2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2022-34625HIGH7.2Mealie1.0.0beta3 was discovered to contain a Server-Side Template Injection vulnerability, which allows attackers to exe...
CVE-2022-29154HIGH7.4An issue was discovered in rsync before 3.2.5 that allows malicious remote servers to write arbitrary files inside the d...
CVE-2022-25867HIGH7.5The package io.socket:socket.io-client before 2.0.1 are vulnerable to NULL Pointer Dereference when parsing a packet wit...
CVE-2022-35421HIGH7.2Online Tours And Travels Management System v1.0 was discovered to contain a SQL injection vulnerability via the pname pa...
CVE-2022-37315HIGH7.5graphql-go (aka GraphQL for Go) through 0.8.0 has infinite recursion in the type definition parser.
CVE-2022-35922HIGH7.5Rust-WebSocket is a WebSocket (RFC6455) library written in Rust. In versions prior to 0.26.5 untrusted websocket connect...
CVE-2022-35920HIGH7.5Sanic is an opensource python web server/framework. Affected versions of sanic allow access to lateral directories when ...
CVE-2022-31198HIGH7.5OpenZeppelin Contracts is a library for secure smart contract development. This issue concerns instances of Governor tha...
CVE-2022-31195HIGH7.2DSpace open source software is a repository application which provides durable access to digital resources. In affected ...
CVE-2022-31194HIGH7.2DSpace open source software is a repository application which provides durable access to digital resources. dspace-jspui...
CVE-2022-31184HIGH7.5Discourse is the an open source discussion platform. In affected versions an email activation route can be abused to sen...
CVE-2022-31173HIGH7.5Juniper is a GraphQL server library for Rust. Affected versions of Juniper are vulnerable to uncontrolled recursion resu...
CVE-2022-34161HIGH8.8IBM CICS TX 11.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unau...
CVE-2022-2581HIGH7.8Out-of-bounds Read in GitHub repository vim/vim prior to 9.0.0104.
CVE-2022-2580HIGH7.8Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0102.
CVE-2022-2571HIGH7.8Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0101.
CVE-2022-36301HIGH7.5BF-OS version 3.x up to and including 3.83 do not enforce strong passwords which may allow a remote attacker to brute-fo...
CVE-2022-34567HIGH8.8An issue in \Roaming\Mango\Plugins of University of Texas Multi-image Analysis GUI (Mango) 4.1 allows attackers to escal...
CVE-2022-34154HIGH8.8Authenticated (author or higher user role) Arbitrary File Upload vulnerability in ideasToCode Enable SVG, WebP & ICO Upl...
CVE-2022-2509HIGH7.5A vulnerability found in gnutls. This security flaw happens because of a double free error occurs during verification of...
CVE-2022-26429HIGH7.8In cta, there is a possible way to write permission usage records of an app due to a missing permission check. This coul...
CVE-2022-2273HIGH8.8The Simple Membership WordPress plugin before 4.1.3 does not properly validate the membership_level parameter when editi...
CVE-2022-2245HIGH8.8The Counter Box WordPress plugin before 1.2.1 is lacking CSRF check when activating and deactivating counters, which cou...
CVE-2022-2184HIGH8.8The CAPTCHA 4WP WordPress plugin before 7.1.0 lets user input reach a sensitive require_once call in one of its admin-si...
CVE-2022-26310HIGH8.8Pandora FMS v7.0NG.760 and below allows an improper authorization in User Management where any authenticated user with a...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now