2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-2126 | HIGH | 7.8 | 1.5% | Jun 19, 2022 | Out-of-bounds Read in GitHub repository vim/vim prior to 8.2. |
| CVE-2022-2125 | HIGH | 7.8 | 1.6% | Jun 19, 2022 | Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2. |
| CVE-2022-2124 | HIGH | 7.8 | 1.5% | Jun 19, 2022 | Buffer Over-read in GitHub repository vim/vim prior to 8.2. |
| CVE-2022-25871 | HIGH | 7.5 | 1.1% | Jun 17, 2022 | All versions of package querymen are vulnerable to Prototype Pollution if the parameters of exported function handler(ty... |
| CVE-2022-25856 | HIGH | 7.5 | 1.8% | Jun 17, 2022 | The package github.com/argoproj/argo-events/sensors/artifacts before 1.7.1 are vulnerable to Directory Traversal in the ... |
| CVE-2022-25852 | HIGH | 7.5 | 1.2% | Jun 17, 2022 | All versions of package pg-native; all versions of package libpq are vulnerable to Denial of Service (DoS) when the addo... |
| CVE-2022-25345 | HIGH | 7.5 | 1.2% | Jun 17, 2022 | All versions of package @discordjs/opus are vulnerable to Denial of Service (DoS) when trying to encode using an encoder... |
| CVE-2022-22138 | HIGH | 7.5 | 1.2% | Jun 17, 2022 | All versions of package fast-string-search are vulnerable to Denial of Service (DoS) when computations are incorrect for... |
| CVE-2022-21213 | HIGH | 7.5 | 2.0% | Jun 17, 2022 | This affects all versions of package mout. The deepFillIn function can be used to 'fill missing properties recursively',... |
| CVE-2022-31083 | HIGH | 7.5 | 0.8% | Jun 17, 2022 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version... |
| CVE-2022-33915 | HIGH | 7 | 0.2% | Jun 17, 2022 | Versions of the Amazon AWS Apache Log4j hotpatch package before log4j-cve-2021-44228-hotpatch-1.3.5 are affected by a ra... |
| CVE-2022-33912 | HIGH | 7.8 | 0.2% | Jun 17, 2022 | A permission issue affects users that deployed the shipped version of the Checkmk Debian package. Packages created by th... |
| CVE-2022-32276 | HIGH | 7.5 | 3.5% | Jun 17, 2022 | Grafana 8.4.3 allows unauthenticated access via (for example) a /dashboard/snapshot/*?orgId=0 URI. NOTE: the vendor cons... |
| CVE-2022-2112 | HIGH | 8.8 | 1.2% | Jun 17, 2022 | Improper Neutralization of Formula Elements in a CSV File in GitHub repository inventree/inventree prior to 0.7.2. |
| CVE-2022-2111 | HIGH | 8.8 | 1.2% | Jun 17, 2022 | Unrestricted Upload of File with Dangerous Type in GitHub repository inventree/inventree prior to 0.7.2. |
| CVE-2022-30325 | HIGH | 8.8 | 0.4% | Jun 16, 2022 | An issue was found on TRENDnet TEW-831DR 1.0 601.130.1.1356 devices. The default pre-shared key for the Wi-Fi networks i... |
| CVE-2022-33756 | HIGH | 7.5 | 1.1% | Jun 16, 2022 | CA Automic Automation 12.2 and 12.3 contain an entropy weakness vulnerability in the Automic AutomationEngine that could... |
| CVE-2022-33753 | HIGH | 8.8 | 0.8% | Jun 16, 2022 | CA Automic Automation 12.2 and 12.3 contain an insecure file creation and handling vulnerability in the Automic agent th... |
| CVE-2022-33751 | HIGH | 7.5 | 1.1% | Jun 16, 2022 | CA Automic Automation 12.2 and 12.3 contain an insecure memory handling vulnerability in the Automic agent that could al... |
| CVE-2022-33739 | HIGH | 7.5 | 1.1% | Jun 16, 2022 | CA Clarity 15.8 and below and 15.9.0 contain an insecure XML parsing vulnerability that could allow a remote attacker to... |
| CVE-2022-26173 | HIGH | 8.8 | 0.7% | Jun 16, 2022 | JForum v2.8.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via http://target_host:port/jforum-2.8.0/jfo... |
| CVE-2022-31295 | HIGH | 7.5 | 1.3% | Jun 16, 2022 | An issue in the delete_post() function of Online Discussion Forum Site 1 allows unauthenticated attackers to arbitrarily... |
| CVE-2022-31464 | HIGH | 7.8 | 0.4% | Jun 16, 2022 | Insecure permissions configuration in Adaware Protect v1.2.439.4251 allows attackers to escalate privileges via changing... |
| CVE-2022-27511 | HIGH | 8.1 | 12.0% | Jun 16, 2022 | Corruption of the system by a remote, unauthenticated user. The impact of this can include the reset of the administrato... |
| CVE-2022-32547 | HIGH | 7.8 | 1.3% | Jun 16, 2022 | In ImageMagick, there is load of misaligned address for type 'double', which requires 8 byte alignment and for type 'flo... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now