2022 CVE Vulnerabilities

27,554 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-24666HIGH7.5A program using swift-nio-http2 is vulnerable to a denial of service attack, caused by a network peer sending a speciall...
CVE-2022-24321HIGH7.5A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists that could cause Denial of Service ...
CVE-2022-24320MEDIUM5.9A CWE-295: Improper Certificate Validation vulnerability exists that could allow a Man-in-theMiddle attack when communic...
CVE-2022-24319MEDIUM5.9A CWE-295: Improper Certificate Validation vulnerability exists that could allow a Man-in-theMiddle attack when communic...
CVE-2022-24318HIGH7.5A CWE-326: Inadequate Encryption Strength vulnerability exists that could cause non-encrypted communication with the ser...
CVE-2022-24317HIGH7.5A CWE-862: Missing Authorization vulnerability exists that could cause information exposure when an attacker sends a spe...
CVE-2022-24316HIGH7.5A CWE-665: Improper Initialization vulnerability exists that could cause information exposure when an attacker sends a s...
CVE-2022-24315HIGH7.5A CWE-125: Out-of-bounds Read vulnerability exists that could cause denial of service when an attacker repeatedly sends ...
CVE-2022-24314HIGH7.5A CWE-125: Out-of-bounds Read vulnerability exists that could cause memory leaks potentially resulting in denial of serv...
CVE-2022-24313CRITICAL9.8A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could cause a stack-based buffer overflo...
CVE-2022-24312CRITICAL9.8A CWE-22: Improper Limitation of a Pathname to a Restricted Directory vulnerability exists that could cause modification...
CVE-2022-24311CRITICAL9.8A CWE-22: Improper Limitation of a Pathname to a Restricted Directory vulnerability exists that could cause modification...
CVE-2022-24310CRITICAL9.8A CWE-190: Integer Overflow or Wraparound vulnerability exists that could cause heap-based buffer overflow, leading to d...
CVE-2022-23049MEDIUM5.4Exponent CMS 2.6.0patch2 allows an authenticated user to inject persistent JavaScript code on the "User-Agent" header wh...
CVE-2022-23048HIGH7.2Exponent CMS 2.6.0patch2 allows an authenticated admin user to upload a malicious extension in the format of a ZIP file ...
CVE-2022-23047MEDIUM4.8Exponent CMS 2.6.0patch2 allows an authenticated admin user to inject persistent JavaScript code inside the "Site/Organi...
CVE-2022-22813CRITICAL9.8A CWE-798: Use of Hard-coded Credentials vulnerability exists. If an attacker were to obtain the TLS cryptographic key a...
CVE-2022-22812MEDIUM6.1A CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists that...
CVE-2022-22811HIGH8.1A CWE-352: Cross-Site Request Forgery (CSRF) vulnerability exists that could induce users to perform unintended actions,...
CVE-2022-22810CRITICAL9.8A CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists that could allow an attacker t...
CVE-2022-22809MEDIUM5.3A CWE-306: Missing Authentication for Critical Function vulnerability exists that could allow modifications of the touch...
CVE-2022-22808HIGH8.8A CWE-352: Cross-Site Request Forgery (CSRF) exists that could cause a remote attacker to gain unauthorized access to th...
CVE-2022-22807HIGH7.4A CWE-1021 Improper Restriction of Rendered UI Layers or Frames vulnerability exists that could cause unintended modific...
CVE-2022-22780MEDIUM6.5The Zoom Client for Meetings chat functionality was susceptible to Zip bombing attacks in the following product versions...
CVE-2022-22779LOW3.7The Keybase Clients for macOS and Windows before version 5.9.0 fails to properly remove exploded messages initiated by a...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now