2022 CVE Vulnerabilities

27,553 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-22303MEDIUM5.5An exposure of sensitive system information to an unauthorized control sphere vulnerability [CWE-497] in FortiManager ve...
CVE-2022-22301HIGH7.8An improper neutralization of special elements used in an OS Command vulnerability [CWE-78] in FortiAP-C console 5.4.0 t...
CVE-2022-0577MEDIUM6.5Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository scrapy/scrapy prior to 2.6.1.
CVE-2022-25051MEDIUM5.5An Off-by-one Error occurs in cmr113_decode of rtl_433 21.12 when decoding a crafted file.
CVE-2022-25050MEDIUM5.5rtl_433 21.12 was discovered to contain a stack overflow in the function somfy_iohc_decode(). This vulnerability allows ...
CVE-2022-25012MEDIUM5.5Argus Surveillance DVR v4.0 employs weak password encryption.
CVE-2022-25010CRITICAL9.1The component /rootfs in RageFile of Stepmania v5.1b2 and below allows attackers access to the entire file system.
CVE-2022-24720CRITICAL9.8image_processing is an image processing wrapper for libvips and ImageMagick/GraphicsMagick. Prior to version 1.12.2, usi...
CVE-2022-24255HIGH8.8Extensis Portfolio v4.0 was discovered to contain hardcoded credentials which allows attackers to gain administrator pri...
CVE-2022-24254HIGH8.8An unrestricted file upload vulnerability in the Backup/Restore Archive component of Extensis Portfolio v4.0 allows remo...
CVE-2022-24253HIGH8.8Extensis Portfolio v4.0 was discovered to contain an authenticated unrestricted file upload vulnerability via the compon...
CVE-2022-24252HIGH8.8An unrestricted file upload vulnerability in the FileTransferServlet component of Extensis Portfolio v4.0 allows remote ...
CVE-2022-24251HIGH8.8Extensis Portfolio v4.0 was discovered to contain an authenticated unrestricted file upload vulnerability via the Catalo...
CVE-2022-24719MEDIUM6.1Fluture-Node is a FP-style HTTP and streaming utils for Node based on Fluture. Using `followRedirects` or `followRedirec...
CVE-2022-24718MEDIUM6.5ssr-pages is an HTML page builder for the purpose of server-side rendering (SSR). In versions prior to 0.1.4, a path tra...
CVE-2022-24717MEDIUM6.1ssr-pages is an HTML page builder for the purpose of server-side rendering (SSR). In versions prior to 0.1.5, a cross si...
CVE-2022-22300HIGH8.8A improper handling of insufficient permissions or privileges in Fortinet FortiAnalyzer version 5.6.0 through 5.6.11, Fo...
CVE-2022-23387HIGH7.5An issue was discovered in taocms 3.0.2. This is a SQL blind injection that can obtain database data through the Comment...
CVE-2022-22321MEDIUM5.5IBM MQ Appliance 9.2 CD and 9.2 LTS local messaging users stored with a password hash that provides insufficient protect...
CVE-2022-23380HIGH8.8There is a SQL injection vulnerability in the background of taocms 3.0.2 in parameter id:action=admin&id=2&ctrl=edit.
CVE-2022-23377HIGH7.5Archeevo below 5.0 is affected by local file inclusion through file=~/web.config to allow an attacker to retrieve local ...
CVE-2022-0777HIGH7.5Weak Password Recovery Mechanism for Forgotten Password in GitHub repository microweber/microweber prior to 1.3.
CVE-2022-0776MEDIUM6.1Cross-site Scripting (XSS) - DOM in GitHub repository hakimel/reveal.js prior to 4.3.0.
CVE-2022-25022MEDIUM5.4A cross-site scripting (XSS) vulnerability in Htmly v2.8.1 allows attackers to excute arbitrary web scripts HTML via a c...
CVE-2022-25020MEDIUM5.4A cross-site scripting (XSS) vulnerability in Pluxml v5.8.7 allows attackers to execute arbitrary web scripts or HTML vi...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now