2022 CVE Vulnerabilities

27,554 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-25375MEDIUM5.5An issue was discovered in drivers/usb/gadget/function/rndis.c in the Linux kernel before 5.16.10. The RNDIS USB gadget ...
CVE-2022-25372HIGH7.8Pritunl Client through 1.2.3019.52 on Windows allows local privilege escalation, related to an ACL entry for CREATOR OWN...
CVE-2022-23848CRITICAL9.8In Alluxio before 2.7.3, the logserver does not validate the input stream. NOTE: this is not the same as the CVE-2021-44...
CVE-2022-23054MEDIUM6.1Openmct versions 1.3.0 to 1.7.7 are vulnerable against stored XSS via the “Summary Widget” element, that allows the inje...
CVE-2022-23053MEDIUM6.1Openmct versions 1.3.0 to 1.7.7 are vulnerable against stored XSS via the “Condition Widget” element, that allows the in...
CVE-2022-22126MEDIUM6.1Openmct versions 1.3.0 to 1.7.7 are vulnerable against stored XSS via the “Web Page” element, that allows the injection ...
CVE-2022-0688MEDIUM4.9Business Logic Errors in Packagist microweber/microweber prior to 1.2.11.
CVE-2022-0686CRITICAL9.1Authorization Bypass Through User-Controlled Key in NPM url-parse prior to 1.5.8.
CVE-2022-0685HIGH7.8Use of Out-of-range Pointer Offset in GitHub repository vim/vim prior to 8.2.4418.
CVE-2022-0690MEDIUM6.1Cross-site Scripting (XSS) - Reflected in Packagist microweber/microweber prior to 1.2.11.
CVE-2022-23376MEDIUM6.1WikiDocs version 0.1.18 has multiple reflected XSS vulnerabilities on different pages.
CVE-2022-23375HIGH8.8WikiDocs version 0.1.18 has an authenticated remote code execution vulnerability. An attacker can upload a malicious fil...
CVE-2022-0689MEDIUM5.3Use multiple time the one-time coupon in Packagist microweber/microweber prior to 1.2.11.
CVE-2022-0632MEDIUM5.5NULL Pointer Dereference in Homebrew mruby prior to 3.2.
CVE-2022-0630HIGH7.1Out-of-bounds Read in Homebrew mruby prior to 3.2.
CVE-2022-0678MEDIUM6.1Cross-site Scripting (XSS) - Reflected in Packagist microweber/microweber prior to 1.2.11.
CVE-2022-0409HIGH7.8Unrestricted Upload of File with Dangerous Type in Packagist showdoc/showdoc prior to 2.10.2.
CVE-2022-24980HIGH7.5An issue was discovered in the Kitodo.Presentation (aka dif) extension before 2.3.2, 3.x before 3.2.3, and 3.3.x before ...
CVE-2022-24979MEDIUM5.3An issue was discovered in the Varnishcache extension before 2.0.1 for TYPO3. The Edge Site Includes (ESI) content eleme...
CVE-2022-25366HIGH7.8Cryptomator through 1.6.5 allows DYLIB injection because, although it has the flag 0x1000 for Hardened Runtime, it has t...
CVE-2022-25365HIGH7.8Docker Desktop before 4.5.1 on Windows allows attackers to move arbitrary files. NOTE: this issue exists because of an i...
CVE-2022-25256MEDIUM6.1SAS Web Report Studio 4.4 allows XSS. /SASWebReportStudio/logonAndRender.do has two parameters: saspfs_request_backlabel...
CVE-2022-25137CRITICAL9.8A command injection vulnerability in the function recvSlaveUpgstatus of TOTOLINK Technology routers T6 V3_Firmware T6_V3...
CVE-2022-25136CRITICAL9.8A command injection vulnerability in the function meshSlaveUpdate of TOTOLINK Technology routers T6 V3_Firmware T6_V3_V4...
CVE-2022-25135CRITICAL9.8A command injection vulnerability in the function recv_mesh_info_sync of TOTOLINK Technology router T6 V3_Firmware T6_V3...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now