2022 CVE Vulnerabilities
27,554 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-25321 | MEDIUM | 6.1 | 1.1% | Feb 18, 2022 | An issue was discovered in Cerebrate through 1.4. XSS could occur in the bookmarks component. |
| CVE-2022-25320 | MEDIUM | 5.3 | 0.9% | Feb 18, 2022 | An issue was discovered in Cerebrate through 1.4. Username enumeration could occur. |
| CVE-2022-25319 | MEDIUM | 5.3 | 1.3% | Feb 18, 2022 | An issue was discovered in Cerebrate through 1.4. Endpoints could be open even when not enabled. |
| CVE-2022-25318 | MEDIUM | 4.3 | 0.6% | Feb 18, 2022 | An issue was discovered in Cerebrate through 1.4. An incorrect sharing group ACL allowed an unprivileged user to edit an... |
| CVE-2022-25317 | MEDIUM | 6.1 | 0.6% | Feb 18, 2022 | An issue was discovered in Cerebrate through 1.4. genericForm allows reflected XSS in form descriptions via a user-contr... |
| CVE-2022-25315 | CRITICAL | 9.8 | 4.8% | Feb 18, 2022 | In Expat (aka libexpat) before 2.4.5, there is an integer overflow in storeRawNames. |
| CVE-2022-25314 | HIGH | 7.5 | 4.7% | Feb 18, 2022 | In Expat (aka libexpat) before 2.4.5, there is an integer overflow in copyString. |
| CVE-2022-25313 | MEDIUM | 6.5 | 3.3% | Feb 18, 2022 | In Expat (aka libexpat) before 2.4.5, an attacker can trigger stack exhaustion in build_model via a large nesting depth ... |
| CVE-2022-22922 | CRITICAL | 9.8 | 1.3% | Feb 18, 2022 | TP-Link TL-WA850RE Wi-Fi Range Extender before v6_200923 was discovered to use highly predictable and easily detectable ... |
| CVE-2022-22916 | CRITICAL | 9.8 | 39.9% | Feb 17, 2022 | O2OA v6.4.7 was discovered to contain a remote code execution (RCE) vulnerability via /x_program_center/jaxrs/invoke. |
| CVE-2022-23646 | HIGH | 7.5 | 1.8% | Feb 17, 2022 | Next.js is a React framework. Starting with version 10.0.0 and prior to version 12.1.0, Next.js is vulnerable to User In... |
| CVE-2022-22914 | HIGH | 7.5 | 1.4% | Feb 17, 2022 | An incorrect access control issue in the component FileManager of Ovidentia CMS 6.0 allows authenticated attackers to to... |
| CVE-2022-22912 | CRITICAL | 9.8 | 2.4% | Feb 17, 2022 | Prototype pollution vulnerability via .parse() in Plist before v3.0.4 allows attackers to cause a Denial of Service (DoS... |
| CVE-2022-0633 | MEDIUM | 6.5 | 2.0% | Feb 17, 2022 | The UpdraftPlus WordPress plugin Free before 1.22.3 and Premium before 2.22.3 do not properly validate a user has the re... |
| CVE-2022-0639 | MEDIUM | 5.3 | 1.5% | Feb 17, 2022 | Authorization Bypass Through User-Controlled Key in NPM url-parse prior to 1.5.7. |
| CVE-2022-24683 | HIGH | 7.5 | 1.5% | Feb 17, 2022 | HashiCorp Nomad and Nomad Enterprise 0.9.2 through 1.0.17, 1.1.11, and 1.2.5 allow operators with read-fs and alloc-exec... |
| CVE-2022-0638 | MEDIUM | 4.3 | 0.4% | Feb 17, 2022 | Cross-Site Request Forgery (CSRF) in Packagist microweber/microweber prior to 1.2.11. |
| CVE-2022-23632 | HIGH | 7.5 | 1.7% | Feb 17, 2022 | Traefik is an HTTP reverse proxy and load balancer. Prior to version 2.6.1, Traefik skips the router transport layer sec... |
| CVE-2022-20750 | HIGH | 7.5 | 1.1% | Feb 17, 2022 | A vulnerability in the checkpoint manager implementation of Cisco Redundancy Configuration Manager (RCM) for Cisco StarO... |
| CVE-2022-20659 | MEDIUM | 6.1 | 1.2% | Feb 17, 2022 | A vulnerability in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Netwo... |
| CVE-2022-20653 | HIGH | 7.5 | 1.8% | Feb 17, 2022 | A vulnerability in the DNS-based Authentication of Named Entities (DANE) email verification component of Cisco AsyncOS S... |
| CVE-2022-23319 | MEDIUM | 5.5 | 0.7% | Feb 17, 2022 | A segmentation fault during PCF file parsing in pcf2bdf versions >=1.05 allows an attacker to trigger a program crash vi... |
| CVE-2022-23318 | HIGH | 7.1 | 0.8% | Feb 17, 2022 | A heap-buffer-overflow in pcf2bdf, versions >= 1.05 allows an attacker to trigger unsafe memory access via a specially c... |
| CVE-2022-22899 | MEDIUM | 5.5 | 1.0% | Feb 17, 2022 | Core FTP / SFTP Server v2 Build 725 was discovered to allow unauthenticated attackers to cause a Denial of Service (DoS)... |
| CVE-2022-0629 | HIGH | 7.8 | 1.9% | Feb 17, 2022 | Stack-based Buffer Overflow in GitHub repository vim/vim prior to 8.2. |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now