2022 CVE Vulnerabilities

27,554 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-0408HIGH7.8Stack-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.
CVE-2022-0407HIGH7.8Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.
CVE-2022-0339CRITICAL9.8Server-Side Request Forgery (SSRF) in Pypi calibreweb prior to 0.6.16.
CVE-2022-0273MEDIUM6.5Improper Access Control in Pypi calibreweb prior to 0.6.16.
CVE-2022-22919MEDIUM6.1Adenza AxiomSL ControllerView through 10.8.1 allows redirection for SSO login URLs.
CVE-2022-24032MEDIUM5.3Adenza AxiomSL ControllerView through 10.8.1 is vulnerable to user enumeration. An attacker can identify valid usernames...
CVE-2022-24124HIGH7.5The query API in Casdoor before 1.13.1 has a SQL injection vulnerability related to the field and value parameters, as d...
CVE-2022-24123CRITICAL9MarkText through 0.16.3 does not sanitize the input of a mermaid block before rendering. This could lead to Remote Code ...
CVE-2022-24122HIGH7.8kernel/ucount.c in the Linux kernel 5.14 through 5.16.4, when unprivileged user namespaces are enabled, allows a use-aft...
CVE-2022-23599MEDIUM6.1Products.ATContentTypes are the core content types for Plone 2.1 - 4.3. Versions of Plone that are dependent on Products...
CVE-2022-23598MEDIUM6.1laminas-form is a package for validating and displaying simple and complex forms. When rendering validation error messag...
CVE-2022-21721HIGH7.5Next.js is a React framework. Starting with version 12.0.0 and prior to version 12.0.9, vulnerable code could allow a ba...
CVE-2022-0395MEDIUM5.4Cross-site Scripting (XSS) - Stored in Packagist remdex/livehelperchat prior to 3.93v.
CVE-2022-0393HIGH7.1Out-of-bounds Read in GitHub repository vim/vim prior to 8.2.
CVE-2022-0392HIGH7.8Heap-based Buffer Overflow in GitHub repository vim prior to 8.2.
CVE-2022-0352MEDIUM6.1Cross-site Scripting (XSS) - Reflected in Pypi calibreweb prior to 0.6.16.
CVE-2022-23889MEDIUM5.3The comment function in YzmCMS v6.3 was discovered as being able to be operated concurrently, allowing attackers to crea...
CVE-2022-23888HIGH8.8YzmCMS v6.3 was discovered to contain a Cross-Site Request Forgey (CSRF) via the component /yzmcms/comment/index/init.ht...
CVE-2022-23887MEDIUM6.5YzmCMS v6.3 was discovered to contain a Cross-Site Request Forgery (CSRF) which allows attackers to arbitrarily delete u...
CVE-2022-23979MEDIUM4.8Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability discovered in Ultimate Reviews WordPress plugin (...
CVE-2022-23727HIGH7.8There is a privilege escalation vulnerability in some webOS TVs. Due to wrong setting environments, local attacker is ab...
CVE-2022-23456MEDIUM5.5Potential arbitrary file deletion vulnerability has been identified in HP Support Assistant software.
CVE-2022-22994CRITICAL9.8A remote code execution vulnerability was discovered on Western Digital My Cloud devices where an attacker could trick a...
CVE-2022-22993HIGH8.8A limited SSRF vulnerability was discovered on Western Digital My Cloud devices that could allow an attacker to imperson...
CVE-2022-22992CRITICAL9.8A command injection remote code execution vulnerability was discovered on Western Digital My Cloud Devices that could al...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now