2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-3425HIGH7.2The Analyticator WordPress plugin before 6.5.6 unserializes user input provided via the settings, which could allow high...
CVE-2022-0316CRITICAL9.8The WeStand WordPress theme before 2.1, footysquare WordPress theme, aidreform WordPress theme, statfort WordPress theme...
CVE-2022-46959MEDIUM4.3An issue in the component /admin/backups/work-dir of Sonic v1.0.4 allows attackers to execute a directory traversal.
CVE-2022-48281MEDIUM5.5processCropSelections in tools/tiffcrop.c in LibTIFF through 4.5.0 has a heap-based buffer overflow (e.g., "WRITE of siz...
CVE-2022-3918HIGH8.8A program using FoundationNetworking in swift-corelibs-foundation is potentially vulnerable to CRLF ( ) injection in URL...
CVE-2022-1109HIGH7.5An incorrect default permissions vulnerability in Lenovo Leyun cloud music application could allow denial of service.
CVE-2022-48279HIGH7.5In ModSecurity before 2.9.6 and 3.x before 3.0.8, HTTP multipart requests were incorrectly parsed and could bypass the W...
CVE-2022-48152CRITICAL9.8SQL Injection vulnerability in RemoteClinic 2.0 allows attackers to execute arbitrary commands and gain sensitive inform...
CVE-2022-48120CRITICAL9.8SQL Injection vulnerability in kishan0725 Hospital Management System thru commit 4770d740f2512693ef8fd9aa10a8d17f79fad9b...
CVE-2022-47024HIGH7.8A null pointer dereference issue was discovered in function gui_x11_create_blank_mouse in gui_x11.c in vim 8.1.2269 thru...
CVE-2022-47021HIGH7.8A null pointer dereference issue was discovered in functions op_get_data and op_open1 in opusfile.c in xiph opusfile 0.9...
CVE-2022-47016Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2022-47015MEDIUM6.5MariaDB Server before 10.3.34 thru 10.9.3 is vulnerable to Denial of Service. It is possible for function spider_db_mbas...
CVE-2022-47012HIGH7.5Use of uninitialized variable in function gen_eth_recv in GNS3 dynamips 0.2.21.
CVE-2022-45748HIGH8.8An issue was discovered with assimp 5.1.4, a use after free occurred in function ColladaParser::ExtractDataObjectFromCha...
CVE-2022-45558MEDIUM6.1Cross site scripting (XSS) vulnerability in Hundredrabbits Left 7.1.5 for MacOS allows attackers to execute arbitrary co...
CVE-2022-45557MEDIUM6.1Cross site scripting (XSS) vulnerability in Hundredrabbits Left 7.1.5 for MacOS allows attackers to execute arbitrary co...
CVE-2022-45542MEDIUM5.4EyouCMS <= 1.6.0 was discovered a reflected-XSS in the FileManager component in GET parameter "filename" when editing an...
CVE-2022-45541MEDIUM6.1EyouCMS <= 1.6.0 was discovered a reflected-XSS in the article attribute editor component in POST value "value" if the v...
CVE-2022-45540MEDIUM6.1EyouCMS <= 1.6.0 was discovered a reflected-XSS in article type editor component in POST value "name" if the value conta...
CVE-2022-45539MEDIUM6.1EyouCMS <= 1.6.0 was discovered a reflected-XSS in FileManager component in GET value "activepath" when creating a new f...
CVE-2022-45538MEDIUM6.1EyouCMS <= 1.6.0 was discovered a reflected-XSS in the article publish component in cookie "ENV_GOBACK_URL".
CVE-2022-45537MEDIUM6.1EyouCMS <= 1.6.0 was discovered a reflected-XSS in the article publish component in cookie "ENV_LIST_URL".
CVE-2022-41733MEDIUM5.3 IBM InfoSphere Information Server 11.7 could allow a remote attacked to cause some of the components to be unusable unt...
CVE-2022-39193MEDIUM5.3An issue was discovered in the CheckUser extension for MediaWiki through 1.39.x. Various components of this extension ca...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now