2022 CVE Vulnerabilities

27,554 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-25321MEDIUM6.1An issue was discovered in Cerebrate through 1.4. XSS could occur in the bookmarks component.
CVE-2022-25320MEDIUM5.3An issue was discovered in Cerebrate through 1.4. Username enumeration could occur.
CVE-2022-25319MEDIUM5.3An issue was discovered in Cerebrate through 1.4. Endpoints could be open even when not enabled.
CVE-2022-25318MEDIUM4.3An issue was discovered in Cerebrate through 1.4. An incorrect sharing group ACL allowed an unprivileged user to edit an...
CVE-2022-25317MEDIUM6.1An issue was discovered in Cerebrate through 1.4. genericForm allows reflected XSS in form descriptions via a user-contr...
CVE-2022-25315CRITICAL9.8In Expat (aka libexpat) before 2.4.5, there is an integer overflow in storeRawNames.
CVE-2022-25314HIGH7.5In Expat (aka libexpat) before 2.4.5, there is an integer overflow in copyString.
CVE-2022-25313MEDIUM6.5In Expat (aka libexpat) before 2.4.5, an attacker can trigger stack exhaustion in build_model via a large nesting depth ...
CVE-2022-22922CRITICAL9.8TP-Link TL-WA850RE Wi-Fi Range Extender before v6_200923 was discovered to use highly predictable and easily detectable ...
CVE-2022-22916CRITICAL9.8O2OA v6.4.7 was discovered to contain a remote code execution (RCE) vulnerability via /x_program_center/jaxrs/invoke.
CVE-2022-23646HIGH7.5Next.js is a React framework. Starting with version 10.0.0 and prior to version 12.1.0, Next.js is vulnerable to User In...
CVE-2022-22914HIGH7.5An incorrect access control issue in the component FileManager of Ovidentia CMS 6.0 allows authenticated attackers to to...
CVE-2022-22912CRITICAL9.8Prototype pollution vulnerability via .parse() in Plist before v3.0.4 allows attackers to cause a Denial of Service (DoS...
CVE-2022-0633MEDIUM6.5The UpdraftPlus WordPress plugin Free before 1.22.3 and Premium before 2.22.3 do not properly validate a user has the re...
CVE-2022-0639MEDIUM5.3Authorization Bypass Through User-Controlled Key in NPM url-parse prior to 1.5.7.
CVE-2022-24683HIGH7.5HashiCorp Nomad and Nomad Enterprise 0.9.2 through 1.0.17, 1.1.11, and 1.2.5 allow operators with read-fs and alloc-exec...
CVE-2022-0638MEDIUM4.3Cross-Site Request Forgery (CSRF) in Packagist microweber/microweber prior to 1.2.11.
CVE-2022-23632HIGH7.5Traefik is an HTTP reverse proxy and load balancer. Prior to version 2.6.1, Traefik skips the router transport layer sec...
CVE-2022-20750HIGH7.5A vulnerability in the checkpoint manager implementation of Cisco Redundancy Configuration Manager (RCM) for Cisco StarO...
CVE-2022-20659MEDIUM6.1A vulnerability in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Netwo...
CVE-2022-20653HIGH7.5A vulnerability in the DNS-based Authentication of Named Entities (DANE) email verification component of Cisco AsyncOS S...
CVE-2022-23319MEDIUM5.5A segmentation fault during PCF file parsing in pcf2bdf versions >=1.05 allows an attacker to trigger a program crash vi...
CVE-2022-23318HIGH7.1A heap-buffer-overflow in pcf2bdf, versions >= 1.05 allows an attacker to trigger unsafe memory access via a specially c...
CVE-2022-22899MEDIUM5.5Core FTP / SFTP Server v2 Build 725 was discovered to allow unauthenticated attackers to cause a Denial of Service (DoS)...
CVE-2022-0629HIGH7.8Stack-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now