2022 CVE Vulnerabilities

27,554 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-0623CRITICAL9.1Out-of-bounds Read in Homebrew mruby prior to 3.2.
CVE-2022-24953MEDIUM5.3The Crypt_GPG extension before 1.6.7 for PHP does not prevent additional options in GPG calls, which presents a risk for...
CVE-2022-22901MEDIUM5.5There is an Assertion in 'context_p->next_scanner_info_p->type == SCANNER_TYPE_FUNCTION' failed at parser_parse_function...
CVE-2022-0622MEDIUM5.3Generation of Error Message Containing Sensitive Information in Packagist snipe/snipe-it prior to 5.3.11.
CVE-2022-25270MEDIUM6.5The Quick Edit module does not properly check entity access in some circumstances. This could result in users with the "...
CVE-2022-25271HIGH7.5Drupal core's form API has a vulnerability where certain contributed or custom modules' forms may be vulnerable to impro...
CVE-2022-24985HIGH8.8Forms generated by JQueryForm.com before 2022-02-05 allows a remote authenticated attacker to bypass authentication and ...
CVE-2022-24984CRITICAL9.8Forms generated by JQueryForm.com before 2022-02-05 (if file-upload capability is enabled) allow remote unauthenticated ...
CVE-2022-24983HIGH7.5Forms generated by JQueryForm.com before 2022-02-05 allow remote attackers to obtain the URI to any uploaded file by cap...
CVE-2022-24982MEDIUM6.5Forms generated by JQueryForm.com before 2022-02-05 allows a remote authenticated attacker to access the cleartext crede...
CVE-2022-24981MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability in forms generated by JQueryForm.com before 2022-02-05 allows remot...
CVE-2022-23636HIGH8.1Wasmtime is an open source runtime for WebAssembly & WASI. Prior to versions 0.34.1 and 0.33.1, there exists a bug in th...
CVE-2022-22885CRITICAL9.8Hutool v5.7.18's HttpRequest was discovered to ignore all TLS/SSL certificate validation.
CVE-2022-22881CRITICAL9.8Jeecg-boot v3.0 was discovered to contain a SQL injection vulnerability via the code parameter in /sys/user/queryUserCom...
CVE-2022-22880CRITICAL9.8Jeecg-boot v3.0 was discovered to contain a SQL injection vulnerability via the code parameter in /jeecg-boot/sys/user/q...
CVE-2022-25265HIGH7.8In the Linux kernel through 5.16.10, certain binary files may have the exec-all attribute if they were built in approxim...
CVE-2022-25258MEDIUM4.6An issue was discovered in drivers/usb/gadget/composite.c in the Linux kernel before 5.16.10. The USB Gadget subsystem l...
CVE-2022-25255HIGH7.8In Qt 5.9.x through 5.15.x before 5.15.9 and 6.x before 6.2.4 on Linux and UNIX, QProcess could execute a binary from th...
CVE-2022-23644HIGH8.8BookWyrm is a decentralized social network for tracking reading habits and reviewing books. The functionality to load a ...
CVE-2022-22853MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in Hospital Patient Record Management System v1.0 allows attackers to ...
CVE-2022-24665HIGH8.8PHP Everywhere <= 2.0.3 included functionality that allowed execution of PHP Code Snippets via a WordPress gutenberg blo...
CVE-2022-24664HIGH8.8PHP Everywhere <= 2.0.3 included functionality that allowed execution of PHP Code Snippets via WordPress metaboxes, whic...
CVE-2022-24663HIGH8.8PHP Everywhere <= 2.0.3 included functionality that allowed execution of PHP Code Snippets via WordPress shortcodes, whi...
CVE-2022-24086CRITICAL9.8Adobe Commerce versions 2.4.3-p1 (and earlier) and 2.3.7-p2 (and earlier) are affected by an improper input validation v...
CVE-2022-23804HIGH7.8A stack-based buffer overflow vulnerability exists in the Gerber Viewer gerber and excellon ReadIJCoord coordinate parsi...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now