2022 CVE Vulnerabilities

27,554 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-21651MEDIUM6.1Shopware is an open source e-commerce software platform. An open redirect vulnerability has been discovered. Users may b...
CVE-2022-21642MEDIUM4.3Discourse is an open source platform for community discussion. In affected versions when composing a message from topic ...
CVE-2022-22111HIGH8.8In DayByDay CRM, version 2.2.0 is vulnerable to missing authorization. Any application user in the application who has u...
CVE-2022-22110HIGH7.5In Daybyday CRM, versions 1.1 through 2.2.0 enforce weak password requirements in the user update functionality. A user ...
CVE-2022-22109MEDIUM5.4In Daybyday CRM, version 2.2.0 is vulnerable to Stored Cross-Site Scripting (XSS) vulnerability that allows low privileg...
CVE-2022-22108MEDIUM4.3In Daybyday CRM, versions 2.0.0 through 2.2.0 are vulnerable to Missing Authorization. An attacker that has the lowest p...
CVE-2022-22107MEDIUM4.3In Daybyday CRM, versions 2.0.0 through 2.2.0 are vulnerable to Missing Authorization. An attacker that has the lowest p...
CVE-2022-21650MEDIUM5.4Convos is an open source multi-user chat that runs in a web browser. You can't use SVG extension in Convos' chat window,...
CVE-2022-21649MEDIUM5.4Convos is an open source multi-user chat that runs in a web browser. Characters starting with "https://" in the chat win...
CVE-2022-21648MEDIUM6.1Latte is an open source template engine for PHP. Versions since 2.8.0 Latte has included a template sandbox and in affec...
CVE-2022-21647CRITICAL9.8CodeIgniter is an open source PHP full-stack web framework. Deserialization of Untrusted Data was found in the `old()` f...
CVE-2022-21644HIGH7.2USOC is an open source CMS with a focus on simplicity. In affected versions USOC allows for SQL injection via usersearch...
CVE-2022-21643CRITICAL9.8USOC is an open source CMS with a focus on simplicity. In affected versions USOC allows for SQL injection via register.p...
CVE-2022-0086CRITICAL9.8uppy is vulnerable to Server-Side Request Forgery (SSRF)
CVE-2022-20023MEDIUM6.5In Bluetooth, there is a possible application crash due to bluetooth flooding a device with LMP_AU_rand packet. This cou...
CVE-2022-20022MEDIUM6.5In Bluetooth, there is a possible link disconnection due to bluetooth does not properly handle a connection attempt from...
CVE-2022-20021MEDIUM6.5In Bluetooth, there is a possible application crash due to bluetooth does not properly handle the reception of multiple ...
CVE-2022-20020MEDIUM5.5In libvcodecdrv, there is a possible information disclosure due to a missing bounds check. This could lead to local info...
CVE-2022-20019MEDIUM5.5In libMtkOmxGsmDec, there is a possible information disclosure due to an incorrect bounds check. This could lead to loca...
CVE-2022-20018MEDIUM4.4In seninf driver, there is a possible information disclosure due to uninitialized data. This could lead to local informa...
CVE-2022-20016MEDIUM6.7In vow driver, there is a possible memory corruption due to improper locking. This could lead to local escalation of pri...
CVE-2022-20015MEDIUM4.4In kd_camera_hw driver, there is a possible information disclosure due to uninitialized data. This could lead to local i...
CVE-2022-20014MEDIUM6.7In vow driver, there is a possible memory corruption due to improper input validation. This could lead to local escalati...
CVE-2022-20013MEDIUM6.4In vow driver, there is a possible memory corruption due to a race condition. This could lead to local escalation of pri...
CVE-2022-20012HIGH7.8In mdp driver, there is a possible memory corruption due to an integer overflow. This could lead to local escalation of ...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now