2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-1114 | HIGH | 7.1 | 1.1% | Apr 29, 2022 | A heap-use-after-free flaw was found in ImageMagick's RelinquishDCMInfo() function of dcm.c file. This vulnerability is ... |
| CVE-2022-1048 | HIGH | 7 | 0.2% | Apr 29, 2022 | A use-after-free flaw was found in the Linux kernel’s sound subsystem in the way a user triggers concurrent calls of PCM... |
| CVE-2022-24900 | HIGH | 8.6 | 8.0% | Apr 29, 2022 | Piano LED Visualizer is software that allows LED lights to light up as a person plays a piano connected to a computer. V... |
| CVE-2022-1534 | HIGH | 7.1 | 0.3% | Apr 29, 2022 | Buffer Over-read at parse_rawml.c:1416 in GitHub repository bfabiszewski/libmobi prior to 0.11. The bug causes the progr... |
| CVE-2022-1533 | HIGH | 7.8 | 0.4% | Apr 29, 2022 | Buffer Over-read in GitHub repository bfabiszewski/libmobi prior to 0.11. This vulnerability is capable of arbitrary cod... |
| CVE-2022-29555 | HIGH | 8.8 | 0.4% | Apr 28, 2022 | The Deviceconnect microservice through 1.3.0 in Northern.tech Mender Enterprise before 3.2.2. allows Cross-Origin Websoc... |
| CVE-2022-28060 | HIGH | 7.5 | 1.8% | Apr 28, 2022 | SQL Injection vulnerability in Victor CMS v1.0, via the user_name parameter to /includes/login.php. |
| CVE-2022-29410 | HIGH | 8.8 | 0.9% | Apr 28, 2022 | Authenticated SQL Injection (SQLi) vulnerability in Mufeng's Hermit 音乐播放器 plugin <= 3.1.6 on WordPress allows attackers ... |
| CVE-2022-29585 | HIGH | 7.5 | 1.0% | Apr 28, 2022 | In Mahara before 20.10.5, 21.04.4, 21.10.2, and 22.04.0, a site using Isolated Institutions is vulnerable if more than t... |
| CVE-2022-28892 | HIGH | 8.8 | 0.4% | Apr 28, 2022 | Mahara before 20.10.5, 21.04.4, 21.10.2, and 22.04.0 is vulnerable to Cross Site Request Forgery (CSRF) because randomly... |
| CVE-2022-24892 | HIGH | 7.5 | 0.8% | Apr 28, 2022 | Shopware is an open source e-commerce software platform. Starting with version 5.0.4 and before version 5.7.9, multiple ... |
| CVE-2022-24879 | HIGH | 7.5 | 0.6% | Apr 28, 2022 | Shopware is an open source e-commerce software platform. Versions prior to 5.7.9 are vulnerable to malfunction of cross-... |
| CVE-2022-22783 | HIGH | 7.5 | 1.0% | Apr 28, 2022 | A vulnerability in Zoom On-Premise Meeting Connector Controller version 4.8.102.20220310 and On-Premise Meeting Connecto... |
| CVE-2022-22782 | HIGH | 7.1 | 0.4% | Apr 28, 2022 | The Zoom Client for Meetings for Windows prior to version 5.9.7, Zoom Rooms for Conference Room for Windows prior to ver... |
| CVE-2022-22781 | HIGH | 7.5 | 0.4% | Apr 28, 2022 | The Zoom Client for Meetings for MacOS (Standard and for IT Admin) prior to version 5.9.6 failed to properly check the p... |
| CVE-2022-24935 | HIGH | 7.5 | 0.7% | Apr 28, 2022 | Lexmark products through 2022-02-10 have Incorrect Access Control. |
| CVE-2022-29821 | HIGH | 7.7 | 0.2% | Apr 28, 2022 | In JetBrains Rider before 2022.1 local code execution via links in ReSharper Quick Documentation was possible |
| CVE-2022-29819 | HIGH | 7.7 | 0.2% | Apr 28, 2022 | In JetBrains IntelliJ IDEA before 2022.1 local code execution via links in Quick Documentation was possible |
| CVE-2022-29818 | HIGH | 7.1 | 0.1% | Apr 28, 2022 | In JetBrains IntelliJ IDEA before 2022.1 origin checks in the internal web server were flawed |
| CVE-2022-29814 | HIGH | 7.7 | 0.2% | Apr 28, 2022 | In JetBrains IntelliJ IDEA before 2022.1 local code execution via HTML descriptions in custom JSON schemas was possible |
| CVE-2022-1509 | HIGH | 8.8 | 4.5% | Apr 28, 2022 | Command Injection Vulnerability in GitHub repository hestiacp/hestiacp prior to 1.5.12. An authenticated remote attacker... |
| CVE-2022-24735 | HIGH | 7.8 | 2.2% | Apr 27, 2022 | Redis is an in-memory database that persists on disk. By exploiting weaknesses in the Lua script execution environment, ... |
| CVE-2022-22315 | HIGH | 8.8 | 0.7% | Apr 27, 2022 | IBM UrbanCode Deploy (UCD) 7.2.2.1 could allow an authenticated user with special permissions to obtain elevated privile... |
| CVE-2022-22278 | HIGH | 7.5 | 0.9% | Apr 27, 2022 | A vulnerability in SonicOS CFS (Content filtering service) returns a large 403 forbidden HTTP response message to the so... |
| CVE-2022-22275 | HIGH | 7.5 | 1.0% | Apr 27, 2022 | Improper Restriction of TCP Communication Channel in HTTP/S inbound traffic from WAN to DMZ bypassing security policy un... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now