2022 CVE Vulnerabilities
27,554 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-23873 | HIGH | 8.8 | 1.3% | Feb 3, 2022 | Victor CMS v1.0 was discovered to contain a SQL injection vulnerability that allows attackers to inject arbitrary comman... |
| CVE-2022-23871 | MEDIUM | 5.4 | 0.6% | Feb 3, 2022 | Multiple cross-site scripting (XSS) vulnerabilities in the component outcomes_addProcess.php of Gibbon CMS v22.0.01 allo... |
| CVE-2022-23357 | CRITICAL | 9.1 | 19.9% | Feb 3, 2022 | mozilo2.0 was discovered to be vulnerable to directory traversal attacks via the parameter curent_dir. |
| CVE-2022-24031 | HIGH | 8.2 | 0.3% | Feb 3, 2022 | An issue was discovered in NvmExpressDxe in Insyde InsydeH2O with kernel 5.1 through 5.5. An SMM memory corruption vulne... |
| CVE-2022-24030 | HIGH | 7.5 | 0.3% | Feb 3, 2022 | An issue was discovered in AhciBusDxe in Insyde InsydeH2O with kernel 5.1 through 5.5. An SMM memory corruption vulnerab... |
| CVE-2022-23833 | HIGH | 7.5 | 49.2% | Feb 3, 2022 | An issue was discovered in MultiPartParser in Django 2.2 before 2.2.27, 3.2 before 3.2.12, and 4.0 before 4.0.2. Passing... |
| CVE-2022-22818 | MEDIUM | 6.1 | 3.3% | Feb 3, 2022 | The {% debug %} template tag in Django 2.2 before 2.2.27, 3.2 before 3.2.12, and 4.0 before 4.0.2 does not properly enco... |
| CVE-2022-24069 | HIGH | 8.2 | 0.3% | Feb 3, 2022 | An issue was discovered in AhciBusDxe in Insyde InsydeH2O with kernel 5.0 before 05.08.41, 5.1 before 05.16.29, 5.2 befo... |
| CVE-2022-0432 | MEDIUM | 6.1 | 4.5% | Feb 2, 2022 | Prototype Pollution in GitHub repository mastodon/mastodon prior to 3.5.0. |
| CVE-2022-0443 | HIGH | 7.8 | 1.4% | Feb 2, 2022 | Use After Free in GitHub repository vim/vim prior to 8.2. |
| CVE-2022-22510 | HIGH | 7.5 | 1.0% | Feb 2, 2022 | Codesys Profinet in version V4.2.0.0 is prone to null pointer dereference that allows a denial of service (DoS) attack o... |
| CVE-2022-22509 | HIGH | 8.8 | 1.0% | Feb 2, 2022 | In Phoenix Contact FL SWITCH Series 2xxx in version 3.00 an incorrect privilege assignment allows an low privileged user... |
| CVE-2022-21817 | CRITICAL | 9.3 | 2.0% | Feb 2, 2022 | NVIDIA Omniverse Launcher contains a Cross-Origin Resource Sharing (CORS) vulnerability which can allow an unprivileged ... |
| CVE-2022-21724 | CRITICAL | 9.8 | 3.0% | Feb 2, 2022 | pgjdbc is the offical PostgreSQL JDBC Driver. A security hole was found in the jdbc driver for postgresql database while... |
| CVE-2022-0366 | HIGH | 8.8 | 1.0% | Feb 2, 2022 | An authenticated and authorized agent user could potentially gain administrative access via an SQLi vulnerability to Cap... |
| CVE-2022-24301 | MEDIUM | 6.5 | 1.0% | Feb 2, 2022 | In Minetest before 5.4.0, players can add or subtract items from a different player's inventory. |
| CVE-2022-24300 | CRITICAL | 9.8 | 1.7% | Feb 2, 2022 | Minetest before 5.4.0 allows attackers to add or modify arbitrary meta fields of the same item stack as saved user input... |
| CVE-2022-24198 | MEDIUM | 6.5 | 0.5% | Feb 1, 2022 | iText v7.1.17 was discovered to contain an out-of-bounds exception via the component ARCFOUREncryption.encryptARCFOUR, w... |
| CVE-2022-24197 | MEDIUM | 6.5 | 1.5% | Feb 1, 2022 | iText v7.1.17 was discovered to contain a stack-based buffer overflow via the component ByteBuffer.append, which allows ... |
| CVE-2022-24196 | MEDIUM | 6.5 | 1.6% | Feb 1, 2022 | iText v7.1.17, up to (exluding)": 7.1.18 and 7.2.2 was discovered to contain an out-of-memory error via the component re... |
| CVE-2022-24223 | CRITICAL | 9.8 | 62.0% | Feb 1, 2022 | AtomCMS v2.0 was discovered to contain a SQL injection vulnerability via /admin/login.php. |
| CVE-2022-24222 | CRITICAL | 9.8 | 1.1% | Feb 1, 2022 | eliteCMS v1.0 was discovered to contain a SQL injection vulnerability via /admin/edit_user.php. |
| CVE-2022-24221 | CRITICAL | 9.8 | 1.1% | Feb 1, 2022 | eliteCMS v1.0 was discovered to contain a SQL injection vulnerability via /admin/functions/functions.php. |
| CVE-2022-24220 | CRITICAL | 9.8 | 1.1% | Feb 1, 2022 | eliteCMS v1.0 was discovered to contain a SQL injection vulnerability via /admin/edit_post.php. |
| CVE-2022-24219 | CRITICAL | 9.8 | 1.1% | Feb 1, 2022 | eliteCMS v1.0 was discovered to contain a SQL injection vulnerability via /admin/edit_page.php. |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now