2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-24307 | CRITICAL | 9.8 | 1.4% | Feb 3, 2022 | Mastodon before 3.3.2 and 3.4.x before 3.4.6 has incorrect access control because it does not compact incoming signed JS... |
| CVE-2022-23357 | CRITICAL | 9.1 | 19.9% | Feb 3, 2022 | mozilo2.0 was discovered to be vulnerable to directory traversal attacks via the parameter curent_dir. |
| CVE-2022-21817 | CRITICAL | 9.3 | 2.0% | Feb 2, 2022 | NVIDIA Omniverse Launcher contains a Cross-Origin Resource Sharing (CORS) vulnerability which can allow an unprivileged ... |
| CVE-2022-21724 | CRITICAL | 9.8 | 3.0% | Feb 2, 2022 | pgjdbc is the offical PostgreSQL JDBC Driver. A security hole was found in the jdbc driver for postgresql database while... |
| CVE-2022-24300 | CRITICAL | 9.8 | 1.7% | Feb 2, 2022 | Minetest before 5.4.0 allows attackers to add or modify arbitrary meta fields of the same item stack as saved user input... |
| CVE-2022-24223 | CRITICAL | 9.8 | 62.0% | Feb 1, 2022 | AtomCMS v2.0 was discovered to contain a SQL injection vulnerability via /admin/login.php. |
| CVE-2022-24222 | CRITICAL | 9.8 | 1.1% | Feb 1, 2022 | eliteCMS v1.0 was discovered to contain a SQL injection vulnerability via /admin/edit_user.php. |
| CVE-2022-24221 | CRITICAL | 9.8 | 1.1% | Feb 1, 2022 | eliteCMS v1.0 was discovered to contain a SQL injection vulnerability via /admin/functions/functions.php. |
| CVE-2022-24220 | CRITICAL | 9.8 | 1.1% | Feb 1, 2022 | eliteCMS v1.0 was discovered to contain a SQL injection vulnerability via /admin/edit_post.php. |
| CVE-2022-24219 | CRITICAL | 9.8 | 1.1% | Feb 1, 2022 | eliteCMS v1.0 was discovered to contain a SQL injection vulnerability via /admin/edit_page.php. |
| CVE-2022-24218 | CRITICAL | 9.1 | 17.0% | Feb 1, 2022 | An issue in /admin/delete_image.php of eliteCMS v1.0 allows attackers to delete arbitrary files. |
| CVE-2022-0401 | CRITICAL | 9.8 | 1.6% | Feb 1, 2022 | Path Traversal in NPM w-zip prior to 1.0.12. |
| CVE-2022-0320 | CRITICAL | 9.8 | 2.0% | Feb 1, 2022 | The Essential Addons for Elementor WordPress plugin before 5.0.5 does not validate and sanitise some template data befor... |
| CVE-2022-24263 | CRITICAL | 9.8 | 8.2% | Jan 31, 2022 | Hospital Management System v4.0 was discovered to contain a SQL injection vulnerability in /Hospital-Management-System-m... |
| CVE-2022-0339 | CRITICAL | 9.8 | 1.0% | Jan 30, 2022 | Server-Side Request Forgery (SSRF) in Pypi calibreweb prior to 0.6.16. |
| CVE-2022-24123 | CRITICAL | 9 | 1.9% | Jan 29, 2022 | MarkText through 0.16.3 does not sanitize the input of a mermaid block before rendering. This could lead to Remote Code ... |
| CVE-2022-22994 | CRITICAL | 9.8 | 1.9% | Jan 28, 2022 | A remote code execution vulnerability was discovered on Western Digital My Cloud devices where an attacker could trick a... |
| CVE-2022-22992 | CRITICAL | 9.8 | 2.3% | Jan 28, 2022 | A command injection remote code execution vulnerability was discovered on Western Digital My Cloud Devices that could al... |
| CVE-2022-21217 | CRITICAL | 9.8 | 1.4% | Jan 28, 2022 | An out-of-bounds write vulnerability exists in the device TestEmail functionality of reolink RLC-410W v3.0.0.136_2012110... |
| CVE-2022-22294 | CRITICAL | 9.8 | 1.1% | Jan 28, 2022 | A SQL injection vulnerability exists in ZFAKA<=1.43 which an attacker can use to complete SQL injection in the foregroun... |
| CVE-2022-23097 | CRITICAL | 9.1 | 2.4% | Jan 28, 2022 | An issue was discovered in the DNS proxy in Connman through 1.40. forward_dns_reply mishandles a strnlen call, leading t... |
| CVE-2022-23096 | CRITICAL | 9.1 | 2.6% | Jan 28, 2022 | An issue was discovered in the DNS proxy in Connman through 1.40. The TCP server reply implementation lacks a check for ... |
| CVE-2022-21723 | CRITICAL | 9.1 | 4.5% | Jan 27, 2022 | PJSIP is a free and open source multimedia communication library written in C language implementing standard based proto... |
| CVE-2022-21722 | CRITICAL | 9.1 | 2.4% | Jan 27, 2022 | PJSIP is a free and open source multimedia communication library written in C language implementing standard based proto... |
| CVE-2022-21686 | CRITICAL | 9.8 | 1.8% | Jan 26, 2022 | PrestaShop is an Open Source e-commerce platform. Starting with version 1.7.0.0 and ending with version 1.7.8.3, an atta... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now