2022 CVE Vulnerabilities

27,553 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-25069CRITICAL9.6Mark Text v0.16.3 was discovered to contain a DOM-based cross-site scripting (XSS) vulnerability which allows attackers ...
CVE-2022-25312CRITICAL9.1An XML external entity (XXE) injection vulnerability was discovered in the Any23 RDFa XSLTStylesheet extractor and is kn...
CVE-2022-25106MEDIUM5.5D-Link DIR-859 v1.05 was discovered to contain a stack-based buffer overflow via the function genacgi_main. This vulnera...
CVE-2022-23915HIGH8.8The package weblate from 0 and before 4.11.1 are vulnerable to Remote Code Execution (RCE) via argument injection when u...
CVE-2022-26484MEDIUM4.9An issue was discovered in Veritas InfoScale Operations Manager (VIOM) before 7.4.2 Patch 600 and 8.x before 8.0.0 Patch...
CVE-2022-26483MEDIUM4.8An issue was discovered in Veritas InfoScale Operations Manager (VIOM) before 7.4.2 Patch 600 and 8.x before 8.0.0 Patch...
CVE-2022-0855MEDIUM6.1Improper Resolution of Path Equivalence in GitHub repository microweber-dev/whmcs_plugin prior to 0.0.4.
CVE-2022-26318CRITICAL9.8On WatchGuard Firebox and XTM appliances, an unauthenticated user can execute arbitrary code, aka FBX-22786. This vulner...
CVE-2022-23233HIGH7.5StorageGRID (formerly StorageGRID Webscale) versions prior to 11.6.0 are susceptible to a vulnerability which when succe...
CVE-2022-23232MEDIUM4.9StorageGRID (formerly StorageGRID Webscale) versions prior to 11.6.0 are susceptible to a vulnerability which when succe...
CVE-2022-25623HIGH7.8The Symantec Management Agent is susceptible to a privilege escalation vulnerability. A low privilege local account can ...
CVE-2022-24727Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2022-23915. Reason: This candidate is a reservation d...
CVE-2022-21828HIGH7.2A user with high privilege access to the Incapptic Connect web console can remotely execute code on the Incapptic Connec...
CVE-2022-26336MEDIUM5.5A shortcoming in the HMEF package of poi-scratchpad (Apache POI) allows an attacker to cause an Out of Memory exception....
CVE-2022-23729HIGH7.8When the device is in factory state, it can be access the shell without adb authentication process. The LG ID is LVE-SMP...
CVE-2022-22946MEDIUM5.5In spring cloud gateway versions prior to 3.1.1+ , applications that are configured to enable HTTP2 and no key store or ...
CVE-2022-23397MEDIUM6.1The Cedar Gate EZ-NET portal 6.5.5 6.8.0 Internet portal has a call to display messages to users which does not properly...
CVE-2022-0839CRITICAL9.8Improper Restriction of XML External Entity Reference in GitHub repository liquibase/liquibase prior to 4.8.0.
CVE-2022-26201CRITICAL9.8Victor CMS v1.0 was discovered to contain a SQL injection vulnerability.
CVE-2022-0832MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.3.3.
CVE-2022-0831MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.3.3.
CVE-2022-23328HIGH7.5A design flaw in all versions of Go-Ethereum allows an attacker node to send 5120 pending transactions of a high gas pri...
CVE-2022-23327HIGH7.5A design flaw in Go-Ethereum 1.10.12 and older versions allows an attacker node to send 5120 future transactions with a ...
CVE-2022-0752MEDIUM6.1Cross-site Scripting (XSS) - Generic in GitHub repository hestiacp/hestiacp prior to 1.5.9.
CVE-2022-0848CRITICAL9.8OS Command Injection in GitHub repository part-db/part-db prior to 0.5.11.

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now