2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-24475 | HIGH | 8.3 | 1.7% | Apr 5, 2022 | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability |
| CVE-2022-23974 | HIGH | 7.5 | 2.0% | Apr 5, 2022 | In 0.9.3 or older versions of Apache Pinot segment upload path allowed segment directories to be imported into pinot tab... |
| CVE-2022-24978 | HIGH | 8.8 | 1.1% | Apr 5, 2022 | Zoho ManageEngine ADAudit Plus before 7055 allows authenticated Privilege Escalation on Integrated products. This occurs... |
| CVE-2022-24780 | HIGH | 8.8 | 5.3% | Apr 5, 2022 | Combodo iTop is a web based IT Service Management tool. In versions prior to 2.7.6 and 3.0.0, users of the iTop user por... |
| CVE-2022-26630 | HIGH | 8.8 | 0.9% | Apr 5, 2022 | Jellycms v3.8.1 and below was discovered to contain an arbitrary file upload vulnerability via \app.\admin\Controllers\d... |
| CVE-2022-24795 | HIGH | 7.5 | 3.5% | Apr 5, 2022 | yajl-ruby is a C binding to the YAJL JSON parsing and generation library. The 1.x branch and the 2.x branch of `yajl` co... |
| CVE-2022-26986 | HIGH | 7.2 | 4.1% | Apr 5, 2022 | SQL Injection in ImpressCMS 1.4.3 and earlier allows remote attackers to inject into the code in unintended way, this al... |
| CVE-2022-26982 | HIGH | 7.2 | 9.2% | Apr 5, 2022 | SimpleMachinesForum 2.1.1 and earlier allows remote authenticated administrators to execute arbitrary code by inserting ... |
| CVE-2022-26361 | HIGH | 7.8 | 0.3% | Apr 5, 2022 | IOMMU: RMRR (VT-d) and unity map (AMD-Vi) handling issues T[his CNA information record relates to multiple CVEs; the tex... |
| CVE-2022-26360 | HIGH | 7.8 | 0.3% | Apr 5, 2022 | IOMMU: RMRR (VT-d) and unity map (AMD-Vi) handling issues T[his CNA information record relates to multiple CVEs; the tex... |
| CVE-2022-26359 | HIGH | 7.8 | 0.3% | Apr 5, 2022 | IOMMU: RMRR (VT-d) and unity map (AMD-Vi) handling issues T[his CNA information record relates to multiple CVEs; the tex... |
| CVE-2022-26358 | HIGH | 7.8 | 0.3% | Apr 5, 2022 | IOMMU: RMRR (VT-d) and unity map (AMD-Vi) handling issues T[his CNA information record relates to multiple CVEs; the tex... |
| CVE-2022-26357 | HIGH | 7 | 0.2% | Apr 5, 2022 | race in VT-d domain ID cleanup Xen domain IDs are up to 15 bits wide. VT-d hardware may allow for only less than 15 bits... |
| CVE-2022-1235 | HIGH | 8.2 | 0.5% | Apr 5, 2022 | Weak secrethash can be brute-forced in GitHub repository livehelperchat/livehelperchat prior to 3.96. |
| CVE-2022-25154 | HIGH | 7.3 | 0.2% | Apr 5, 2022 | A DLL hijacking vulnerability in Samsung portable SSD T5 PC software before 1.6.9 could allow a local attacker to escala... |
| CVE-2022-23909 | HIGH | 7.8 | 1.0% | Apr 5, 2022 | There is an unquoted service path in Sherpa Connector Service (SherpaConnectorService.exe) 2020.2.20328.2050. This might... |
| CVE-2022-1213 | HIGH | 8.1 | 0.6% | Apr 5, 2022 | SSRF filter bypass port 80, 433 in GitHub repository livehelperchat/livehelperchat prior to 3.67v. An attacker could mak... |
| CVE-2022-26281 | HIGH | 7.5 | 1.1% | Apr 5, 2022 | BigAnt Server v5.6.06 was discovered to contain an incorrect access control issue. |
| CVE-2022-26619 | HIGH | 7.5 | 0.9% | Apr 5, 2022 | Halo Blog CMS v1.4.17 was discovered to allow attackers to upload arbitrary files via the Attachment Upload function. |
| CVE-2022-25584 | HIGH | 7.5 | 1.2% | Apr 5, 2022 | Seyeon Tech Co., Ltd FlexWATCH FW3170-PS-E Network Video System 4.23-3000_GY allows attackers to access sensitive inform... |
| CVE-2022-0809 | HIGH | 8.8 | 1.0% | Apr 5, 2022 | Out of bounds memory access in WebXR in Google Chrome prior to 99.0.4844.51 allowed a remote attacker to potentially exp... |
| CVE-2022-0808 | HIGH | 8.8 | 0.9% | Apr 5, 2022 | Use after free in Chrome OS Shell in Google Chrome on Chrome OS prior to 99.0.4844.51 allowed a remote attacker who conv... |
| CVE-2022-0805 | HIGH | 8.8 | 0.9% | Apr 5, 2022 | Use after free in Browser Switcher in Google Chrome prior to 99.0.4844.51 allowed a remote attacker who convinced a user... |
| CVE-2022-0800 | HIGH | 8.8 | 1.0% | Apr 5, 2022 | Heap buffer overflow in Cast UI in Google Chrome prior to 99.0.4844.51 allowed a remote attacker who convinced a user to... |
| CVE-2022-0799 | HIGH | 8.8 | 1.0% | Apr 5, 2022 | Insufficient policy enforcement in Installer in Google Chrome on Windows prior to 99.0.4844.51 allowed a remote attacker... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now