2022 CVE Vulnerabilities
27,554 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-0498 | — | — | — | Feb 4, 2022 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2022-0487 | MEDIUM | 5.5 | 0.4% | Feb 4, 2022 | A use-after-free vulnerability was found in rtsx_usb_ms_drv_remove in drivers/memstick/host/rtsx_usb_ms.c in memstick in... |
| CVE-2022-0484 | HIGH | 8.8 | 1.0% | Feb 4, 2022 | Lack of validation of URLs causes Mirantis Container Cloud Lens Extension before v3.1.1 to open external programs other ... |
| CVE-2022-0481 | HIGH | 7.5 | 0.9% | Feb 4, 2022 | NULL Pointer Dereference in Homebrew mruby prior to 3.2. |
| CVE-2022-0472 | MEDIUM | 5.4 | 0.8% | Feb 4, 2022 | Unrestricted Upload of File with Dangerous Type in Packagist jsdecena/laracom prior to v2.0.9. |
| CVE-2022-0381 | MEDIUM | 6.1 | 3.9% | Feb 4, 2022 | The Embed Swagger WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to insufficient escaping/sanitiza... |
| CVE-2022-0380 | MEDIUM | 6.1 | 0.9% | Feb 4, 2022 | The Fotobook WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to insufficient escaping and the use o... |
| CVE-2022-0365 | CRITICAL | 9.8 | 2.2% | Feb 4, 2022 | The affected product is vulnerable to an authenticated OS command injection, which may allow an attacker to inject and e... |
| CVE-2022-0317 | LOW | 3.3 | 0.1% | Feb 4, 2022 | An improper input validation vulnerability in go-attestation before 0.3.3 allows local users to provide a maliciously-fo... |
| CVE-2022-0264 | MEDIUM | 5.5 | 0.3% | Feb 4, 2022 | A vulnerability was found in the Linux kernel's eBPF verifier when handling internal data structures. Internal memory lo... |
| CVE-2022-0227 | — | — | — | Feb 4, 2022 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. Reason: This CVE has been rejected as it was incorrectly assigned. Al... |
| CVE-2022-0218 | MEDIUM | 6.1 | 70.5% | Feb 4, 2022 | The WP HTML Mail WordPress plugin is vulnerable to unauthorized access which allows unauthenticated attackers to retriev... |
| CVE-2022-23330 | HIGH | 8.8 | 1.8% | Feb 4, 2022 | A remote code execution (RCE) vulnerability in HelloWorldAddonController.java of jpress v4.2.0 allows attackers to execu... |
| CVE-2022-23329 | CRITICAL | 9.8 | 14.4% | Feb 4, 2022 | A vulnerability in ${"freemarker.template.utility.Execute"?new() of UJCMS Jspxcms v10.2.0 allows attackers to execute ar... |
| CVE-2022-24348 | HIGH | 7.7 | 2.7% | Feb 4, 2022 | Argo CD before 2.1.9 and 2.2.x before 2.2.4 allows directory traversal related to Helm charts because of an error in hel... |
| CVE-2022-24448 | LOW | 3.3 | 0.4% | Feb 4, 2022 | An issue was discovered in fs/nfs/dir.c in the Linux kernel before 5.16.5. If an application sets the O_DIRECTORY flag, ... |
| CVE-2022-24129 | HIGH | 8.2 | 6.1% | Feb 4, 2022 | The OIDC OP plugin before 3.0.4 for Shibboleth Identity Provider allows server-side request forgery (SSRF) due to insuff... |
| CVE-2022-24249 | MEDIUM | 5.5 | 0.6% | Feb 4, 2022 | A Null Pointer Dereference vulnerability exists in GPAC 1.1.0 via the xtra_box_write function in /box_code_base.c, which... |
| CVE-2022-24262 | HIGH | 8.8 | 1.8% | Feb 4, 2022 | The config restore function of Voipmonitor GUI before v24.96 does not properly check files sent as restore archives, all... |
| CVE-2022-24260 | CRITICAL | 9.8 | 50.9% | Feb 4, 2022 | A SQL injection vulnerability in Voipmonitor GUI before v24.96 allows attackers to escalate privileges to the Administra... |
| CVE-2022-24259 | CRITICAL | 9.8 | 2.0% | Feb 4, 2022 | An incorrect check in the component cdr.php of Voipmonitor GUI before v24.96 allows unauthenticated attackers to escalat... |
| CVE-2022-23316 | MEDIUM | 4.9 | 1.0% | Feb 4, 2022 | An issue was discovered in taoCMS v3.0.2. There is an arbitrary file read vulnerability that can read any files via admi... |
| CVE-2022-24172 | HIGH | 7.5 | 1.2% | Feb 4, 2022 | Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a stack overflow in the function formAddDhcpBind... |
| CVE-2022-24171 | CRITICAL | 9.8 | 3.0% | Feb 4, 2022 | Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerability in the functio... |
| CVE-2022-24170 | CRITICAL | 9.8 | 3.0% | Feb 4, 2022 | Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerability in the functio... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now