ...
CVE-2022-24696HIGH7.8Mirametrix Glance before 5.1.1.42207 (released on 2018-08-30) allows a local attacker to elevate privileges. NOTE: this ...
CVE-2022-24128HIGH8Timescale TimescaleDB 1.x and 2.x before 2.5.2 may allow privilege escalation during extension installation. The install...
CVE-2022-23960MEDIUM5.6Certain Arm Cortex and Neoverse processors through 2022-03-08 do not properly restrict cache speculation, aka Spectre-BH...
CVE-2022-26967HIGH7.8GPAC 2.0 allows a heap-based buffer overflow in gf_base64_encode. It can be triggered via MP4Box.
CVE-2022-26966MEDIUM5.5An issue was discovered in the Linux kernel before 5.16.12. drivers/net/usb/sr9700.c allows attackers to obtain sensitiv...
CVE-2022-0930MEDIUM4.8File upload filter bypass leading to stored XSS in GitHub repository microweber/microweber prior to 1.2.12.
CVE-2022-0929MEDIUM6.1XSS on dynamic_text module in GitHub repository microweber/microweber prior to 1.2.11.
CVE-2022-0926MEDIUM4.8File upload filter bypass leading to stored XSS in GitHub repository microweber/microweber prior to 1.2.12.
CVE-2022-0880MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository star7th/showdoc prior to 2.10.2.
CVE-2022-26533MEDIUM6.1Alist v2.1.0 and below was discovered to contain a cross-site scripting (XSS) vulnerability via /i/:data/ipa.plist.
CVE-2022-26276MEDIUM5.3An issue in index.php of OneNav v0.9.14 allows attackers to perform directory traversal.
CVE-2022-24760CRITICAL10Parse Server is an open source http web server backend. In versions prior to 4.10.7 there is a Remote Code Execution (RC...
CVE-2022-24421HIGH7.8Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially expl...
CVE-2022-24420HIGH7.8Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially expl...
CVE-2022-24419HIGH7.8Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially expl...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now