2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-21442 | HIGH | 8.8 | 0.3% | Apr 19, 2022 | Vulnerability in Oracle GoldenGate (component: OGG Core Library). The supported version that is affected is Prior to 23.... |
| CVE-2022-21441 | HIGH | 7.5 | 1.3% | Apr 19, 2022 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions th... |
| CVE-2022-21430 | HIGH | 8.5 | 1.1% | Apr 19, 2022 | Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications Applications ... |
| CVE-2022-21424 | HIGH | 8.3 | 1.2% | Apr 19, 2022 | Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications Applications ... |
| CVE-2022-21422 | HIGH | 7.5 | 1.0% | Apr 19, 2022 | Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications Applications ... |
| CVE-2022-21421 | HIGH | 7.5 | 1.5% | Apr 19, 2022 | Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Ana... |
| CVE-2022-21410 | HIGH | 7.2 | 1.1% | Apr 19, 2022 | Vulnerability in the Oracle Database - Enterprise Edition Sharding component of Oracle Database Server. The supported ve... |
| CVE-2022-21404 | HIGH | 8.1 | 1.8% | Apr 19, 2022 | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Reactive WebServer). Supported versions tha... |
| CVE-2022-1384 | HIGH | 8.8 | 0.6% | Apr 19, 2022 | Mattermost version 6.4.x and earlier fails to properly check the plugin version when a plugin is installed from the Mark... |
| CVE-2022-1329 | HIGH | 8.8 | 92.9% | Apr 19, 2022 | The Elementor Website Builder plugin for WordPress is vulnerable to unauthorized execution of several AJAX actions due t... |
| CVE-2022-1119 | HIGH | 7.5 | 19.6% | Apr 19, 2022 | The Simple File List WordPress plugin is vulnerable to Arbitrary File Download via the eeFile parameter found in the ~/i... |
| CVE-2022-27055 | HIGH | 7.5 | 1.5% | Apr 19, 2022 | ecjia-daojia 1.38.1-20210202629 is vulnerable to information leakage via content/apps/installer/classes/Helper.php. When... |
| CVE-2022-29153 | HIGH | 7.5 | 8.5% | Apr 19, 2022 | HashiCorp Consul and Consul Enterprise up to 1.9.16, 1.10.9, and 1.11.4 may allow server side request forgery when the C... |
| CVE-2022-29315 | HIGH | 8.8 | 1.4% | Apr 19, 2022 | Invicti Acunetix before 14 allows CSV injection via the Description field on the Add Targets page, if the Export CSV fea... |
| CVE-2022-1065 | HIGH | 8.8 | 2.8% | Apr 19, 2022 | A vulnerability within the authentication process of Abacus ERP allows a remote attacker to bypass the second authentica... |
| CVE-2022-28108 | HIGH | 8.8 | 11.8% | Apr 19, 2022 | Selenium Server (Grid) before 4 allows CSRF because it permits non-JSON content types such as application/x-www-form-url... |
| CVE-2022-24841 | HIGH | 8.1 | 0.8% | Apr 18, 2022 | fleetdm/fleet is an open source device management, built on osquery. All versions of fleet making use of the teams featu... |
| CVE-2022-29458 | HIGH | 7.1 | 1.3% | Apr 18, 2022 | ncurses 6.3 before patch 20220416 has an out-of-bounds read and segmentation violation in convert_strings in tinfo/read_... |
| CVE-2022-29457 | HIGH | 8.8 | 7.7% | Apr 18, 2022 | Zoho ManageEngine ADSelfService Plus before 6121, ADAuditPlus 7060, Exchange Reporter Plus 5701, and ADManagerPlus 7131 ... |
| CVE-2022-24863 | HIGH | 7.5 | 2.3% | Apr 18, 2022 | http-swagger is an open source wrapper to automatically generate RESTful API documentation with Swagger 2.0. In versions... |
| CVE-2022-1037 | HIGH | 7.2 | 1.3% | Apr 18, 2022 | The EXMAGE WordPress plugin before 1.0.7 does to ensure that images added via URLs are external images, which could lead... |
| CVE-2022-0661 | HIGH | 7.2 | 40.6% | Apr 18, 2022 | The Ad Injection WordPress plugin through 1.2.0.19 does not properly sanitize the body of the adverts injected into the ... |
| CVE-2022-27530 | HIGH | 7.8 | 0.8% | Apr 18, 2022 | A maliciously crafted TIF or PICT file in Autodesk AutoCAD 2022, 2021, 2020, 2019 can be used to write beyond the alloca... |
| CVE-2022-27529 | HIGH | 7.8 | 0.7% | Apr 18, 2022 | A maliciously crafted PICT, BMP, PSD or TIF file in Autodesk AutoCAD 2022, 2021, 2020, 2019 may be used to write beyond ... |
| CVE-2022-27526 | HIGH | 7.8 | 1.4% | Apr 18, 2022 | A malicious crafted TGA file when consumed through DesignReview.exe application could lead to memory corruption vulnerab... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now