2022 CVE Vulnerabilities
27,554 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-0623 | CRITICAL | 9.1 | 1.6% | Feb 17, 2022 | Out-of-bounds Read in Homebrew mruby prior to 3.2. |
| CVE-2022-24953 | MEDIUM | 5.3 | 0.8% | Feb 17, 2022 | The Crypt_GPG extension before 1.6.7 for PHP does not prevent additional options in GPG calls, which presents a risk for... |
| CVE-2022-22901 | MEDIUM | 5.5 | 0.8% | Feb 17, 2022 | There is an Assertion in 'context_p->next_scanner_info_p->type == SCANNER_TYPE_FUNCTION' failed at parser_parse_function... |
| CVE-2022-0622 | MEDIUM | 5.3 | 1.0% | Feb 17, 2022 | Generation of Error Message Containing Sensitive Information in Packagist snipe/snipe-it prior to 5.3.11. |
| CVE-2022-25270 | MEDIUM | 6.5 | 0.8% | Feb 17, 2022 | The Quick Edit module does not properly check entity access in some circumstances. This could result in users with the "... |
| CVE-2022-25271 | HIGH | 7.5 | 1.2% | Feb 16, 2022 | Drupal core's form API has a vulnerability where certain contributed or custom modules' forms may be vulnerable to impro... |
| CVE-2022-24985 | HIGH | 8.8 | 2.3% | Feb 16, 2022 | Forms generated by JQueryForm.com before 2022-02-05 allows a remote authenticated attacker to bypass authentication and ... |
| CVE-2022-24984 | CRITICAL | 9.8 | 2.5% | Feb 16, 2022 | Forms generated by JQueryForm.com before 2022-02-05 (if file-upload capability is enabled) allow remote unauthenticated ... |
| CVE-2022-24983 | HIGH | 7.5 | 2.6% | Feb 16, 2022 | Forms generated by JQueryForm.com before 2022-02-05 allow remote attackers to obtain the URI to any uploaded file by cap... |
| CVE-2022-24982 | MEDIUM | 6.5 | 1.2% | Feb 16, 2022 | Forms generated by JQueryForm.com before 2022-02-05 allows a remote authenticated attacker to access the cleartext crede... |
| CVE-2022-24981 | MEDIUM | 6.1 | 1.0% | Feb 16, 2022 | A reflected cross-site scripting (XSS) vulnerability in forms generated by JQueryForm.com before 2022-02-05 allows remot... |
| CVE-2022-23636 | HIGH | 8.1 | 0.8% | Feb 16, 2022 | Wasmtime is an open source runtime for WebAssembly & WASI. Prior to versions 0.34.1 and 0.33.1, there exists a bug in th... |
| CVE-2022-22885 | CRITICAL | 9.8 | 1.3% | Feb 16, 2022 | Hutool v5.7.18's HttpRequest was discovered to ignore all TLS/SSL certificate validation. |
| CVE-2022-22881 | CRITICAL | 9.8 | 1.4% | Feb 16, 2022 | Jeecg-boot v3.0 was discovered to contain a SQL injection vulnerability via the code parameter in /sys/user/queryUserCom... |
| CVE-2022-22880 | CRITICAL | 9.8 | 1.4% | Feb 16, 2022 | Jeecg-boot v3.0 was discovered to contain a SQL injection vulnerability via the code parameter in /jeecg-boot/sys/user/q... |
| CVE-2022-25265 | HIGH | 7.8 | 1.1% | Feb 16, 2022 | In the Linux kernel through 5.16.10, certain binary files may have the exec-all attribute if they were built in approxim... |
| CVE-2022-25258 | MEDIUM | 4.6 | 0.9% | Feb 16, 2022 | An issue was discovered in drivers/usb/gadget/composite.c in the Linux kernel before 5.16.10. The USB Gadget subsystem l... |
| CVE-2022-25255 | HIGH | 7.8 | 0.3% | Feb 16, 2022 | In Qt 5.9.x through 5.15.x before 5.15.9 and 6.x before 6.2.4 on Linux and UNIX, QProcess could execute a binary from th... |
| CVE-2022-23644 | HIGH | 8.8 | 0.9% | Feb 16, 2022 | BookWyrm is a decentralized social network for tracking reading habits and reviewing books. The functionality to load a ... |
| CVE-2022-22853 | MEDIUM | 5.4 | 0.8% | Feb 16, 2022 | A stored cross-site scripting (XSS) vulnerability in Hospital Patient Record Management System v1.0 allows attackers to ... |
| CVE-2022-24665 | HIGH | 8.8 | 2.4% | Feb 16, 2022 | PHP Everywhere <= 2.0.3 included functionality that allowed execution of PHP Code Snippets via a WordPress gutenberg blo... |
| CVE-2022-24664 | HIGH | 8.8 | 1.6% | Feb 16, 2022 | PHP Everywhere <= 2.0.3 included functionality that allowed execution of PHP Code Snippets via WordPress metaboxes, whic... |
| CVE-2022-24663 | HIGH | 8.8 | 2.0% | Feb 16, 2022 | PHP Everywhere <= 2.0.3 included functionality that allowed execution of PHP Code Snippets via WordPress shortcodes, whi... |
| CVE-2022-24086 | CRITICAL | 9.8 | 99.2% | Feb 16, 2022 | Adobe Commerce versions 2.4.3-p1 (and earlier) and 2.3.7-p2 (and earlier) are affected by an improper input validation v... |
| CVE-2022-23804 | HIGH | 7.8 | 1.5% | Feb 16, 2022 | A stack-based buffer overflow vulnerability exists in the Gerber Viewer gerber and excellon ReadIJCoord coordinate parsi... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now