2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2022-2042HIGH7.8Use After Free in GitHub repository vim/vim prior to 8.2.
CVE-2022-22479HIGH8.8IBM Spectrum Copy Data Management 2.2.0.0through 2.2.15.0 is vulnerable to cross-site request forgery which could allow ...
CVE-2022-27502HIGH7.8RealVNC VNC Server 6.9.0 through 5.1.0 for Windows allows local privilege escalation because an installer repair operati...
CVE-2022-31043HIGH7.5Guzzle is an open source PHP HTTP client. In affected versions `Authorization` headers on requests are sensitive informa...
CVE-2022-31042HIGH7.5Guzzle is an open source PHP HTTP client. In affected versions the `Cookie` headers on requests are sensitive informatio...
CVE-2022-30703HIGH7.8Trend Micro Security 2021 and 2022 (Consumer) is vulnerable to an exposed dangerous method vulnerability that could allo...
CVE-2022-31051HIGH7.5semantic-release is an open source npm package for automated version management and package publishing. In affected vers...
CVE-2022-31033HIGH7.5The Mechanize library is used for automating interaction with websites. Mechanize automatically stores and sends cookies...
CVE-2022-29228HIGH7.5Envoy is a cloud-native high-performance proxy. In versions prior to 1.22.1 the OAuth filter would try to invoke the rem...
CVE-2022-29227HIGH7.5Envoy is a cloud-native high-performance edge/middle/service proxy. In versions prior to 1.22.1 if Envoy attempts to sen...
CVE-2022-29225HIGH7.5Envoy is a cloud-native high-performance proxy. In versions prior to 1.22.1 secompressors accumulate decompressed data i...
CVE-2022-30556HIGH7.5Apache HTTP Server 2.4.53 and earlier may return lengths to applications calling r:wsread() that point past the end of t...
CVE-2022-30522HIGH7.5If Apache HTTP Server 2.4.53 is configured to do transformations with mod_sed in contexts where the input to mod_sed may...
CVE-2022-2037HIGH8Excessive Attack Surface in GitHub repository tooljet/tooljet prior to v1.16.0.
CVE-2022-2027HIGH8Improper Neutralization of Formula Elements in a CSV File in GitHub repository kromitgmbh/titra prior to 0.77.0.
CVE-2022-29404HIGH7.5In Apache HTTP Server 2.4.53 and earlier, a malicious request to a lua script that calls r:parsebody(0) may cause a deni...
CVE-2022-26377HIGH7.5Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in mod_proxy_ajp of Apache HTTP Se...
CVE-2022-25153HIGH7.8The ITarian Endpoint Manage Communication Client, prior to version 6.43.41148.21120, is compiled using insecure OpenSSL ...
CVE-2022-25152HIGH8.8The ITarian platform (SAAS / on-premise) offers the possibility to run code on agents via a function called procedures. ...
CVE-2022-25151HIGH7.5Within the Service Desk module of the ITarian platform (SAAS and on-premise), a remote attacker can obtain sensitive inf...
CVE-2022-1993HIGH8.1Path Traversal in GitHub repository gogs/gogs prior to 0.12.9.
CVE-2022-31214HIGH7.8A Privilege Context Switching issue was discovered in join.c in Firejail 0.9.68. By crafting a bogus Firejail container ...
CVE-2022-2019HIGH7.5A vulnerability classified as critical was found in SourceCodester Prison Management System 1.0. Affected by this vulner...
CVE-2022-2018HIGH7.2A vulnerability classified as critical has been found in SourceCodester Prison Management System 1.0. Affected is an unk...
CVE-2022-2017HIGH7.2A vulnerability was found in SourceCodester Prison Management System 1.0. It has been rated as critical. This issue affe...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now