2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-2068 | HIGH | 7.3 | 95.8% | Jun 21, 2022 | In addition to the c_rehash shell command injection identified in CVE-2022-1292, further circumstances where the c_rehas... |
| CVE-2022-27872 | HIGH | 7.8 | 0.7% | Jun 21, 2022 | A maliciously crafted PDF file may be used to dereference a pointer for read or write operation while parsing PDF files ... |
| CVE-2022-27871 | HIGH | 7.8 | 0.7% | Jun 21, 2022 | Autodesk AutoCAD product suite, Revit, Design Review and Navisworks releases using PDFTron prior to 9.1.17 version may b... |
| CVE-2022-27870 | HIGH | 7.8 | 0.7% | Jun 21, 2022 | A maliciously crafted TGA file in Autodesk AutoCAD 2023 may be used to write beyond the allocated buffer while parsing T... |
| CVE-2022-27869 | HIGH | 7.8 | 0.7% | Jun 21, 2022 | A maliciously crafted TIFF file in Autodesk AutoCAD 2023 can be forced to read and write beyond allocated boundaries whe... |
| CVE-2022-27868 | HIGH | 7.8 | 1.0% | Jun 21, 2022 | A maliciously crafted CAT file in Autodesk AutoCAD 2023 can be used to trigger use-after-free vulnerability. Exploitatio... |
| CVE-2022-27867 | HIGH | 7.8 | 0.7% | Jun 21, 2022 | A maliciously crafted JT file in Autodesk AutoCAD 2022, 2021, 2020, 2019 can be used to trigger use-after-free vulnerabi... |
| CVE-2022-23171 | HIGH | 8.8 | 0.6% | Jun 21, 2022 | AtlasVPN - Privilege Escalation Lack of proper security controls on named pipe messages can allow an attacker with low p... |
| CVE-2022-22979 | HIGH | 7.5 | 1.3% | Jun 21, 2022 | In Spring Cloud Function versions prior to 3.2.6, it is possible for a user who directly interacts with framework provid... |
| CVE-2022-1833 | HIGH | 8.8 | 0.8% | Jun 21, 2022 | A flaw was found in AMQ Broker Operator 7.9.4 installed via UI using OperatorHub where a low-privilege user that has acc... |
| CVE-2022-1665 | HIGH | 8.2 | 0.3% | Jun 21, 2022 | A set of pre-production kernel packages of Red Hat Enterprise Linux for IBM Power architecture can be booted by the grub... |
| CVE-2022-33056 | HIGH | 7.2 | 0.9% | Jun 21, 2022 | Online Railway Reservation System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /... |
| CVE-2022-33055 | HIGH | 7.2 | 0.9% | Jun 21, 2022 | Online Railway Reservation System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /... |
| CVE-2022-33049 | HIGH | 7.2 | 0.9% | Jun 21, 2022 | Online Railway Reservation System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /... |
| CVE-2022-33048 | HIGH | 7.2 | 0.9% | Jun 21, 2022 | Online Railway Reservation System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /... |
| CVE-2022-33913 | HIGH | 7.5 | 1.0% | Jun 20, 2022 | In Mahara 21.04 before 21.04.6, 21.10 before 21.10.4, and 22.04.2, files can sometimes be downloaded through thumb.php w... |
| CVE-2022-1720 | HIGH | 7.8 | 2.1% | Jun 20, 2022 | Buffer Over-read in function grab_file_name in GitHub repository vim/vim prior to 8.2.4956. This vulnerability is capabl... |
| CVE-2022-1939 | HIGH | 7.2 | 1.4% | Jun 20, 2022 | The Allow svg files WordPress plugin before 1.1 does not properly validate uploaded files, which could allow high privil... |
| CVE-2022-1824 | HIGH | 8.2 | 0.3% | Jun 20, 2022 | An uncontrolled search path vulnerability in McAfee Consumer Product Removal Tool prior to version 10.4.128 could allow ... |
| CVE-2022-1823 | HIGH | 7.8 | 0.3% | Jun 20, 2022 | Improper privilege management vulnerability in McAfee Consumer Product Removal Tool prior to version 10.4.128 could allo... |
| CVE-2022-1801 | HIGH | 7.5 | 1.2% | Jun 20, 2022 | The Very Simple Contact Form WordPress plugin before 11.6 exposes the solution to the captcha in the rendered contact fo... |
| CVE-2022-1614 | HIGH | 7.5 | 1.1% | Jun 20, 2022 | The WP-EMail WordPress plugin before 2.69.0 prioritizes getting a visitor's IP from certain HTTP headers over PHP's REMO... |
| CVE-2022-1472 | HIGH | 7.2 | 1.2% | Jun 20, 2022 | The Better Find and Replace WordPress plugin before 1.3.6 does not properly sanitise, validate and escape various parame... |
| CVE-2022-34006 | HIGH | 7.8 | 0.3% | Jun 19, 2022 | An issue was discovered in TitanFTP (aka Titan FTP) NextGen before 1.2.1050. When installing, Microsoft SQL Express 2019... |
| CVE-2022-2129 | HIGH | 7.8 | 1.3% | Jun 19, 2022 | Out-of-bounds Write in GitHub repository vim/vim prior to 8.2. |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now