2022 CVE Vulnerabilities
27,554 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-0527 | MEDIUM | 6.1 | 0.8% | Feb 9, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository chatwoot/chatwoot prior to 2.2.0. |
| CVE-2022-0526 | MEDIUM | 6.1 | 0.8% | Feb 9, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository chatwoot/chatwoot prior to 2.2.0. |
| CVE-2022-24682 | MEDIUM | 6.1 | 30.9% | Feb 9, 2022 | An issue was discovered in the Calendar feature in Zimbra Collaboration Suite 8.8.x before 8.8.15 patch 30 (update 1), a... |
| CVE-2022-0525 | CRITICAL | 9.1 | 1.2% | Feb 9, 2022 | Out-of-bounds Read in Homebrew mruby prior to 3.2. |
| CVE-2022-24677 | CRITICAL | 9.8 | 2.3% | Feb 9, 2022 | Admin.php in HYBBS2 through 2.3.2 allows remote code execution because it writes plugin-related configuration informatio... |
| CVE-2022-24676 | HIGH | 8.8 | 1.5% | Feb 9, 2022 | update_code in Admin.php in HYBBS2 through 2.3.2 allows arbitrary file upload via a crafted ZIP archive. |
| CVE-2022-23627 | MEDIUM | 6.8 | 1.0% | Feb 8, 2022 | ArchiSteamFarm (ASF) is a C# application with primary purpose of idling Steam cards from multiple accounts simultaneousl... |
| CVE-2022-23626 | HIGH | 8.8 | 9.9% | Feb 8, 2022 | m1k1o/blog is a lightweight self-hosted facebook-styled PHP blog. Errors from functions `imagecreatefrom*` and `image*` ... |
| CVE-2022-0524 | HIGH | 7.5 | 1.5% | Feb 8, 2022 | Business Logic Errors in GitHub repository publify/publify prior to 9.2.7. |
| CVE-2022-21713 | MEDIUM | 4.3 | 1.2% | Feb 8, 2022 | Grafana is an open-source platform for monitoring and observability. Affected versions of Grafana expose multiple API en... |
| CVE-2022-21703 | HIGH | 8.8 | 2.3% | Feb 8, 2022 | Grafana is an open-source platform for monitoring and observability. Affected versions are subject to a cross site reque... |
| CVE-2022-0523 | HIGH | 7.8 | 1.1% | Feb 8, 2022 | Use After Free in GitHub repository radareorg/radare2 prior to 5.6.2. |
| CVE-2022-0522 | HIGH | 7.1 | 0.9% | Feb 8, 2022 | Access of Memory Location Before Start of Buffer in NPM radare2.js prior to 5.6.2. |
| CVE-2022-0521 | HIGH | 7.1 | 0.9% | Feb 8, 2022 | Access of Memory Location After End of Buffer in GitHub repository radareorg/radare2 prior to 5.6.2. |
| CVE-2022-0520 | HIGH | 7.8 | 1.1% | Feb 8, 2022 | Use After Free in NPM radare2.js prior to 5.6.2. |
| CVE-2022-0519 | HIGH | 7.1 | 0.9% | Feb 8, 2022 | Buffer Access with Incorrect Length Value in GitHub repository radareorg/radare2 prior to 5.6.2. |
| CVE-2022-0518 | HIGH | 7.1 | 1.0% | Feb 8, 2022 | Heap-based Buffer Overflow in GitHub repository radareorg/radare2 prior to 5.6.2. |
| CVE-2022-21702 | MEDIUM | 5.4 | 2.4% | Feb 8, 2022 | Grafana is an open-source platform for monitoring and observability. In affected versions an attacker could serve HTML c... |
| CVE-2022-0139 | CRITICAL | 9.8 | 1.2% | Feb 8, 2022 | Use After Free in GitHub repository radareorg/radare2 prior to 5.6.0. |
| CVE-2022-0510 | MEDIUM | 5.4 | 0.7% | Feb 8, 2022 | Cross-site Scripting (XSS) - Reflected in Packagist pimcore/pimcore prior to 10.3.1. |
| CVE-2022-23340 | CRITICAL | 9.8 | 1.5% | Feb 8, 2022 | Joplin 2.6.10 allows remote attackers to execute system commands through malicious code in user search results. |
| CVE-2022-23331 | HIGH | 8.8 | 1.2% | Feb 8, 2022 | In DataEase v1.6.1, an authenticated user can gain unauthorized access to all user information and can change the admini... |
| CVE-2022-0509 | MEDIUM | 5.4 | 1.4% | Feb 8, 2022 | Cross-site Scripting (XSS) - Stored in Packagist pimcore/pimcore prior to 10.3.1. |
| CVE-2022-22146 | MEDIUM | 6.1 | 0.7% | Feb 8, 2022 | Cross-site scripting vulnerability in TransmitMail 2.5.0 to 2.6.1 allows a remote unauthenticated attacker to inject an ... |
| CVE-2022-22142 | MEDIUM | 6.1 | 0.9% | Feb 8, 2022 | Reflected cross-site scripting vulnerability in the checkbox of php_mailform versions prior to Version 1.40 allows a rem... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now