2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-23515 | MEDIUM | 6.1 | 0.8% | Dec 14, 2022 | Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri... |
| CVE-2022-23514 | HIGH | 7.5 | 1.7% | Dec 14, 2022 | Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri... |
| CVE-2022-23512 | HIGH | 8.1 | 0.8% | Dec 14, 2022 | MeterSphere is a one-stop open source continuous testing platform. Versions prior to 2.4.1 are vulnerable to Path Inject... |
| CVE-2022-4494 | CRITICAL | 9.8 | 0.5% | Dec 14, 2022 | A vulnerability, which was classified as critical, has been found in bspkrs MCPMappingViewer. Affected by this issue is ... |
| CVE-2022-4493 | CRITICAL | 9.8 | 0.5% | Dec 14, 2022 | A vulnerability classified as critical was found in scifio. Affected by this vulnerability is the function downloadAndUn... |
| CVE-2022-3590 | MEDIUM | 5.9 | 3.1% | Dec 14, 2022 | WordPress is affected by an unauthenticated blind SSRF in the pingback feature. Because of a TOCTOU race condition betwe... |
| CVE-2022-3073 | MEDIUM | 6.1 | 0.5% | Dec 14, 2022 | Quanos "SCHEMA ST4" example web templates in version Bootstrap 2019 v2/2021 v1/2022 v1/2022 SP1 v1 or below are prone to... |
| CVE-2022-34271 | HIGH | 8.8 | 1.4% | Dec 14, 2022 | A vulnerability in import module of Apache Atlas allows an authenticated user to write to web server filesystem. This i... |
| CVE-2022-23504 | MEDIUM | 4.9 | 0.5% | Dec 14, 2022 | TYPO3 is an open source PHP based web content management system. Versions prior to 9.5.38, 10.4.33, 11.5.20, and 12.1.1 ... |
| CVE-2022-23503 | HIGH | 8.8 | 0.8% | Dec 14, 2022 | TYPO3 is an open source PHP based web content management system. Versions prior to 8.7.49, 9.5.38, 10.4.33, 11.5.20, and... |
| CVE-2022-23502 | MEDIUM | 5.4 | 0.4% | Dec 14, 2022 | TYPO3 is an open source PHP based web content management system. In versions prior to 10.4.33, 11.5.20, and 12.1.1, When... |
| CVE-2022-23501 | MEDIUM | 6.5 | 0.5% | Dec 14, 2022 | TYPO3 is an open source PHP based web content management system. In versions prior to 8.7.49, 9.5.38, 10.4.33, 11.5.20, ... |
| CVE-2022-23500 | HIGH | 7.5 | 0.7% | Dec 14, 2022 | TYPO3 is an open source PHP based web content management system. In versions prior to 9.5.38, 10.4.33, 11.5.20, and 12.1... |
| CVE-2022-4440 | HIGH | 8.8 | 0.6% | Dec 14, 2022 | Use after free in Profiles in Google Chrome prior to 108.0.5359.124 allowed a remote attacker to potentially exploit hea... |
| CVE-2022-4439 | HIGH | 8.8 | 0.6% | Dec 14, 2022 | Use after free in Aura in Google Chrome on Windows prior to 108.0.5359.124 allowed a remote attacker who convinced the u... |
| CVE-2022-4438 | HIGH | 8.8 | 0.7% | Dec 14, 2022 | Use after free in Blink Frames in Google Chrome prior to 108.0.5359.124 allowed a remote attacker who convinced the user... |
| CVE-2022-4437 | HIGH | 8.8 | 0.7% | Dec 14, 2022 | Use after free in Mojo IPC in Google Chrome prior to 108.0.5359.124 allowed a remote attacker to potentially exploit hea... |
| CVE-2022-4436 | HIGH | 8.8 | 0.6% | Dec 14, 2022 | Use after free in Blink Media in Google Chrome prior to 108.0.5359.124 allowed a remote attacker to potentially exploit ... |
| CVE-2022-24377 | CRITICAL | 9.8 | 2.3% | Dec 14, 2022 | The package cycle-import-check before 1.3.2 are vulnerable to Command Injection via the writeFileToTmpDirAndOpenIt funct... |
| CVE-2022-42141 | MEDIUM | 5.4 | 0.5% | Dec 14, 2022 | Delta Electronics DX-2100-L1-CN 2.42 is vulnerable to Cross Site Scripting (XSS) via lform/urlfilter. |
| CVE-2022-42140 | HIGH | 7.2 | 2.4% | Dec 14, 2022 | Delta Electronics DX-2100-L1-CN 2.42 is vulnerable to Command Injection via lform/net_diagnose. |
| CVE-2022-42139 | HIGH | 8.8 | 18.2% | Dec 14, 2022 | Delta Electronics DVW-W02W2-E2 1.5.0.10 is vulnerable to Command Injection via Crafted URL. |
| CVE-2022-40264 | HIGH | 7.1 | 0.3% | Dec 14, 2022 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ICONICS/Mitsubishi Elect... |
| CVE-2022-37155 | HIGH | 8.8 | 40.0% | Dec 14, 2022 | RCE in SPIP 3.1.13 through 4.1.2 allows remote authenticated users to execute arbitrary code via the _oups parameter. |
| CVE-2022-44874 | MEDIUM | 5.5 | 0.3% | Dec 13, 2022 | wasm3 commit 7890a2097569fde845881e0b352d813573e371f9 was discovered to contain a segmentation fault via the component o... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now