2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-23865 | CRITICAL | 9.8 | 1.5% | Apr 15, 2022 | Nyron 1.0 is affected by a SQL injection vulnerability through Nyron/Library/Catalog/winlibsrch.aspx. To exploit this vu... |
| CVE-2022-20695 | CRITICAL | 10 | 19.2% | Apr 15, 2022 | A vulnerability in the authentication functionality of Cisco Wireless LAN Controller (WLC) Software could allow an unaut... |
| CVE-2022-28044 | CRITICAL | 9.8 | 1.8% | Apr 15, 2022 | Irzip v0.640 was discovered to contain a heap memory corruption via the component lrzip.c:initialise_control. |
| CVE-2022-26651 | CRITICAL | 9.8 | 6.6% | Apr 15, 2022 | An issue was discovered in Asterisk through 19.x and Certified Asterisk through 16.8-cert13. The func_odbc module provid... |
| CVE-2022-26499 | CRITICAL | 9.1 | 7.3% | Apr 15, 2022 | An SSRF issue was discovered in Asterisk through 19.x. When using STIR/SHAKEN, it's possible to send arbitrary requests ... |
| CVE-2022-26034 | CRITICAL | 9.1 | 0.9% | Apr 15, 2022 | Improper authentication vulnerability in the communication protocol provided by AD (Automation Design) server of CENTUM ... |
| CVE-2022-28711 | CRITICAL | 9.8 | 1.6% | Apr 14, 2022 | A memory corruption vulnerability exists in the cgi.c unescape functionality of ArduPilot APWeb master branch 50b6b7ac -... |
| CVE-2022-27007 | CRITICAL | 9.8 | 1.5% | Apr 14, 2022 | nginx njs 0.7.2 is affected suffers from Use-after-free in njs_function_frame_alloc() when it try to invoke from a resto... |
| CVE-2022-26507 | CRITICAL | 9.8 | 2.2% | Apr 14, 2022 | A heap-based buffer overflow exists in XML Decompression DecodeTreeBlock in AT&T Labs Xmill 0.7. A crafted input file ca... |
| CVE-2022-24845 | CRITICAL | 9.8 | 1.3% | Apr 13, 2022 | Vyper is a pythonic Smart Contract Language for the ethereum virtual machine. In affected versions, the return of `<ifac... |
| CVE-2022-24816 | CRITICAL | 10 | 98.7% | Apr 13, 2022 | JAI-EXT is an open-source project which aims to extend the Java Advanced Imaging (JAI) API. Programs allowing Jiffle scr... |
| CVE-2022-27479 | CRITICAL | 9.8 | 2.7% | Apr 13, 2022 | Apache Superset before 1.4.2 is vulnerable to SQL injection in chart data requests. Users should update to 1.4.2 or high... |
| CVE-2022-24788 | CRITICAL | 9.8 | 0.9% | Apr 13, 2022 | Vyper is a pythonic Smart Contract Language for the ethereum virtual machine. Versions of vyper prior to 0.3.2 suffer fr... |
| CVE-2022-1345 | CRITICAL | 9 | 1.0% | Apr 13, 2022 | Stored XSS viva .svg file upload in GitHub repository causefx/organizr prior to 2.1.1810. This allows attackers to execu... |
| CVE-2022-22956 | CRITICAL | 9.8 | 49.9% | Apr 13, 2022 | VMware Workspace ONE Access has two authentication bypass vulnerabilities (CVE-2022-22955 & CVE-2022-22956) in the OAuth... |
| CVE-2022-22955 | CRITICAL | 9.8 | 7.6% | Apr 13, 2022 | VMware Workspace ONE Access has two authentication bypass vulnerabilities (CVE-2022-22955 & CVE-2022-22956) in the OAuth... |
| CVE-2022-1346 | CRITICAL | 9 | 1.0% | Apr 13, 2022 | Multiple Stored XSS in GitHub repository causefx/organizr prior to 2.1.1810. This allows attackers to execute malicious ... |
| CVE-2022-1344 | CRITICAL | 9 | 1.0% | Apr 13, 2022 | Stored XSS due to no sanitization in the filename in GitHub repository causefx/organizr prior to 2.1.1810. This allows a... |
| CVE-2022-22561 | CRITICAL | 9.8 | 1.3% | Apr 12, 2022 | Dell PowerScale OneFS, versions 8.2.x-9.3.0.x, contain an improper restriction of excessive authentication attempts. An ... |
| CVE-2022-28397 | CRITICAL | 9.8 | 3.4% | Apr 12, 2022 | An arbitrary file upload vulnerability in the file upload module of Ghost CMS v4.42.0 allows attackers to execute arbitr... |
| CVE-2022-27952 | CRITICAL | 9.8 | 2.1% | Apr 12, 2022 | An arbitrary file upload vulnerability in the file upload module of PayloadCMS v0.15.0 allows attackers to execute arbit... |
| CVE-2022-27263 | CRITICAL | 9.8 | 3.1% | Apr 12, 2022 | An arbitrary file upload vulnerability in the file upload module of Strapi v4.1.5 allows attackers to execute arbitrary ... |
| CVE-2022-27262 | CRITICAL | 9.8 | 2.1% | Apr 12, 2022 | An arbitrary file upload vulnerability in the file upload module of Skipper v0.9.1 allows attackers to execute arbitrary... |
| CVE-2022-27260 | CRITICAL | 9.8 | 3.0% | Apr 12, 2022 | An arbitrary file upload vulnerability in the file upload component of ButterCMS v1.2.8 allows attackers to execute arbi... |
| CVE-2022-27140 | CRITICAL | 9.8 | 2.6% | Apr 12, 2022 | An arbitrary file upload vulnerability in the file upload module of express-fileupload 1.3.1 allows attackers to execute... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now