2022 CVE Vulnerabilities

27,554 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-0498Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2022-0487MEDIUM5.5A use-after-free vulnerability was found in rtsx_usb_ms_drv_remove in drivers/memstick/host/rtsx_usb_ms.c in memstick in...
CVE-2022-0484HIGH8.8Lack of validation of URLs causes Mirantis Container Cloud Lens Extension before v3.1.1 to open external programs other ...
CVE-2022-0481HIGH7.5NULL Pointer Dereference in Homebrew mruby prior to 3.2.
CVE-2022-0472MEDIUM5.4Unrestricted Upload of File with Dangerous Type in Packagist jsdecena/laracom prior to v2.0.9.
CVE-2022-0381MEDIUM6.1The Embed Swagger WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to insufficient escaping/sanitiza...
CVE-2022-0380MEDIUM6.1The Fotobook WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to insufficient escaping and the use o...
CVE-2022-0365CRITICAL9.8The affected product is vulnerable to an authenticated OS command injection, which may allow an attacker to inject and e...
CVE-2022-0317LOW3.3An improper input validation vulnerability in go-attestation before 0.3.3 allows local users to provide a maliciously-fo...
CVE-2022-0264MEDIUM5.5A vulnerability was found in the Linux kernel's eBPF verifier when handling internal data structures. Internal memory lo...
CVE-2022-0227Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. Reason: This CVE has been rejected as it was incorrectly assigned. Al...
CVE-2022-0218MEDIUM6.1The WP HTML Mail WordPress plugin is vulnerable to unauthorized access which allows unauthenticated attackers to retriev...
CVE-2022-23330HIGH8.8A remote code execution (RCE) vulnerability in HelloWorldAddonController.java of jpress v4.2.0 allows attackers to execu...
CVE-2022-23329CRITICAL9.8A vulnerability in ${"freemarker.template.utility.Execute"?new() of UJCMS Jspxcms v10.2.0 allows attackers to execute ar...
CVE-2022-24348HIGH7.7Argo CD before 2.1.9 and 2.2.x before 2.2.4 allows directory traversal related to Helm charts because of an error in hel...
CVE-2022-24448LOW3.3An issue was discovered in fs/nfs/dir.c in the Linux kernel before 5.16.5. If an application sets the O_DIRECTORY flag, ...
CVE-2022-24129HIGH8.2The OIDC OP plugin before 3.0.4 for Shibboleth Identity Provider allows server-side request forgery (SSRF) due to insuff...
CVE-2022-24249MEDIUM5.5A Null Pointer Dereference vulnerability exists in GPAC 1.1.0 via the xtra_box_write function in /box_code_base.c, which...
CVE-2022-24262HIGH8.8The config restore function of Voipmonitor GUI before v24.96 does not properly check files sent as restore archives, all...
CVE-2022-24260CRITICAL9.8A SQL injection vulnerability in Voipmonitor GUI before v24.96 allows attackers to escalate privileges to the Administra...
CVE-2022-24259CRITICAL9.8An incorrect check in the component cdr.php of Voipmonitor GUI before v24.96 allows unauthenticated attackers to escalat...
CVE-2022-23316MEDIUM4.9An issue was discovered in taoCMS v3.0.2. There is an arbitrary file read vulnerability that can read any files via admi...
CVE-2022-24172HIGH7.5Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a stack overflow in the function formAddDhcpBind...
CVE-2022-24171CRITICAL9.8Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerability in the functio...
CVE-2022-24170CRITICAL9.8Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerability in the functio...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now