2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-1529HIGH8.8An attacker could have sent a message to the parent process where the contents were used to double-index into a JavaScri...
CVE-2022-1520MEDIUM4.3When viewing an email message A, which contains an attached message B, where B is encrypted or digitally signed or both,...
CVE-2022-1197MEDIUM5.4When importing a revoked key that specified key compromise as the revocation reason, Thunderbird did not update the exis...
CVE-2022-1196MEDIUM6.5After a VR Process is destroyed, a reference to it may have been retained and used, leading to a use-after-free and pote...
CVE-2022-1097MEDIUM6.5<code>NSSToken</code> objects were referenced via direct points, and could have been accessed in an unsafe way on differ...
CVE-2022-0843HIGH8.8Mozilla developers Kershaw Chang, Ryan VanderMeulen, and Randell Jesup reported memory safety bugs present in Firefox 97...
CVE-2022-0566HIGH8.8It may be possible for an attacker to craft an email message that causes Thunderbird to perform an out-of-bounds write o...
CVE-2022-0517HIGH7.8Mozilla VPN can load an OpenSSL configuration file from an unsecured directory. A user or attacker with limited privileg...
CVE-2022-0511HIGH8.8Mozilla developers and community members Gabriele Svelto, Sebastian Hengst, Randell Jesup, Luan Herrera, Lars T Hansen, ...
CVE-2022-46170CRITICAL9.8CodeIgniter is a PHP full-stack web framework. When an application uses (1) multiple session cookies (e.g., one for user...
CVE-2022-23556HIGH7.5CodeIgniter is a PHP full-stack web framework. This vulnerability may allow attackers to spoof their IP address when the...
CVE-2022-23540HIGH7.6In versions `<=8.5.1` of `jsonwebtoken` library, lack of algorithm definition in the `jwt.verify()` function can lead to...
CVE-2022-47926CRITICAL9.8AyaCMS 3.1.2 is vulnerable to file deletion via /aya/module/admin/fst_del.inc.php
CVE-2022-46102CRITICAL9.8AyaCMS 3.1.2 is vulnerable to Arbitrary file upload via /aya/module/admin/fst_down.inc.php
CVE-2022-46101HIGH8.8AyaCMS v3.1.2 was found to have a code flaw in the ust_sql.inc.php file, which allows attackers to cause command executi...
CVE-2022-23541MEDIUM6.3jsonwebtoken is an implementation of JSON Web Tokens. Versions `<= 8.5.1` of `jsonwebtoken` library can be misconfigured...
CVE-2022-44510MEDIUM5.4Adobe Experience Manager version 6.5.14 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerabilit...
CVE-2022-4516Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n...
CVE-2022-45966CRITICAL9.8here is an arbitrary file upload vulnerability in the file management function module of Classcms3.5.
CVE-2022-47896HIGH7.8In JetBrains IntelliJ IDEA before 2022.3.1 code Templates were vulnerable to SSTI attacks.
CVE-2022-47895HIGH7.5In JetBrains IntelliJ IDEA before 2022.3.1 the "Validate JSP File" action used the HTTP protocol to download required JA...
CVE-2022-45347CRITICAL9.8Apache ShardingSphere-Proxy prior to 5.3.0 when using MySQL as database backend didn't cleanup the database session comp...
CVE-2022-41697MEDIUM5.3A user enumeration vulnerability exists in the login functionality of Ghost Foundation Ghost 5.9.4. A specially-crafted ...
CVE-2022-41654MEDIUM4.3An authentication bypass vulnerability exists in the newsletter subscription functionality of Ghost Foundation Ghost 5.9...
CVE-2022-25948MEDIUM5.3The package liquidjs before 10.0.0 are vulnerable to Information Exposure when ownPropertyOnly parameter is set to False...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now