2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-1165 | CRITICAL | 9.1 | 1.6% | Apr 4, 2022 | The Blackhole for Bad Bots WordPress plugin before 3.3.2 uses headers such as CF-CONNECTING-IP, CLIENT-IP etc to determi... |
| CVE-2022-0939 | CRITICAL | 9.9 | 1.0% | Apr 4, 2022 | Server-Side Request Forgery (SSRF) in GitHub repository janeczku/calibre-web prior to 0.6.18. |
| CVE-2022-26530 | CRITICAL | 9.1 | 1.5% | Apr 3, 2022 | swaylock before 1.6 allows attackers to trigger a crash and achieve unlocked access to a Wayland compositor. |
| CVE-2022-28381 | CRITICAL | 9.8 | 68.7% | Apr 3, 2022 | Mediaserver.exe in ALLMediaServer 1.6 has a stack-based buffer overflow that allows remote attackers to execute arbitrar... |
| CVE-2022-28368 | CRITICAL | 9.8 | 82.4% | Apr 3, 2022 | Dompdf 1.2.1 allows remote code execution via a .php file in the src:url field of an @font-face Cascading Style Sheets (... |
| CVE-2022-27534 | CRITICAL | 9.8 | 3.0% | Apr 1, 2022 | Kaspersky Anti-Virus products for home and Kaspersky Endpoint Security with antivirus databases released before 12 March... |
| CVE-2022-27177 | CRITICAL | 9.8 | 2.1% | Apr 1, 2022 | A Python format string issue leading to information disclosure and potentially remote code execution in ConsoleMe for al... |
| CVE-2022-25158 | CRITICAL | 9.1 | 1.3% | Apr 1, 2022 | Cleartext Storage of Sensitive Information vulnerability in Mitsubishi Electric MELSEC iQ-F series FX5U(C) CPU all versi... |
| CVE-2022-25157 | CRITICAL | 9.1 | 2.3% | Apr 1, 2022 | Use of Password Hash Instead of Password for Authentication vulnerability in Mitsubishi Electric MELSEC iQ-F series FX5U... |
| CVE-2022-22965 | CRITICAL | 9.8 | 99.7% | Apr 1, 2022 | A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b... |
| CVE-2022-22963 | CRITICAL | 9.8 | 99.9% | Apr 1, 2022 | In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is po... |
| CVE-2022-22570 | CRITICAL | 10 | 1.0% | Apr 1, 2022 | A buffer overflow vulnerability found in the UniFi Door Access Reader Lite’s (UA Lite) firmware (Version 3.8.28.24 and e... |
| CVE-2022-26562 | CRITICAL | 9.8 | 2.1% | Apr 1, 2022 | An issue in provider/libserver/ECKrbAuth.cpp of Kopano Core <= v11.0.2.51 contains an issue which allows attackers to au... |
| CVE-2022-24066 | CRITICAL | 9.8 | 4.1% | Apr 1, 2022 | The package simple-git before 3.5.0 are vulnerable to Command Injection due to an incomplete fix of [CVE-2022-24433](htt... |
| CVE-2022-24440 | CRITICAL | 9.8 | 2.7% | Apr 1, 2022 | The package cocoapods-downloader before 1.6.0, from 1.6.2 and before 1.6.3 are vulnerable to Command Injection via git a... |
| CVE-2022-21223 | CRITICAL | 9.8 | 1.8% | Apr 1, 2022 | The package cocoapods-downloader before 1.6.2 are vulnerable to Command Injection via hg argument injection. When callin... |
| CVE-2022-21235 | CRITICAL | 9.8 | 1.8% | Apr 1, 2022 | The package github.com/masterminds/vcs before 1.13.3 are vulnerable to Command Injection via argument injection. When hg... |
| CVE-2022-24803 | CRITICAL | 9.8 | 2.7% | Apr 1, 2022 | Asciidoctor-include-ext is Asciidoctor’s standard include processor reimplemented as an extension. Versions prior to 0.4... |
| CVE-2022-24802 | CRITICAL | 9.8 | 1.6% | Apr 1, 2022 | deepmerge-ts is a typescript library providing functionality to deep merging of javascript objects. deepmerge-ts is vuln... |
| CVE-2022-24797 | CRITICAL | 9.1 | 1.3% | Mar 31, 2022 | Pomerium is an identity-aware access proxy. In distributed service mode, Pomerium's Authenticate service exposes pprof d... |
| CVE-2022-24796 | CRITICAL | 9.8 | 3.5% | Mar 31, 2022 | RaspberryMatic is a free and open-source operating system for running a cloud-free smart-home using the homematicIP / Ho... |
| CVE-2022-24791 | CRITICAL | 9.8 | 1.1% | Mar 31, 2022 | Wasmtime is a standalone JIT-style runtime for WebAssembly, using Cranelift. There is a use after free vulnerability in ... |
| CVE-2022-26546 | CRITICAL | 9.1 | 1.4% | Mar 31, 2022 | Hospital Management System v1.0 was discovered to lack an authorization component, allowing attackers to access sensitiv... |
| CVE-2022-24136 | CRITICAL | 9.8 | 1.9% | Mar 31, 2022 | Hospital Management System v1.0 is affected by an unrestricted upload of dangerous file type vulerability in treatmentre... |
| CVE-2022-26646 | CRITICAL | 9.8 | 1.3% | Mar 30, 2022 | Online Banking System Protect v1.0 was discovered to contain a local file inclusion (LFI) vulnerability via the pages pa... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now