2022 CVE Vulnerabilities
27,554 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-21651 | MEDIUM | 6.1 | 0.8% | Jan 5, 2022 | Shopware is an open source e-commerce software platform. An open redirect vulnerability has been discovered. Users may b... |
| CVE-2022-21642 | MEDIUM | 4.3 | 0.7% | Jan 5, 2022 | Discourse is an open source platform for community discussion. In affected versions when composing a message from topic ... |
| CVE-2022-22111 | HIGH | 8.8 | 1.0% | Jan 5, 2022 | In DayByDay CRM, version 2.2.0 is vulnerable to missing authorization. Any application user in the application who has u... |
| CVE-2022-22110 | HIGH | 7.5 | 1.1% | Jan 5, 2022 | In Daybyday CRM, versions 1.1 through 2.2.0 enforce weak password requirements in the user update functionality. A user ... |
| CVE-2022-22109 | MEDIUM | 5.4 | 0.5% | Jan 5, 2022 | In Daybyday CRM, version 2.2.0 is vulnerable to Stored Cross-Site Scripting (XSS) vulnerability that allows low privileg... |
| CVE-2022-22108 | MEDIUM | 4.3 | 0.7% | Jan 5, 2022 | In Daybyday CRM, versions 2.0.0 through 2.2.0 are vulnerable to Missing Authorization. An attacker that has the lowest p... |
| CVE-2022-22107 | MEDIUM | 4.3 | 0.7% | Jan 5, 2022 | In Daybyday CRM, versions 2.0.0 through 2.2.0 are vulnerable to Missing Authorization. An attacker that has the lowest p... |
| CVE-2022-21650 | MEDIUM | 5.4 | 0.8% | Jan 4, 2022 | Convos is an open source multi-user chat that runs in a web browser. You can't use SVG extension in Convos' chat window,... |
| CVE-2022-21649 | MEDIUM | 5.4 | 0.9% | Jan 4, 2022 | Convos is an open source multi-user chat that runs in a web browser. Characters starting with "https://" in the chat win... |
| CVE-2022-21648 | MEDIUM | 6.1 | 0.8% | Jan 4, 2022 | Latte is an open source template engine for PHP. Versions since 2.8.0 Latte has included a template sandbox and in affec... |
| CVE-2022-21647 | CRITICAL | 9.8 | 37.7% | Jan 4, 2022 | CodeIgniter is an open source PHP full-stack web framework. Deserialization of Untrusted Data was found in the `old()` f... |
| CVE-2022-21644 | HIGH | 7.2 | 1.0% | Jan 4, 2022 | USOC is an open source CMS with a focus on simplicity. In affected versions USOC allows for SQL injection via usersearch... |
| CVE-2022-21643 | CRITICAL | 9.8 | 1.2% | Jan 4, 2022 | USOC is an open source CMS with a focus on simplicity. In affected versions USOC allows for SQL injection via register.p... |
| CVE-2022-0086 | CRITICAL | 9.8 | 1.2% | Jan 4, 2022 | uppy is vulnerable to Server-Side Request Forgery (SSRF) |
| CVE-2022-20023 | MEDIUM | 6.5 | 0.3% | Jan 4, 2022 | In Bluetooth, there is a possible application crash due to bluetooth flooding a device with LMP_AU_rand packet. This cou... |
| CVE-2022-20022 | MEDIUM | 6.5 | 0.3% | Jan 4, 2022 | In Bluetooth, there is a possible link disconnection due to bluetooth does not properly handle a connection attempt from... |
| CVE-2022-20021 | MEDIUM | 6.5 | 0.3% | Jan 4, 2022 | In Bluetooth, there is a possible application crash due to bluetooth does not properly handle the reception of multiple ... |
| CVE-2022-20020 | MEDIUM | 5.5 | 0.1% | Jan 4, 2022 | In libvcodecdrv, there is a possible information disclosure due to a missing bounds check. This could lead to local info... |
| CVE-2022-20019 | MEDIUM | 5.5 | 0.1% | Jan 4, 2022 | In libMtkOmxGsmDec, there is a possible information disclosure due to an incorrect bounds check. This could lead to loca... |
| CVE-2022-20018 | MEDIUM | 4.4 | 0.1% | Jan 4, 2022 | In seninf driver, there is a possible information disclosure due to uninitialized data. This could lead to local informa... |
| CVE-2022-20016 | MEDIUM | 6.7 | 0.1% | Jan 4, 2022 | In vow driver, there is a possible memory corruption due to improper locking. This could lead to local escalation of pri... |
| CVE-2022-20015 | MEDIUM | 4.4 | 0.1% | Jan 4, 2022 | In kd_camera_hw driver, there is a possible information disclosure due to uninitialized data. This could lead to local i... |
| CVE-2022-20014 | MEDIUM | 6.7 | 0.1% | Jan 4, 2022 | In vow driver, there is a possible memory corruption due to improper input validation. This could lead to local escalati... |
| CVE-2022-20013 | MEDIUM | 6.4 | 0.1% | Jan 4, 2022 | In vow driver, there is a possible memory corruption due to a race condition. This could lead to local escalation of pri... |
| CVE-2022-20012 | HIGH | 7.8 | 0.1% | Jan 4, 2022 | In mdp driver, there is a possible memory corruption due to an integer overflow. This could lead to local escalation of ... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now