2022 CVE Vulnerabilities
27,554 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-25375 | MEDIUM | 5.5 | 1.1% | Feb 20, 2022 | An issue was discovered in drivers/usb/gadget/function/rndis.c in the Linux kernel before 5.16.10. The RNDIS USB gadget ... |
| CVE-2022-25372 | HIGH | 7.8 | 0.6% | Feb 20, 2022 | Pritunl Client through 1.2.3019.52 on Windows allows local privilege escalation, related to an ACL entry for CREATOR OWN... |
| CVE-2022-23848 | CRITICAL | 9.8 | 1.2% | Feb 20, 2022 | In Alluxio before 2.7.3, the logserver does not validate the input stream. NOTE: this is not the same as the CVE-2021-44... |
| CVE-2022-23054 | MEDIUM | 6.1 | 0.6% | Feb 20, 2022 | Openmct versions 1.3.0 to 1.7.7 are vulnerable against stored XSS via the “Summary Widget” element, that allows the inje... |
| CVE-2022-23053 | MEDIUM | 6.1 | 0.6% | Feb 20, 2022 | Openmct versions 1.3.0 to 1.7.7 are vulnerable against stored XSS via the “Condition Widget” element, that allows the in... |
| CVE-2022-22126 | MEDIUM | 6.1 | 0.6% | Feb 20, 2022 | Openmct versions 1.3.0 to 1.7.7 are vulnerable against stored XSS via the “Web Page” element, that allows the injection ... |
| CVE-2022-0688 | MEDIUM | 4.9 | 0.9% | Feb 20, 2022 | Business Logic Errors in Packagist microweber/microweber prior to 1.2.11. |
| CVE-2022-0686 | CRITICAL | 9.1 | 1.8% | Feb 20, 2022 | Authorization Bypass Through User-Controlled Key in NPM url-parse prior to 1.5.8. |
| CVE-2022-0685 | HIGH | 7.8 | 1.8% | Feb 20, 2022 | Use of Out-of-range Pointer Offset in GitHub repository vim/vim prior to 8.2.4418. |
| CVE-2022-0690 | MEDIUM | 6.1 | 1.1% | Feb 19, 2022 | Cross-site Scripting (XSS) - Reflected in Packagist microweber/microweber prior to 1.2.11. |
| CVE-2022-23376 | MEDIUM | 6.1 | 0.8% | Feb 19, 2022 | WikiDocs version 0.1.18 has multiple reflected XSS vulnerabilities on different pages. |
| CVE-2022-23375 | HIGH | 8.8 | 19.9% | Feb 19, 2022 | WikiDocs version 0.1.18 has an authenticated remote code execution vulnerability. An attacker can upload a malicious fil... |
| CVE-2022-0689 | MEDIUM | 5.3 | 1.0% | Feb 19, 2022 | Use multiple time the one-time coupon in Packagist microweber/microweber prior to 1.2.11. |
| CVE-2022-0632 | MEDIUM | 5.5 | 0.8% | Feb 19, 2022 | NULL Pointer Dereference in Homebrew mruby prior to 3.2. |
| CVE-2022-0630 | HIGH | 7.1 | 1.0% | Feb 19, 2022 | Out-of-bounds Read in Homebrew mruby prior to 3.2. |
| CVE-2022-0678 | MEDIUM | 6.1 | 2.3% | Feb 19, 2022 | Cross-site Scripting (XSS) - Reflected in Packagist microweber/microweber prior to 1.2.11. |
| CVE-2022-0409 | HIGH | 7.8 | 0.9% | Feb 19, 2022 | Unrestricted Upload of File with Dangerous Type in Packagist showdoc/showdoc prior to 2.10.2. |
| CVE-2022-24980 | HIGH | 7.5 | 1.2% | Feb 19, 2022 | An issue was discovered in the Kitodo.Presentation (aka dif) extension before 2.3.2, 3.x before 3.2.3, and 3.3.x before ... |
| CVE-2022-24979 | MEDIUM | 5.3 | 0.7% | Feb 19, 2022 | An issue was discovered in the Varnishcache extension before 2.0.1 for TYPO3. The Edge Site Includes (ESI) content eleme... |
| CVE-2022-25366 | HIGH | 7.8 | 0.5% | Feb 19, 2022 | Cryptomator through 1.6.5 allows DYLIB injection because, although it has the flag 0x1000 for Hardened Runtime, it has t... |
| CVE-2022-25365 | HIGH | 7.8 | 0.8% | Feb 19, 2022 | Docker Desktop before 4.5.1 on Windows allows attackers to move arbitrary files. NOTE: this issue exists because of an i... |
| CVE-2022-25256 | MEDIUM | 6.1 | 1.2% | Feb 19, 2022 | SAS Web Report Studio 4.4 allows XSS. /SASWebReportStudio/logonAndRender.do has two parameters: saspfs_request_backlabel... |
| CVE-2022-25137 | CRITICAL | 9.8 | 2.2% | Feb 19, 2022 | A command injection vulnerability in the function recvSlaveUpgstatus of TOTOLINK Technology routers T6 V3_Firmware T6_V3... |
| CVE-2022-25136 | CRITICAL | 9.8 | 2.2% | Feb 19, 2022 | A command injection vulnerability in the function meshSlaveUpdate of TOTOLINK Technology routers T6 V3_Firmware T6_V3_V4... |
| CVE-2022-25135 | CRITICAL | 9.8 | 3.0% | Feb 19, 2022 | A command injection vulnerability in the function recv_mesh_info_sync of TOTOLINK Technology router T6 V3_Firmware T6_V3... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now