2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-34625 | HIGH | 7.2 | 2.2% | Aug 2, 2022 | Mealie1.0.0beta3 was discovered to contain a Server-Side Template Injection vulnerability, which allows attackers to exe... |
| CVE-2022-29154 | HIGH | 7.4 | 1.7% | Aug 2, 2022 | An issue was discovered in rsync before 3.2.5 that allows malicious remote servers to write arbitrary files inside the d... |
| CVE-2022-25867 | HIGH | 7.5 | 1.3% | Aug 2, 2022 | The package io.socket:socket.io-client before 2.0.1 are vulnerable to NULL Pointer Dereference when parsing a packet wit... |
| CVE-2022-35421 | HIGH | 7.2 | 0.8% | Aug 2, 2022 | Online Tours And Travels Management System v1.0 was discovered to contain a SQL injection vulnerability via the pname pa... |
| CVE-2022-37315 | HIGH | 7.5 | 0.8% | Aug 1, 2022 | graphql-go (aka GraphQL for Go) through 0.8.0 has infinite recursion in the type definition parser. |
| CVE-2022-35922 | HIGH | 7.5 | 1.5% | Aug 1, 2022 | Rust-WebSocket is a WebSocket (RFC6455) library written in Rust. In versions prior to 0.26.5 untrusted websocket connect... |
| CVE-2022-35920 | HIGH | 7.5 | 1.0% | Aug 1, 2022 | Sanic is an opensource python web server/framework. Affected versions of sanic allow access to lateral directories when ... |
| CVE-2022-31198 | HIGH | 7.5 | 0.6% | Aug 1, 2022 | OpenZeppelin Contracts is a library for secure smart contract development. This issue concerns instances of Governor tha... |
| CVE-2022-31195 | HIGH | 7.2 | 1.1% | Aug 1, 2022 | DSpace open source software is a repository application which provides durable access to digital resources. In affected ... |
| CVE-2022-31194 | HIGH | 7.2 | 0.9% | Aug 1, 2022 | DSpace open source software is a repository application which provides durable access to digital resources. dspace-jspui... |
| CVE-2022-31184 | HIGH | 7.5 | 0.6% | Aug 1, 2022 | Discourse is the an open source discussion platform. In affected versions an email activation route can be abused to sen... |
| CVE-2022-31173 | HIGH | 7.5 | 1.3% | Aug 1, 2022 | Juniper is a GraphQL server library for Rust. Affected versions of Juniper are vulnerable to uncontrolled recursion resu... |
| CVE-2022-34161 | HIGH | 8.8 | 0.4% | Aug 1, 2022 | IBM CICS TX 11.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unau... |
| CVE-2022-2581 | HIGH | 7.8 | 0.5% | Aug 1, 2022 | Out-of-bounds Read in GitHub repository vim/vim prior to 9.0.0104. |
| CVE-2022-2580 | HIGH | 7.8 | 0.5% | Aug 1, 2022 | Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0102. |
| CVE-2022-2571 | HIGH | 7.8 | 0.5% | Aug 1, 2022 | Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0101. |
| CVE-2022-36301 | HIGH | 7.5 | 0.8% | Aug 1, 2022 | BF-OS version 3.x up to and including 3.83 do not enforce strong passwords which may allow a remote attacker to brute-fo... |
| CVE-2022-34567 | HIGH | 8.8 | 1.3% | Aug 1, 2022 | An issue in \Roaming\Mango\Plugins of University of Texas Multi-image Analysis GUI (Mango) 4.1 allows attackers to escal... |
| CVE-2022-34154 | HIGH | 8.8 | 1.0% | Aug 1, 2022 | Authenticated (author or higher user role) Arbitrary File Upload vulnerability in ideasToCode Enable SVG, WebP & ICO Upl... |
| CVE-2022-2509 | HIGH | 7.5 | 1.5% | Aug 1, 2022 | A vulnerability found in gnutls. This security flaw happens because of a double free error occurs during verification of... |
| CVE-2022-26429 | HIGH | 7.8 | 0.1% | Aug 1, 2022 | In cta, there is a possible way to write permission usage records of an app due to a missing permission check. This coul... |
| CVE-2022-2273 | HIGH | 8.8 | 0.9% | Aug 1, 2022 | The Simple Membership WordPress plugin before 4.1.3 does not properly validate the membership_level parameter when editi... |
| CVE-2022-2245 | HIGH | 8.8 | 0.4% | Aug 1, 2022 | The Counter Box WordPress plugin before 1.2.1 is lacking CSRF check when activating and deactivating counters, which cou... |
| CVE-2022-2184 | HIGH | 8.8 | 0.5% | Aug 1, 2022 | The CAPTCHA 4WP WordPress plugin before 7.1.0 lets user input reach a sensitive require_once call in one of its admin-si... |
| CVE-2022-26310 | HIGH | 8.8 | 0.6% | Aug 1, 2022 | Pandora FMS v7.0NG.760 and below allows an improper authorization in User Management where any authenticated user with a... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now