2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-29534 | HIGH | 7.5 | 1.5% | Apr 20, 2022 | An issue was discovered in MISP before 2.4.158. In UsersController.php, password confirmation can be bypassed via vector... |
| CVE-2022-24872 | HIGH | 8.1 | 1.0% | Apr 20, 2022 | Shopware is an open commerce platform based on Symfony Framework and Vue. Permissions set to sales channel context by ad... |
| CVE-2022-24862 | HIGH | 7.7 | 1.0% | Apr 20, 2022 | Databasir is a team-oriented relational database model document management platform. Databasir 1.01 has Server-Side Requ... |
| CVE-2022-24861 | HIGH | 8.8 | 2.8% | Apr 20, 2022 | Databasir is a team-oriented relational database model document management platform. Databasir 1.01 has remote code exec... |
| CVE-2022-26516 | HIGH | 7.8 | 0.3% | Apr 20, 2022 | Authorized users may install a maliciously modified package file when updating the device via the web user interface. Th... |
| CVE-2022-25343 | HIGH | 7.5 | 1.3% | Apr 20, 2022 | An issue was discovered on Olivetti d-COLOR MF3555 2XD_S000.002.271 devices. The Web Application is affected by Denial o... |
| CVE-2022-25342 | HIGH | 8.1 | 1.0% | Apr 20, 2022 | An issue was discovered on Olivetti d-COLOR MF3555 2XD_S000.002.271 devices. The Web Application is affected by Broken A... |
| CVE-2022-29527 | HIGH | 7 | 0.3% | Apr 20, 2022 | Amazon AWS amazon-ssm-agent before 3.1.1208.0 creates a world-writable sudoers file, which allows local attackers to inj... |
| CVE-2022-28327 | HIGH | 7.5 | 3.9% | Apr 20, 2022 | The generic P-256 feature in crypto/elliptic in Go before 1.17.9 and 1.18.x before 1.18.1 allows a panic via long scalar... |
| CVE-2022-27536 | HIGH | 7.5 | 1.3% | Apr 20, 2022 | Certificate.Verify in crypto/x509 in Go 1.18.x before 1.18.1 can be caused to panic on macOS when presented with certain... |
| CVE-2022-24675 | HIGH | 7.5 | 5.3% | Apr 20, 2022 | encoding/pem in Go before 1.17.9 and 1.18.x before 1.18.1 has a Decode stack overflow via a large amount of PEM data. |
| CVE-2022-29266 | HIGH | 7.5 | 7.7% | Apr 20, 2022 | In APache APISIX before 3.13.1, the jwt-auth plugin has a security issue that leaks the user's secret key because the er... |
| CVE-2022-27629 | HIGH | 8.8 | 0.8% | Apr 20, 2022 | Cross-site request forgery (CSRF) vulnerability in 'MicroPayments - Paid Author Subscriptions, Content, Downloads, Membe... |
| CVE-2022-24826 | HIGH | 7.8 | 2.1% | Apr 20, 2022 | On Windows, if Git LFS operates on a malicious repository with a `..exe` file as well as a file named `git.exe`, and `gi... |
| CVE-2022-0071 | HIGH | 8.8 | 0.4% | Apr 19, 2022 | Incomplete fix for CVE-2021-3101. Hotdog, prior to v1.0.2, did not mimic the resource limits, device restrictions, or sy... |
| CVE-2022-0070 | HIGH | 8.8 | 0.4% | Apr 19, 2022 | Incomplete fix for CVE-2021-3100. The Apache Log4j hotpatch package starting with log4j-cve-2021-44228-hotpatch-1.1-16 w... |
| CVE-2022-27527 | HIGH | 7.8 | 0.5% | Apr 19, 2022 | A Memory Corruption vulnerability may lead to code execution through maliciously crafted DLL files. It was fixed in PDFT... |
| CVE-2022-25788 | HIGH | 7.8 | 1.5% | Apr 19, 2022 | A maliciously crafted JT file in Autodesk AutoCAD 2022 may be used to write beyond the allocated buffer while parsing JT... |
| CVE-2022-21497 | HIGH | 8.1 | 1.6% | Apr 19, 2022 | Vulnerability in the Oracle Web Services Manager product of Oracle Fusion Middleware (component: Web Services Security).... |
| CVE-2022-21491 | HIGH | 7.8 | 0.4% | Apr 19, 2022 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that... |
| CVE-2022-21476 | HIGH | 7.5 | 3.8% | Apr 19, 2022 | Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries).... |
| CVE-2022-21466 | HIGH | 7.5 | 1.7% | Apr 19, 2022 | Vulnerability in the Oracle Commerce Guided Search product of Oracle Commerce (component: Tools and Frameworks). The sup... |
| CVE-2022-21464 | HIGH | 8.2 | 2.1% | Apr 19, 2022 | Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Business Logic Infra SEC). ... |
| CVE-2022-21449 | HIGH | 7.5 | 46.7% | Apr 19, 2022 | Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries).... |
| CVE-2022-21446 | HIGH | 8.2 | 1.5% | Apr 19, 2022 | Vulnerability in the Oracle Solaris product of Oracle Systems (component: Utility). The supported version that is affect... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now