2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-1529 | HIGH | 8.8 | 17.1% | Dec 22, 2022 | An attacker could have sent a message to the parent process where the contents were used to double-index into a JavaScri... |
| CVE-2022-1520 | MEDIUM | 4.3 | 0.3% | Dec 22, 2022 | When viewing an email message A, which contains an attached message B, where B is encrypted or digitally signed or both,... |
| CVE-2022-1197 | MEDIUM | 5.4 | 0.4% | Dec 22, 2022 | When importing a revoked key that specified key compromise as the revocation reason, Thunderbird did not update the exis... |
| CVE-2022-1196 | MEDIUM | 6.5 | 0.7% | Dec 22, 2022 | After a VR Process is destroyed, a reference to it may have been retained and used, leading to a use-after-free and pote... |
| CVE-2022-1097 | MEDIUM | 6.5 | 0.9% | Dec 22, 2022 | <code>NSSToken</code> objects were referenced via direct points, and could have been accessed in an unsafe way on differ... |
| CVE-2022-0843 | HIGH | 8.8 | 0.6% | Dec 22, 2022 | Mozilla developers Kershaw Chang, Ryan VanderMeulen, and Randell Jesup reported memory safety bugs present in Firefox 97... |
| CVE-2022-0566 | HIGH | 8.8 | 0.7% | Dec 22, 2022 | It may be possible for an attacker to craft an email message that causes Thunderbird to perform an out-of-bounds write o... |
| CVE-2022-0517 | HIGH | 7.8 | 0.2% | Dec 22, 2022 | Mozilla VPN can load an OpenSSL configuration file from an unsecured directory. A user or attacker with limited privileg... |
| CVE-2022-0511 | HIGH | 8.8 | 0.5% | Dec 22, 2022 | Mozilla developers and community members Gabriele Svelto, Sebastian Hengst, Randell Jesup, Luan Herrera, Lars T Hansen, ... |
| CVE-2022-46170 | CRITICAL | 9.8 | 0.8% | Dec 22, 2022 | CodeIgniter is a PHP full-stack web framework. When an application uses (1) multiple session cookies (e.g., one for user... |
| CVE-2022-23556 | HIGH | 7.5 | 0.4% | Dec 22, 2022 | CodeIgniter is a PHP full-stack web framework. This vulnerability may allow attackers to spoof their IP address when the... |
| CVE-2022-23540 | HIGH | 7.6 | 0.5% | Dec 22, 2022 | In versions `<=8.5.1` of `jsonwebtoken` library, lack of algorithm definition in the `jwt.verify()` function can lead to... |
| CVE-2022-47926 | CRITICAL | 9.8 | 0.8% | Dec 22, 2022 | AyaCMS 3.1.2 is vulnerable to file deletion via /aya/module/admin/fst_del.inc.php |
| CVE-2022-46102 | CRITICAL | 9.8 | 0.7% | Dec 22, 2022 | AyaCMS 3.1.2 is vulnerable to Arbitrary file upload via /aya/module/admin/fst_down.inc.php |
| CVE-2022-46101 | HIGH | 8.8 | 1.1% | Dec 22, 2022 | AyaCMS v3.1.2 was found to have a code flaw in the ust_sql.inc.php file, which allows attackers to cause command executi... |
| CVE-2022-23541 | MEDIUM | 6.3 | 0.8% | Dec 22, 2022 | jsonwebtoken is an implementation of JSON Web Tokens. Versions `<= 8.5.1` of `jsonwebtoken` library can be misconfigured... |
| CVE-2022-44510 | MEDIUM | 5.4 | 0.5% | Dec 22, 2022 | Adobe Experience Manager version 6.5.14 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerabilit... |
| CVE-2022-4516 | — | — | — | Dec 22, 2022 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n... |
| CVE-2022-45966 | CRITICAL | 9.8 | 0.7% | Dec 22, 2022 | here is an arbitrary file upload vulnerability in the file management function module of Classcms3.5. |
| CVE-2022-47896 | HIGH | 7.8 | 0.3% | Dec 22, 2022 | In JetBrains IntelliJ IDEA before 2022.3.1 code Templates were vulnerable to SSTI attacks. |
| CVE-2022-47895 | HIGH | 7.5 | 0.2% | Dec 22, 2022 | In JetBrains IntelliJ IDEA before 2022.3.1 the "Validate JSP File" action used the HTTP protocol to download required JA... |
| CVE-2022-45347 | CRITICAL | 9.8 | 1.4% | Dec 22, 2022 | Apache ShardingSphere-Proxy prior to 5.3.0 when using MySQL as database backend didn't cleanup the database session comp... |
| CVE-2022-41697 | MEDIUM | 5.3 | 20.2% | Dec 22, 2022 | A user enumeration vulnerability exists in the login functionality of Ghost Foundation Ghost 5.9.4. A specially-crafted ... |
| CVE-2022-41654 | MEDIUM | 4.3 | 18.9% | Dec 22, 2022 | An authentication bypass vulnerability exists in the newsletter subscription functionality of Ghost Foundation Ghost 5.9... |
| CVE-2022-25948 | MEDIUM | 5.3 | 0.8% | Dec 22, 2022 | The package liquidjs before 10.0.0 are vulnerable to Information Exposure when ownPropertyOnly parameter is set to False... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now