2022 CVE Vulnerabilities
27,525 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-34060 | CRITICAL | 9.8 | 1.9% | Jun 24, 2022 | The Togglee package in PyPI version v0.0.8 was discovered to contain a code execution backdoor. This vulnerability allow... |
| CVE-2022-34059 | CRITICAL | 9.8 | 1.9% | Jun 24, 2022 | The Sixfab-Tool in PyPI v0.0.2 to v0.0.3 was discovered to contain a code execution backdoor via the request package. Th... |
| CVE-2022-34057 | CRITICAL | 9.8 | 1.3% | Jun 24, 2022 | The Scoptrial package in PyPI version v0.0.5 was discovered to contain a code execution backdoor via the request package... |
| CVE-2022-34056 | CRITICAL | 9.8 | 1.9% | Jun 24, 2022 | The Watertools package in PyPI v0.0.0 was discovered to contain a code execution backdoor via the request package. This ... |
| CVE-2022-34055 | CRITICAL | 9.8 | 1.9% | Jun 24, 2022 | The drxhello package in PyPI v0.0.1 was discovered to contain a code execution backdoor via the request package. This vu... |
| CVE-2022-34054 | CRITICAL | 9.8 | 1.9% | Jun 24, 2022 | The Perdido package in PyPI v0.0.1 to v0.0.2 was discovered to contain a code execution backdoor via the request package... |
| CVE-2022-34053 | CRITICAL | 9.8 | 1.9% | Jun 24, 2022 | The DR-Web-Engine package in PyPI v0.2.0b0 was discovered to contain a code execution backdoor via the request package. ... |
| CVE-2022-33004 | CRITICAL | 9.8 | 1.9% | Jun 24, 2022 | The Beginner package in PyPI v0.0.2 to v0.0.4 was discovered to contain a code execution backdoor via the request packag... |
| CVE-2022-33003 | CRITICAL | 9.8 | 1.9% | Jun 24, 2022 | The watools package in PyPI v0.0.1 to v0.0.8 was discovered to contain a code execution backdoor via the request package... |
| CVE-2022-33002 | CRITICAL | 9.8 | 1.9% | Jun 24, 2022 | The KGExplore package in PyPI v0.1.1 to v0.1.2 was discovered to contain a code execution backdoor via the request packa... |
| CVE-2022-33001 | CRITICAL | 9.8 | 1.9% | Jun 24, 2022 | The AAmiles package in PyPI v0.1.0 was discovered to contain a code execution backdoor via the request package. This vul... |
| CVE-2022-33000 | CRITICAL | 9.8 | 1.9% | Jun 24, 2022 | The ML-Scanner package in PyPI v0.1.0 to v0.1.5 was discovered to contain a code execution backdoor via the request pack... |
| CVE-2022-32999 | CRITICAL | 9.8 | 1.9% | Jun 24, 2022 | The cloudlabeling package in PyPI v0.0.1 was discovered to contain a code execution backdoor via the request package. Th... |
| CVE-2022-32998 | CRITICAL | 9.8 | 1.9% | Jun 24, 2022 | The cryptoasset-data-downloader package in PyPI v1.0.0 to v1.0.1 was discovered to contain a code execution backdoor via... |
| CVE-2022-32997 | CRITICAL | 9.8 | 1.9% | Jun 24, 2022 | The RootInteractive package in PyPI v0.0.5 to v0.0.19b0 was discovered to contain a code execution backdoor via the requ... |
| CVE-2022-32996 | CRITICAL | 9.8 | 1.9% | Jun 24, 2022 | The django-navbar-client package of v0.9.50 to v1.0.1 was discovered to contain a code execution backdoor via the reques... |
| CVE-2022-30885 | CRITICAL | 9.8 | 2.0% | Jun 24, 2022 | The pyesasky for python, as distributed on PyPI, included a code-execution backdoor inserted by a third party. The curre... |
| CVE-2022-21231 | CRITICAL | 9.8 | 1.3% | Jun 24, 2022 | All versions of package deep-get-set are vulnerable to Prototype Pollution via the 'deep' function. **Note:** This vulne... |
| CVE-2022-31767 | CRITICAL | 9.8 | 4.7% | Jun 24, 2022 | IBM CICS TX Standard and Advanced 11.1 could allow a remote attacker to execute arbitrary commands on the system by send... |
| CVE-2022-30117 | CRITICAL | 9.1 | 2.0% | Jun 24, 2022 | Concrete 8.5.7 and below as well as Concrete 9.0 through 9.0.2 allow traversal in /index.php/ccm/system/file/upload whic... |
| CVE-2022-2120 | CRITICAL | 9.8 | 2.8% | Jun 24, 2022 | OFFIS DCMTK's (All versions prior to 3.6.7) service class user (SCU) is vulnerable to relative path traversal, allowing ... |
| CVE-2022-2119 | CRITICAL | 9.8 | 2.8% | Jun 24, 2022 | OFFIS DCMTK's (All versions prior to 3.6.7) service class provider (SCP) is vulnerable to path traversal, allowing an at... |
| CVE-2022-2105 | CRITICAL | 9.1 | 1.0% | Jun 24, 2022 | Client-side JavaScript controls may be bypassed to change user credentials and permissions without authentication, inclu... |
| CVE-2022-2104 | CRITICAL | 9.8 | 1.0% | Jun 24, 2022 | The www-data (Apache web server) account is configured to run sudo with no password for many commands (including /bin/sh... |
| CVE-2022-2103 | CRITICAL | 9.1 | 1.0% | Jun 24, 2022 | An attacker with weak credentials could access the TCP port via an open FTP port, allowing an attacker to read sensitive... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now