2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-24755 | CRITICAL | 9.8 | 2.0% | Mar 15, 2022 | Bareos is open source software for backup, archiving, and recovery of data for operating systems. When Bareos Director >... |
| CVE-2022-24752 | CRITICAL | 9.8 | 1.3% | Mar 15, 2022 | SyliusGridBundle is a package of generic data grids for Symfony applications. Prior to versions 1.10.1 and 1.11-rc2, val... |
| CVE-2022-26320 | CRITICAL | 9.1 | 0.9% | Mar 14, 2022 | The Rambus SafeZone Basic Crypto Module before 10.4.0, as used in certain Fujifilm (formerly Fuji Xerox) devices before ... |
| CVE-2022-21187 | CRITICAL | 9.8 | 3.7% | Mar 14, 2022 | The package libvcs before 0.11.1 are vulnerable to Command Injection via argument injection. When calling the update_rep... |
| CVE-2022-0658 | CRITICAL | 9.8 | 8.9% | Mar 14, 2022 | The CommonsBooking WordPress plugin before 2.6.8 does not sanitise and escape the location parameter of the calendar_dat... |
| CVE-2022-0254 | CRITICAL | 9.8 | 2.0% | Mar 14, 2022 | The WordPress Zero Spam WordPress plugin before 5.2.11 does not properly sanitise and escape the order and orderby param... |
| CVE-2022-0169 | CRITICAL | 9.8 | 74.6% | Mar 14, 2022 | The Photo Gallery by 10Web WordPress plugin before 1.6.0 does not validate and escape the bwg_tag_id_bwg_thumbnails_0 pa... |
| CVE-2022-23943 | CRITICAL | 9.8 | 50.4% | Mar 14, 2022 | Out-of-bounds Write vulnerability in mod_sed of Apache HTTP Server allows an attacker to overwrite heap memory with poss... |
| CVE-2022-22721 | CRITICAL | 9.1 | 41.9% | Mar 14, 2022 | If LimitXMLRequestBody is set to allow request bodies larger than 350MB (defaults to 1M) on 32 bit systems an integer ov... |
| CVE-2022-22720 | CRITICAL | 9.8 | 28.2% | Mar 14, 2022 | Apache HTTP Server 2.4.52 and earlier fails to close inbound connection when errors are encountered discarding the reque... |
| CVE-2022-24760 | CRITICAL | 10 | 49.1% | Mar 12, 2022 | Parse Server is an open source http web server backend. In versions prior to 4.10.7 there is a Remote Code Execution (RC... |
| CVE-2022-24754 | CRITICAL | 9.8 | 2.0% | Mar 11, 2022 | PJSIP is a free and open source multimedia communication library written in C language. In versions prior to and includi... |
| CVE-2022-25621 | CRITICAL | 9.8 | 1.4% | Mar 11, 2022 | UUNIVERGE WA 1020 Ver8.2.11 and prior, UNIVERGE WA 1510 Ver8.2.11 and prior, UNIVERGE WA 1511 Ver8.2.11 and prior, UNIVE... |
| CVE-2022-23730 | CRITICAL | 9.8 | 1.0% | Mar 11, 2022 | The public API error causes for the attacker to be able to bypass API access control. |
| CVE-2022-24433 | CRITICAL | 9.8 | 3.5% | Mar 11, 2022 | The package simple-git before 3.3.0 are vulnerable to Command Injection via argument injection. When calling the .fetch(... |
| CVE-2022-0860 | CRITICAL | 9.1 | 2.3% | Mar 11, 2022 | Improper Authorization in GitHub repository cobbler/cobbler prior to 3.3.2. |
| CVE-2022-0871 | CRITICAL | 9.1 | 1.4% | Mar 11, 2022 | Missing Authorization in GitHub repository gogs/gogs prior to 0.12.5. |
| CVE-2022-23402 | CRITICAL | 9.8 | 1.0% | Mar 11, 2022 | The following Yokogawa Electric products hard-code the password for CAMS server applications: CENTUM VP versions from R5... |
| CVE-2022-21194 | CRITICAL | 9.8 | 0.9% | Mar 11, 2022 | The following Yokogawa Electric products do not change the passwords of the internal Windows accounts from the initial c... |
| CVE-2022-26520 | CRITICAL | 9.8 | 2.9% | Mar 10, 2022 | In pgjdbc before 42.3.3, an attacker (who controls the jdbc URL or properties) can call java.util.logging.FileHandler to... |
| CVE-2022-26143 | CRITICAL | 9.8 | 87.6% | Mar 10, 2022 | The TP-240 (aka tp240dvr) component in Mitel MiCollab before 9.4 SP1 FP1 and MiVoice Business Express through 8.1 allows... |
| CVE-2022-26131 | CRITICAL | 9.8 | 1.3% | Mar 10, 2022 | Power Line Communications PLC4TRUCKS J2497 trailer receivers are susceptible to remote RF induced signals. |
| CVE-2022-26100 | CRITICAL | 9.8 | 1.1% | Mar 10, 2022 | SAPCAR - version 7.22, does not contain sufficient input validation on the SAPCAR archive. As a result, the SAPCAR proce... |
| CVE-2022-25922 | CRITICAL | 9.1 | 1.1% | Mar 10, 2022 | Power Line Communications PLC4TRUCKS J2497 trailer brake controllers implement diagnostic functions which can be invoked... |
| CVE-2022-25818 | CRITICAL | 9.8 | 0.4% | Mar 10, 2022 | Improper boundary check in UWB stack prior to SMR Mar-2022 Release 1 allows arbitrary code execution. |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now