2022 CVE Vulnerabilities
27,554 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-21805 | MEDIUM | 6.1 | 0.9% | Feb 8, 2022 | Reflected cross-site scripting vulnerability in the attached file name of php_mailform versions prior to Version 1.40 al... |
| CVE-2022-21799 | MEDIUM | 5.2 | 0.3% | Feb 8, 2022 | Cross-site scripting vulnerability in ELECOM LAN router WRC-300FEBK-R firmware v1.13 and earlier allows an attacker on t... |
| CVE-2022-21241 | CRITICAL | 9.6 | 3.1% | Feb 8, 2022 | Cross-site scripting vulnerability in CSV+ prior to 0.8.1 allows a remote unauthenticated attacker to inject an arbitrar... |
| CVE-2022-21193 | HIGH | 7.5 | 2.0% | Feb 8, 2022 | Directory traversal vulnerability in TransmitMail 2.5.0 to 2.6.1 allows a remote unauthenticated attacker to obtain an a... |
| CVE-2022-21173 | HIGH | 8.8 | 0.4% | Feb 8, 2022 | Hidden functionality vulnerability in ELECOM LAN routers (WRH-300BK3 firmware v1.05 and earlier, WRH-300WH3 firmware v1.... |
| CVE-2022-0508 | MEDIUM | 5.3 | 0.9% | Feb 8, 2022 | Server-Side Request Forgery (SSRF) in GitHub repository chocobozzz/peertube prior to f33e515991a32885622b217bf2ed1d1b0d9... |
| CVE-2022-0506 | MEDIUM | 5.4 | 0.6% | Feb 8, 2022 | Cross-site Scripting (XSS) - Stored in Packagist microweber/microweber prior to 1.2.11. |
| CVE-2022-0505 | MEDIUM | 6.5 | 0.7% | Feb 8, 2022 | Cross-Site Request Forgery (CSRF) in Packagist microweber/microweber prior to 1.2.11. |
| CVE-2022-0504 | MEDIUM | 6.5 | 1.1% | Feb 8, 2022 | Generation of Error Message Containing Sensitive Information in Packagist microweber/microweber prior to 1.2.11. |
| CVE-2022-24450 | HIGH | 8.8 | 1.3% | Feb 8, 2022 | NATS nats-server before 2.7.2 has Incorrect Access Control. Any authenticated user can obtain the privileges of the Syst... |
| CVE-2022-23624 | HIGH | 8.8 | 1.2% | Feb 7, 2022 | Frourio-express is a minimal full stack framework, for TypeScript. Frourio-express users who uses frourio-express versio... |
| CVE-2022-23623 | HIGH | 8.8 | 1.2% | Feb 7, 2022 | Frourio is a full stack framework, for TypeScript. Frourio users who uses frourio version prior to v0.26.0 and integrati... |
| CVE-2022-23613 | HIGH | 7.8 | 0.5% | Feb 7, 2022 | xrdp is an open source remote desktop protocol (RDP) server. In affected versions an integer underflow leading to a heap... |
| CVE-2022-21712 | HIGH | 7.5 | 1.4% | Feb 7, 2022 | twisted is an event-driven networking engine written in Python. In affected versions twisted exposes cookies and authori... |
| CVE-2022-21816 | MEDIUM | 5.5 | 0.2% | Feb 7, 2022 | NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (nvidia.ko), where a user in the guest OS can c... |
| CVE-2022-21815 | MEDIUM | 5.5 | 0.2% | Feb 7, 2022 | NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for priva... |
| CVE-2022-21814 | MEDIUM | 6.1 | 0.2% | Feb 7, 2022 | NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel driver package, where improper handling of in... |
| CVE-2022-21813 | MEDIUM | 6.1 | 0.2% | Feb 7, 2022 | NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel driver, where improper handling of insufficie... |
| CVE-2022-22931 | MEDIUM | 4.3 | 1.7% | Feb 7, 2022 | Fix of CVE-2021-40525 do not prepend delimiters upon valid directory validations. Affected implementations include: - ma... |
| CVE-2022-23263 | HIGH | 7.7 | 0.8% | Feb 7, 2022 | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability |
| CVE-2022-23262 | MEDIUM | 6.3 | 1.2% | Feb 7, 2022 | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability |
| CVE-2022-23261 | MEDIUM | 5.3 | 1.5% | Feb 7, 2022 | Microsoft Edge (Chromium-based) Tampering Vulnerability |
| CVE-2022-0149 | MEDIUM | 6.1 | 2.3% | Feb 7, 2022 | The WooCommerce Stored Exporter WordPress plugin before 2.7.1 was affected by a Reflected Cross-Site Scripting (XSS) vul... |
| CVE-2022-0148 | MEDIUM | 5.4 | 1.6% | Feb 7, 2022 | The All-in-one Floating Contact Form, Call, Chat, and 50+ Social Icon Tabs WordPress plugin before 2.0.4 was vulnerable ... |
| CVE-2022-23320 | HIGH | 7.5 | 1.7% | Feb 7, 2022 | XMPie uStore 12.3.7244.0 allows for administrators to generate reports based on raw SQL queries. Since the application s... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now