2022 CVE Vulnerabilities

27,554 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-24218CRITICAL9.1An issue in /admin/delete_image.php of eliteCMS v1.0 allows attackers to delete arbitrary files.
CVE-2022-23601HIGH8.8Symfony is a PHP framework for web and console applications and a set of reusable PHP components. The Symfony form compo...
CVE-2022-0417HIGH7.8Heap-based Buffer Overflow GitHub repository vim/vim prior to 8.2.
CVE-2022-0401CRITICAL9.8Path Traversal in NPM w-zip prior to 1.0.12.
CVE-2022-0320CRITICAL9.8The Essential Addons for Elementor WordPress plugin before 5.0.5 does not validate and sanitise some template data befor...
CVE-2022-0220MEDIUM6.1The check_privacy_settings AJAX action of the WordPress GDPR WordPress plugin before 1.9.27, available to both unauthent...
CVE-2022-23597HIGH8.8Element Desktop is a Matrix client for desktop platforms with Element Web at its core. Element Desktop before 1.9.7 is v...
CVE-2022-23596HIGH7.5Junrar is an open source java RAR archive library. In affected versions A carefully crafted RAR archive can trigger an i...
CVE-2022-21687MEDIUM6.5gh-ost is a triggerless online schema migration solution for MySQL. Versions prior to 1.1.3 are subject to an arbitrary ...
CVE-2022-23607MEDIUM6.5treq is an HTTP library inspired by requests but written on top of Twisted's Agents. Treq's request methods (`treq.get`,...
CVE-2022-23603MEDIUM6.1iTunesRPC-Remastered is a discord rich presence application for use with iTunes & Apple Music. In code before commit 24f...
CVE-2022-23602HIGH8.1Nimforum is a lightweight alternative to Discourse written in Nim. In versions prior to 2.2.0 any forum user can create ...
CVE-2022-0419MEDIUM5.5NULL Pointer Dereference in GitHub repository radareorg/radare2 prior to 5.6.0.
CVE-2022-23774MEDIUM5.3Docker Desktop before 4.4.4 on Windows allows attackers to move arbitrary files.
CVE-2022-24266HIGH7.5Cuppa CMS v1.0 was discovered to contain a SQL injection vulnerability in /administrator/components/table_manager/ via t...
CVE-2022-24265HIGH7.5Cuppa CMS v1.0 was discovered to contain a SQL injection vulnerability in /administrator/components/menu/ via the path=c...
CVE-2022-24264HIGH7.5Cuppa CMS v1.0 was discovered to contain a SQL injection vulnerability in /administrator/components/table_manager/ via t...
CVE-2022-24263CRITICAL9.8Hospital Management System v4.0 was discovered to contain a SQL injection vulnerability in /Hospital-Management-System-m...
CVE-2022-23872MEDIUM4.8Emlog pro v1.1.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the component /admin/con...
CVE-2022-21659MEDIUM5.3Flask-AppBuilder is an application development framework, built on top of the Flask web framework. In affected versions ...
CVE-2022-0286MEDIUM5.5A flaw was found in the Linux kernel. A null pointer dereference in bond_ipsec_add_sa() may lead to local denial of serv...
CVE-2022-0414MEDIUM4.3Improper Validation of Specified Quantity in Input in Packagist dolibarr/dolibarr prior to 16.0.
CVE-2022-23409MEDIUM4.9The Logs plugin before 3.0.4 for Craft CMS allows remote attackers to read arbitrary files via input to actionStream in ...
CVE-2022-24130MEDIUM5.5xterm through Patch 370, when Sixel support is enabled, allows attackers to trigger a buffer overflow in set_sixel in gr...
CVE-2022-0413HIGH7.8Use After Free in GitHub repository vim/vim prior to 8.2.

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now