2022 CVE Vulnerabilities

27,554 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-22789HIGH7.8Charactell - FormStorm Enterprise Account takeover – An attacker can modify (add, remove and update) passwords file for ...
CVE-2022-0335HIGH8.8A flaw was found in Moodle in versions 3.11 to 3.11.4, 3.10 to 3.10.8, 3.9 to 3.9.11 and earlier unsupported versions. T...
CVE-2022-0334MEDIUM4.3A flaw was found in Moodle in versions 3.11 to 3.11.4, 3.10 to 3.10.8, 3.9 to 3.9.11 and earlier unsupported versions. I...
CVE-2022-0333LOW3.8A flaw was found in Moodle in versions 3.11 to 3.11.4, 3.10 to 3.10.8, 3.9 to 3.9.11 and earlier unsupported versions. T...
CVE-2022-0332CRITICAL9.8A flaw was found in Moodle in versions 3.11 to 3.11.4. An SQL injection risk was identified in the h5p activity web serv...
CVE-2022-0270HIGH8.8Prior to v0.6.1, bored-agent failed to sanitize incoming kubernetes impersonation headers allowing a user to override as...
CVE-2022-0351HIGH7.8Access of Memory Location Before Start of Buffer in GitHub repository vim/vim prior to 8.2.
CVE-2022-23035MEDIUM4.6Insufficient cleanup of passed-through device IRQs The management of IRQs associated with physical devices exposed to x8...
CVE-2022-23034MEDIUM5.5A PV guest could DoS Xen while unmapping a grant To address XSA-380, reference counting was introduced for grant mapping...
CVE-2022-23033HIGH7.8arm: guest_physmap_remove_page not removing the p2m mappings The functions to remove one or more entries from a guest p2...
CVE-2022-21697HIGH7.1Jupyter Server Proxy is a Jupyter notebook server extension to proxy web services. Versions of Jupyter Server Proxy prio...
CVE-2022-23945HIGH7.5Missing authentication on ShenYu Admin when register by HTTP. This issue affected Apache ShenYu 2.4.0 and 2.4.1.
CVE-2022-23944CRITICAL9.1User can access /plugin api without authentication. This issue affected Apache ShenYu 2.4.0 and 2.4.1.
CVE-2022-23223HIGH7.5On Apache ShenYu versions 2.4.0 and 2.4.1, and endpoint existed that disclosed the passwords of all users. Users are rec...
CVE-2022-0268MEDIUM5.4Cross-site Scripting (XSS) - Stored in Packagist getgrav/grav prior to 1.7.28.
CVE-2022-0338MEDIUM4.3Insertion of Sensitive Information into Log File in Conda loguru prior to 0.5.3.
CVE-2022-23935HIGH7.8lib/Image/ExifTool.pm in ExifTool before 12.38 mishandles a $file =~ /\|$/ check, leading to command injection.
CVE-2022-0177Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. Reason: This CVE has been rejected as it was incorrectly assigned. Al...
CVE-2022-22554MEDIUM5.5Dell EMC System Update, version 1.9.2 and prior, contain an Unprotected Storage of Credentials vulnerability. A local at...
CVE-2022-21715MEDIUM6.1CodeIgniter4 is the 4.x branch of CodeIgniter, a PHP full-stack web framework. A cross-site scripting (XSS) vulnerabilit...
CVE-2022-21711HIGH7.1elfspirit is an ELF static analysis and injection framework that parses, manipulates, and camouflages ELF files. When an...
CVE-2022-21710MEDIUM6.1ShortDescription is a MediaWiki extension that provides local short description support. A cross-site scripting (XSS) vu...
CVE-2022-23126CRITICAL9.8TeslaMate before 1.25.1 (when using the default Docker configuration) allows attackers to open doors of Tesla vehicles, ...
CVE-2022-23437MEDIUM6.5There's a vulnerability within the Apache Xerces Java (XercesJ) XML parser when handling specially crafted XML document ...
CVE-2022-22296MEDIUM5.3Sourcecodester Hospital's Patient Records Management System 1.0 is vulnerable to Insecure Permissions via the id paramet...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now