2022 CVE Vulnerabilities
27,554 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-0408 | HIGH | 7.8 | 1.5% | Jan 30, 2022 | Stack-based Buffer Overflow in GitHub repository vim/vim prior to 8.2. |
| CVE-2022-0407 | HIGH | 7.8 | 1.2% | Jan 30, 2022 | Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2. |
| CVE-2022-0339 | CRITICAL | 9.8 | 1.0% | Jan 30, 2022 | Server-Side Request Forgery (SSRF) in Pypi calibreweb prior to 0.6.16. |
| CVE-2022-0273 | MEDIUM | 6.5 | 0.7% | Jan 30, 2022 | Improper Access Control in Pypi calibreweb prior to 0.6.16. |
| CVE-2022-22919 | MEDIUM | 6.1 | 0.6% | Jan 30, 2022 | Adenza AxiomSL ControllerView through 10.8.1 allows redirection for SSO login URLs. |
| CVE-2022-24032 | MEDIUM | 5.3 | 1.0% | Jan 30, 2022 | Adenza AxiomSL ControllerView through 10.8.1 is vulnerable to user enumeration. An attacker can identify valid usernames... |
| CVE-2022-24124 | HIGH | 7.5 | 58.9% | Jan 29, 2022 | The query API in Casdoor before 1.13.1 has a SQL injection vulnerability related to the field and value parameters, as d... |
| CVE-2022-24123 | CRITICAL | 9 | 1.9% | Jan 29, 2022 | MarkText through 0.16.3 does not sanitize the input of a mermaid block before rendering. This could lead to Remote Code ... |
| CVE-2022-24122 | HIGH | 7.8 | 1.0% | Jan 29, 2022 | kernel/ucount.c in the Linux kernel 5.14 through 5.16.4, when unprivileged user namespaces are enabled, allows a use-aft... |
| CVE-2022-23599 | MEDIUM | 6.1 | 0.7% | Jan 28, 2022 | Products.ATContentTypes are the core content types for Plone 2.1 - 4.3. Versions of Plone that are dependent on Products... |
| CVE-2022-23598 | MEDIUM | 6.1 | 1.0% | Jan 28, 2022 | laminas-form is a package for validating and displaying simple and complex forms. When rendering validation error messag... |
| CVE-2022-21721 | HIGH | 7.5 | 2.2% | Jan 28, 2022 | Next.js is a React framework. Starting with version 12.0.0 and prior to version 12.0.9, vulnerable code could allow a ba... |
| CVE-2022-0395 | MEDIUM | 5.4 | 0.6% | Jan 28, 2022 | Cross-site Scripting (XSS) - Stored in Packagist remdex/livehelperchat prior to 3.93v. |
| CVE-2022-0393 | HIGH | 7.1 | 1.4% | Jan 28, 2022 | Out-of-bounds Read in GitHub repository vim/vim prior to 8.2. |
| CVE-2022-0392 | HIGH | 7.8 | 1.5% | Jan 28, 2022 | Heap-based Buffer Overflow in GitHub repository vim prior to 8.2. |
| CVE-2022-0352 | MEDIUM | 6.1 | 0.9% | Jan 28, 2022 | Cross-site Scripting (XSS) - Reflected in Pypi calibreweb prior to 0.6.16. |
| CVE-2022-23889 | MEDIUM | 5.3 | 1.1% | Jan 28, 2022 | The comment function in YzmCMS v6.3 was discovered as being able to be operated concurrently, allowing attackers to crea... |
| CVE-2022-23888 | HIGH | 8.8 | 0.8% | Jan 28, 2022 | YzmCMS v6.3 was discovered to contain a Cross-Site Request Forgey (CSRF) via the component /yzmcms/comment/index/init.ht... |
| CVE-2022-23887 | MEDIUM | 6.5 | 0.7% | Jan 28, 2022 | YzmCMS v6.3 was discovered to contain a Cross-Site Request Forgery (CSRF) which allows attackers to arbitrarily delete u... |
| CVE-2022-23979 | MEDIUM | 4.8 | 0.6% | Jan 28, 2022 | Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability discovered in Ultimate Reviews WordPress plugin (... |
| CVE-2022-23727 | HIGH | 7.8 | 0.2% | Jan 28, 2022 | There is a privilege escalation vulnerability in some webOS TVs. Due to wrong setting environments, local attacker is ab... |
| CVE-2022-23456 | MEDIUM | 5.5 | 0.3% | Jan 28, 2022 | Potential arbitrary file deletion vulnerability has been identified in HP Support Assistant software. |
| CVE-2022-22994 | CRITICAL | 9.8 | 1.9% | Jan 28, 2022 | A remote code execution vulnerability was discovered on Western Digital My Cloud devices where an attacker could trick a... |
| CVE-2022-22993 | HIGH | 8.8 | 0.8% | Jan 28, 2022 | A limited SSRF vulnerability was discovered on Western Digital My Cloud devices that could allow an attacker to imperson... |
| CVE-2022-22992 | CRITICAL | 9.8 | 2.3% | Jan 28, 2022 | A command injection remote code execution vulnerability was discovered on Western Digital My Cloud Devices that could al... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now