2022 CVE Vulnerabilities

27,554 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-24445Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2022-23982HIGH7.5The vulnerability discovered in WordPress Perfect Brands for WooCommerce plugin (versions <= 2.0.4) allows server inform...
CVE-2022-23981MEDIUM4.3The vulnerability allows Subscriber+ level users to create brands in WordPress Perfect Brands for WooCommerce plugin (ve...
CVE-2022-21800MEDIUM6.5MMP: All versions prior to v1.0.3, PTP C-series: Device versions prior to v2.8.6.1, and PTMP C-series and A5x: Device ve...
CVE-2022-21215CRITICAL9.8This vulnerability could allow an attacker to force the server to create and execute a web request granting access to ba...
CVE-2022-21196CRITICAL9.8MMP: All versions prior to v1.0.3, PTP C-series: Device versions prior to v2.8.6.1, and PTMP C-series and A5x: Device ve...
CVE-2022-21176HIGH7.5MMP: All versions prior to v1.0.3, PTP C-series: Device versions prior to v2.8.6.1, and PTMP C-series and A5x: Device ve...
CVE-2022-21143CRITICAL9.8MMP: All versions prior to v1.0.3, PTP C-series: Device versions prior to v2.8.6.1, and PTMP C-series and A5x: Device ve...
CVE-2022-21141CRITICAL9.8MMP: All versions prior to v1.0.3, PTP C-series: Device versions prior to v2.8.6.1, and PTMP C-series and A5x: Device ve...
CVE-2022-0673MEDIUM6.5A flaw was found in LemMinX in versions prior to 0.19.0. Cache poisoning of external schema files due to directory trave...
CVE-2022-0672MEDIUM5.5A flaw was found in LemMinX in versions prior to 0.19.0. Insecure redirect could allow unauthorized access to sensitive ...
CVE-2022-0671CRITICAL9.1A flaw was found in vscode-xml in versions prior to 0.19.0. Schema download could lead to blind SSRF or DoS via a large ...
CVE-2022-0646HIGH7.8A flaw use after free in the Linux kernel Management Component Transport Protocol (MCTP) subsystem was found in the way ...
CVE-2022-0585MEDIUM6.5Large loops in multiple protocol dissectors in Wireshark 3.6.0 to 3.6.1 and 3.4.0 to 3.4.11 allow denial of service via ...
CVE-2022-0138HIGH7.5MMP: All versions prior to v1.0.3, PTP C-series: Device versions prior to v2.8.6.1, and PTMP C-series and A5x: Device ve...
CVE-2022-25323MEDIUM6.1ZEROF Web Server 2.0 allows /admin.back XSS.
CVE-2022-25322CRITICAL9.8ZEROF Web Server 2.0 allows /HandleEvent SQL Injection.
CVE-2022-23647MEDIUM6.1Prism is a syntax highlighting library. Starting with version 1.14.0 and prior to version 1.27.0, Prism's command line p...
CVE-2022-0666HIGH7.5CRLF Injection leads to Stack Trace Exposure due to lack of filtering at https://demo.microweber.org/ in Packagist micro...
CVE-2022-0664CRITICAL9.8Use of Hard-coded Cryptographic Key in Go github.com/gravitl/netmaker prior to 0.8.5,0.9.4,0.10.0,0.10.1.
CVE-2022-0631CRITICAL9.8Heap-based Buffer Overflow in Homebrew mruby prior to 3.2.
CVE-2022-0451MEDIUM6.5Dart SDK contains the HTTPClient in dart:io library whcih includes authorization headers when handling cross origin redi...
CVE-2022-25299HIGH7.5This affects the package cesanta/mongoose before 7.6. The unsafe handling of file names during upload using mg_http_uplo...
CVE-2022-25298HIGH7.5This affects the package sprinfall/webcc before 0.3.0. It is possible to traverse directories to fetch arbitrary files f...
CVE-2022-0660HIGH7.5Generation of Error Message Containing Sensitive Information in Packagist microweber/microweber prior to 1.2.11.

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now