2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2022-21855CRITICAL9Microsoft Exchange Server Remote Code Execution Vulnerability
CVE-2022-21849CRITICAL9.8Windows Internet Key Exchange (IKE) Protocol Extensions Remote Code Execution Vulnerability
CVE-2022-21846CRITICAL9Microsoft Exchange Server Remote Code Execution Vulnerability
CVE-2022-22115CRITICAL9In Teedy, versions v1.5 through v1.9 are vulnerable to Stored Cross-Site Scripting (XSS) in the name of a created Tag. S...
CVE-2022-22114CRITICAL9.6In Teedy, versions v1.5 through v1.9 are vulnerable to Reflected Cross-Site Scripting (XSS). The “search term" search fu...
CVE-2022-22847CRITICAL9.8Formpipe Lasernet before 9.13.3 allows file inclusion in Client Web Services (either by an authenticated attacker, or in...
CVE-2022-22845CRITICAL9.8QXIP SIPCAPTURE homer-app before 1.4.28 for HOMER 7.x has the same 167f0db2-f83e-4baa-9736-d56064a5b415 JWT secret key a...
CVE-2022-22824CRITICAL9.8defineAttribute in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.
CVE-2022-22823CRITICAL9.8build_model in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.
CVE-2022-22822CRITICAL9.8addBinding in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.
CVE-2022-22817CRITICAL9.8PIL.ImageMath.eval in Pillow before 9.0.0 allows evaluation of arbitrary expressions, such as ones that use the Python e...
CVE-2022-22704CRITICAL9.8The zabbix-agent2 package before 5.4.9-r1 for Alpine Linux sometimes allows privilege escalation to root because the des...
CVE-2022-21647CRITICAL9.8CodeIgniter is an open source PHP full-stack web framework. Deserialization of Untrusted Data was found in the `old()` f...
CVE-2022-21643CRITICAL9.8USOC is an open source CMS with a focus on simplicity. In affected versions USOC allows for SQL injection via register.p...
CVE-2022-0086CRITICAL9.8uppy is vulnerable to Server-Side Request Forgery (SSRF)
CVE-2022-0080CRITICAL9.8mruby is vulnerable to Heap-based Buffer Overflow

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now