2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-3922MEDIUM4.8The Broken Link Checker WordPress plugin before 1.11.20 does not sanitise and escape some of its settings, which could a...
CVE-2022-46179HIGH7.8LiuOS is a small Python project meant to imitate the functions of a regular operating system. Version 0.1.0 and prior of...
CVE-2022-46174MEDIUM4.2efs-utils is a set of Utilities for Amazon Elastic File System (EFS). A potential race condition issue exists within the...
CVE-2022-46173MEDIUM6.5Elrond-GO is a go implementation for the Elrond Network protocol. Versions prior to 1.3.50 are subject to a processing i...
CVE-2022-46172MEDIUM6.4authentik is an open-source Identity provider focused on flexibility and versatility. In versions prior to 2022.10.4, an...
CVE-2022-3347HIGH7.5DNSSEC validation is not performed correctly. An attacker can cause this package to report successful validation for inv...
CVE-2022-3346MEDIUM6.5DNSSEC validation is not performed correctly. An attacker can cause this package to report successful validation for inv...
CVE-2022-23555HIGH8.8authentik is an open-source Identity Provider focused on flexibility and versatility. Versions prior to 2022.11.4 and 20...
CVE-2022-4773LOW3.3** UNSUPPORTED WHEN ASSIGNED ** A vulnerability classified as problematic was found in cloudsync. Affected by this vulne...
CVE-2022-41967HIGH7.5Dragonfly is a Java runtime dependency management library. Dragonfly v0.3.0-SNAPSHOT does not configure DocumentBuilderF...
CVE-2022-41966HIGH7.5XStream serializes Java objects to XML and back again. Versions prior to 1.4.20 may allow a remote attacker to terminate...
CVE-2022-23544MEDIUM6.1MeterSphere is a one-stop open source continuous testing platform, covering test management, interface testing, UI testi...
CVE-2022-4772HIGH7.8A vulnerability was found in Widoco and classified as critical. Affected by this issue is the function unZipIt of the fi...
CVE-2022-4768CRITICAL9.8A vulnerability was found in Dropbox merou. It has been classified as critical. Affected is the function add_public_key ...
CVE-2022-46442CRITICAL9.8dedecms <=V5.7.102 is vulnerable to SQL Injection. In sys_ sql_ n query.php there are no restrictions on the sql query.
CVE-2022-45963CRITICAL9.8h3c firewall <= 3.10 ESS6703 has a privilege bypass vulnerability.
CVE-2022-45778CRITICAL9.8https://www.hillstonenet.com.cn/ Hillstone Firewall SG-6000 <= 5.0.4.0 is vulnerable to Incorrect Access Control. There ...
CVE-2022-3064HIGH7.5Parsing malicious or large YAML documents can consume excessive amounts of CPU or memory.
CVE-2022-2584HIGH7.5The dag-pb codec can panic when decoding invalid blocks.
CVE-2022-2583LOW3.7A race condition can cause incorrect HTTP request routing.
CVE-2022-2582MEDIUM4.3The AWS S3 Crypto SDK sends an unencrypted hash of the plaintext alongside the ciphertext as a metadata field. This hash...
CVE-2022-3156HIGH7.8A remote code execution vulnerability exists in Rockwell Automation Studio 5000 Logix Emulate software.  Users are grant...
CVE-2022-47968MEDIUM5.4Heimdall Application Dashboard through 2.5.4 allows reflected and stored XSS via "Application name" to the "Add applicat...
CVE-2022-45434MEDIUM5.9Some Dahua software products have a vulnerability of unauthenticated un-throttled ICMP requests on remote DSS Server. Af...
CVE-2022-45433LOW3.7Some Dahua software products have a vulnerability of unauthenticated traceroute host from remote DSS Server. After bypas...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now