2022 CVE Vulnerabilities

27,554 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-0527MEDIUM6.1Cross-site Scripting (XSS) - Stored in GitHub repository chatwoot/chatwoot prior to 2.2.0.
CVE-2022-0526MEDIUM6.1Cross-site Scripting (XSS) - Stored in GitHub repository chatwoot/chatwoot prior to 2.2.0.
CVE-2022-24682MEDIUM6.1An issue was discovered in the Calendar feature in Zimbra Collaboration Suite 8.8.x before 8.8.15 patch 30 (update 1), a...
CVE-2022-0525CRITICAL9.1Out-of-bounds Read in Homebrew mruby prior to 3.2.
CVE-2022-24677CRITICAL9.8Admin.php in HYBBS2 through 2.3.2 allows remote code execution because it writes plugin-related configuration informatio...
CVE-2022-24676HIGH8.8update_code in Admin.php in HYBBS2 through 2.3.2 allows arbitrary file upload via a crafted ZIP archive.
CVE-2022-23627MEDIUM6.8ArchiSteamFarm (ASF) is a C# application with primary purpose of idling Steam cards from multiple accounts simultaneousl...
CVE-2022-23626HIGH8.8m1k1o/blog is a lightweight self-hosted facebook-styled PHP blog. Errors from functions `imagecreatefrom*` and `image*` ...
CVE-2022-0524HIGH7.5Business Logic Errors in GitHub repository publify/publify prior to 9.2.7.
CVE-2022-21713MEDIUM4.3Grafana is an open-source platform for monitoring and observability. Affected versions of Grafana expose multiple API en...
CVE-2022-21703HIGH8.8Grafana is an open-source platform for monitoring and observability. Affected versions are subject to a cross site reque...
CVE-2022-0523HIGH7.8Use After Free in GitHub repository radareorg/radare2 prior to 5.6.2.
CVE-2022-0522HIGH7.1Access of Memory Location Before Start of Buffer in NPM radare2.js prior to 5.6.2.
CVE-2022-0521HIGH7.1Access of Memory Location After End of Buffer in GitHub repository radareorg/radare2 prior to 5.6.2.
CVE-2022-0520HIGH7.8Use After Free in NPM radare2.js prior to 5.6.2.
CVE-2022-0519HIGH7.1Buffer Access with Incorrect Length Value in GitHub repository radareorg/radare2 prior to 5.6.2.
CVE-2022-0518HIGH7.1Heap-based Buffer Overflow in GitHub repository radareorg/radare2 prior to 5.6.2.
CVE-2022-21702MEDIUM5.4Grafana is an open-source platform for monitoring and observability. In affected versions an attacker could serve HTML c...
CVE-2022-0139CRITICAL9.8Use After Free in GitHub repository radareorg/radare2 prior to 5.6.0.
CVE-2022-0510MEDIUM5.4Cross-site Scripting (XSS) - Reflected in Packagist pimcore/pimcore prior to 10.3.1.
CVE-2022-23340CRITICAL9.8Joplin 2.6.10 allows remote attackers to execute system commands through malicious code in user search results.
CVE-2022-23331HIGH8.8In DataEase v1.6.1, an authenticated user can gain unauthorized access to all user information and can change the admini...
CVE-2022-0509MEDIUM5.4Cross-site Scripting (XSS) - Stored in Packagist pimcore/pimcore prior to 10.3.1.
CVE-2022-22146MEDIUM6.1Cross-site scripting vulnerability in TransmitMail 2.5.0 to 2.6.1 allows a remote unauthenticated attacker to inject an ...
CVE-2022-22142MEDIUM6.1Reflected cross-site scripting vulnerability in the checkbox of php_mailform versions prior to Version 1.40 allows a rem...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now