2022 CVE Vulnerabilities

27,553 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-0838MEDIUM6.1Cross-site Scripting (XSS) - Reflected in GitHub repository hestiacp/hestiacp prior to 1.5.10.
CVE-2022-0730CRITICAL9.8Under certain ldap conditions, Cacti authentication can be bypassed with certain credential types.
CVE-2022-25220MEDIUM4.8PeteReport Version 0.5 allows an authenticated admin user to inject persistent JavaScript code inside the markdown descr...
CVE-2022-24725MEDIUM5.5Shescape is a shell escape package for JavaScript. An issue in versions 1.4.0 to 1.5.1 allows for exposure of the home d...
CVE-2022-23710MEDIUM6.1A cross-site-scripting (XSS) vulnerability was discovered in the Data Preview Pane (previously known as Index Pattern Pr...
CVE-2022-23709MEDIUM4.3A flaw was discovered in Kibana in which users with Read access to the Uptime feature could modify alerting rules. A use...
CVE-2022-23708MEDIUM4.3A flaw was discovered in Elasticsearch 7.17.0’s upgrade assistant, in which upgrading from version 6.x to 7.x would disa...
CVE-2022-23052MEDIUM6.5PeteReport Version 0.5 contains a Cross Site Request Forgery (CSRF) vulnerability allowing an attacker to trick users in...
CVE-2022-23051MEDIUM5.4PeteReport Version 0.5 allows an authenticated admin user to inject persistent JavaScript code while adding an 'Attack T...
CVE-2022-22947CRITICAL10In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe...
CVE-2022-22943MEDIUM6.7VMware Tools for Windows (11.x.y and 10.x.y prior to 12.0.0) contains an uncontrolled search path vulnerability. A malic...
CVE-2022-0265CRITICAL9.8Improper Restriction of XML External Entity Reference in GitHub repository hazelcast/hazelcast in 5.1-BETA-1.
CVE-2022-24723MEDIUM5.3URI.js is a Javascript URL mutation library. Before version 1.19.9, whitespace characters are not removed from the begin...
CVE-2022-21716HIGH7.5Twisted is an event-based framework for internet applications, supporting Python 3.6+. Prior to 22.2.0, Twisted SSH clie...
CVE-2022-24724CRITICAL9.8cmark-gfm is GitHub's extended version of the C reference implementation of CommonMark. Prior to versions 0.29.0.gfm.3 a...
CVE-2022-25125CRITICAL9.8MCMS v5.2.4 was discovered to contain a SQL injection vulnerability via search.do in the file /mdiy/dict/listExcludeApp.
CVE-2022-23899CRITICAL9.8MCMS v5.2.5 was discovered to contain a SQL injection vulnerability via search.do in the file /web/MCmsAction.java.
CVE-2022-23898CRITICAL9.8MCMS v5.2.5 was discovered to contain a SQL injection vulnerability via the categoryId parameter in the file IContentDao...
CVE-2022-22700MEDIUM5.3CyberArk Identity versions up to and including 22.1 in the 'StartAuthentication' resource, exposes the response header '...
CVE-2022-0492HIGH7.8A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function. Th...
CVE-2022-26129HIGH7.8Buffer overflow vulnerabilities exist in FRRouting through 8.1.0 due to wrong checks on the subtlv length in the functio...
CVE-2022-26128HIGH7.8A buffer overflow vulnerability exists in FRRouting through 8.1.0 due to a wrong check on the input packet length in the...
CVE-2022-26127HIGH7.8A buffer overflow vulnerability exists in FRRouting through 8.1.0 due to missing a check on the input packet length in t...
CVE-2022-26126HIGH7.8Buffer overflow vulnerabilities exist in FRRouting through 8.1.0 due to the use of strdup with a non-zero-terminated bin...
CVE-2022-26125HIGH7.8Buffer overflow vulnerabilities exist in FRRouting through 8.1.0 due to wrong checks on the input packet length in isisd...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now