2022 CVE Vulnerabilities
27,554 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-24218 | CRITICAL | 9.1 | 17.0% | Feb 1, 2022 | An issue in /admin/delete_image.php of eliteCMS v1.0 allows attackers to delete arbitrary files. |
| CVE-2022-23601 | HIGH | 8.8 | 0.6% | Feb 1, 2022 | Symfony is a PHP framework for web and console applications and a set of reusable PHP components. The Symfony form compo... |
| CVE-2022-0417 | HIGH | 7.8 | 1.5% | Feb 1, 2022 | Heap-based Buffer Overflow GitHub repository vim/vim prior to 8.2. |
| CVE-2022-0401 | CRITICAL | 9.8 | 1.6% | Feb 1, 2022 | Path Traversal in NPM w-zip prior to 1.0.12. |
| CVE-2022-0320 | CRITICAL | 9.8 | 2.0% | Feb 1, 2022 | The Essential Addons for Elementor WordPress plugin before 5.0.5 does not validate and sanitise some template data befor... |
| CVE-2022-0220 | MEDIUM | 6.1 | 2.3% | Feb 1, 2022 | The check_privacy_settings AJAX action of the WordPress GDPR WordPress plugin before 1.9.27, available to both unauthent... |
| CVE-2022-23597 | HIGH | 8.8 | 1.5% | Feb 1, 2022 | Element Desktop is a Matrix client for desktop platforms with Element Web at its core. Element Desktop before 1.9.7 is v... |
| CVE-2022-23596 | HIGH | 7.5 | 1.6% | Feb 1, 2022 | Junrar is an open source java RAR archive library. In affected versions A carefully crafted RAR archive can trigger an i... |
| CVE-2022-21687 | MEDIUM | 6.5 | 1.0% | Feb 1, 2022 | gh-ost is a triggerless online schema migration solution for MySQL. Versions prior to 1.1.3 are subject to an arbitrary ... |
| CVE-2022-23607 | MEDIUM | 6.5 | 1.1% | Feb 1, 2022 | treq is an HTTP library inspired by requests but written on top of Twisted's Agents. Treq's request methods (`treq.get`,... |
| CVE-2022-23603 | MEDIUM | 6.1 | 1.0% | Feb 1, 2022 | iTunesRPC-Remastered is a discord rich presence application for use with iTunes & Apple Music. In code before commit 24f... |
| CVE-2022-23602 | HIGH | 8.1 | 1.3% | Feb 1, 2022 | Nimforum is a lightweight alternative to Discourse written in Nim. In versions prior to 2.2.0 any forum user can create ... |
| CVE-2022-0419 | MEDIUM | 5.5 | 0.9% | Feb 1, 2022 | NULL Pointer Dereference in GitHub repository radareorg/radare2 prior to 5.6.0. |
| CVE-2022-23774 | MEDIUM | 5.3 | 0.9% | Feb 1, 2022 | Docker Desktop before 4.4.4 on Windows allows attackers to move arbitrary files. |
| CVE-2022-24266 | HIGH | 7.5 | 6.4% | Jan 31, 2022 | Cuppa CMS v1.0 was discovered to contain a SQL injection vulnerability in /administrator/components/table_manager/ via t... |
| CVE-2022-24265 | HIGH | 7.5 | 6.7% | Jan 31, 2022 | Cuppa CMS v1.0 was discovered to contain a SQL injection vulnerability in /administrator/components/menu/ via the path=c... |
| CVE-2022-24264 | HIGH | 7.5 | 6.7% | Jan 31, 2022 | Cuppa CMS v1.0 was discovered to contain a SQL injection vulnerability in /administrator/components/table_manager/ via t... |
| CVE-2022-24263 | CRITICAL | 9.8 | 8.2% | Jan 31, 2022 | Hospital Management System v4.0 was discovered to contain a SQL injection vulnerability in /Hospital-Management-System-m... |
| CVE-2022-23872 | MEDIUM | 4.8 | 0.6% | Jan 31, 2022 | Emlog pro v1.1.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the component /admin/con... |
| CVE-2022-21659 | MEDIUM | 5.3 | 1.0% | Jan 31, 2022 | Flask-AppBuilder is an application development framework, built on top of the Flask web framework. In affected versions ... |
| CVE-2022-0286 | MEDIUM | 5.5 | 0.5% | Jan 31, 2022 | A flaw was found in the Linux kernel. A null pointer dereference in bond_ipsec_add_sa() may lead to local denial of serv... |
| CVE-2022-0414 | MEDIUM | 4.3 | 1.1% | Jan 31, 2022 | Improper Validation of Specified Quantity in Input in Packagist dolibarr/dolibarr prior to 16.0. |
| CVE-2022-23409 | MEDIUM | 4.9 | 13.8% | Jan 31, 2022 | The Logs plugin before 3.0.4 for Craft CMS allows remote attackers to read arbitrary files via input to actionStream in ... |
| CVE-2022-24130 | MEDIUM | 5.5 | 1.7% | Jan 31, 2022 | xterm through Patch 370, when Sixel support is enabled, allows attackers to trigger a buffer overflow in set_sixel in gr... |
| CVE-2022-0413 | HIGH | 7.8 | 1.4% | Jan 30, 2022 | Use After Free in GitHub repository vim/vim prior to 8.2. |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now