2022 CVE Vulnerabilities

27,554 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-23873HIGH8.8Victor CMS v1.0 was discovered to contain a SQL injection vulnerability that allows attackers to inject arbitrary comman...
CVE-2022-23871MEDIUM5.4Multiple cross-site scripting (XSS) vulnerabilities in the component outcomes_addProcess.php of Gibbon CMS v22.0.01 allo...
CVE-2022-23357CRITICAL9.1mozilo2.0 was discovered to be vulnerable to directory traversal attacks via the parameter curent_dir.
CVE-2022-24031HIGH8.2An issue was discovered in NvmExpressDxe in Insyde InsydeH2O with kernel 5.1 through 5.5. An SMM memory corruption vulne...
CVE-2022-24030HIGH7.5An issue was discovered in AhciBusDxe in Insyde InsydeH2O with kernel 5.1 through 5.5. An SMM memory corruption vulnerab...
CVE-2022-23833HIGH7.5An issue was discovered in MultiPartParser in Django 2.2 before 2.2.27, 3.2 before 3.2.12, and 4.0 before 4.0.2. Passing...
CVE-2022-22818MEDIUM6.1The {% debug %} template tag in Django 2.2 before 2.2.27, 3.2 before 3.2.12, and 4.0 before 4.0.2 does not properly enco...
CVE-2022-24069HIGH8.2An issue was discovered in AhciBusDxe in Insyde InsydeH2O with kernel 5.0 before 05.08.41, 5.1 before 05.16.29, 5.2 befo...
CVE-2022-0432MEDIUM6.1Prototype Pollution in GitHub repository mastodon/mastodon prior to 3.5.0.
CVE-2022-0443HIGH7.8Use After Free in GitHub repository vim/vim prior to 8.2.
CVE-2022-22510HIGH7.5Codesys Profinet in version V4.2.0.0 is prone to null pointer dereference that allows a denial of service (DoS) attack o...
CVE-2022-22509HIGH8.8In Phoenix Contact FL SWITCH Series 2xxx in version 3.00 an incorrect privilege assignment allows an low privileged user...
CVE-2022-21817CRITICAL9.3NVIDIA Omniverse Launcher contains a Cross-Origin Resource Sharing (CORS) vulnerability which can allow an unprivileged ...
CVE-2022-21724CRITICAL9.8pgjdbc is the offical PostgreSQL JDBC Driver. A security hole was found in the jdbc driver for postgresql database while...
CVE-2022-0366HIGH8.8An authenticated and authorized agent user could potentially gain administrative access via an SQLi vulnerability to Cap...
CVE-2022-24301MEDIUM6.5In Minetest before 5.4.0, players can add or subtract items from a different player's inventory.
CVE-2022-24300CRITICAL9.8Minetest before 5.4.0 allows attackers to add or modify arbitrary meta fields of the same item stack as saved user input...
CVE-2022-24198MEDIUM6.5iText v7.1.17 was discovered to contain an out-of-bounds exception via the component ARCFOUREncryption.encryptARCFOUR, w...
CVE-2022-24197MEDIUM6.5iText v7.1.17 was discovered to contain a stack-based buffer overflow via the component ByteBuffer.append, which allows ...
CVE-2022-24196MEDIUM6.5iText v7.1.17, up to (exluding)": 7.1.18 and 7.2.2 was discovered to contain an out-of-memory error via the component re...
CVE-2022-24223CRITICAL9.8AtomCMS v2.0 was discovered to contain a SQL injection vulnerability via /admin/login.php.
CVE-2022-24222CRITICAL9.8eliteCMS v1.0 was discovered to contain a SQL injection vulnerability via /admin/edit_user.php.
CVE-2022-24221CRITICAL9.8eliteCMS v1.0 was discovered to contain a SQL injection vulnerability via /admin/functions/functions.php.
CVE-2022-24220CRITICAL9.8eliteCMS v1.0 was discovered to contain a SQL injection vulnerability via /admin/edit_post.php.
CVE-2022-24219CRITICAL9.8eliteCMS v1.0 was discovered to contain a SQL injection vulnerability via /admin/edit_page.php.

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now