2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-45145CRITICAL9.8egg-compile.scm in CHICKEN 5.x before 5.3.1 allows arbitrary OS command execution during package installation via escape...
CVE-2022-4396MEDIUM5.4A vulnerability was found in RDFlib pyrdfa3 and classified as problematic. This issue affects the function _get_option o...
CVE-2022-23485LOW3.7Sentry is an error tracking and performance monitoring platform. In versions of the sentry python library prior to 22.11...
CVE-2022-23510HIGH8.8cube-js is a headless business intelligence platform. In version 0.31.23 all authenticated Cube clients could bypass SQL...
CVE-2022-23497HIGH7.5FreshRSS is a free, self-hostable RSS aggregator. User configuration files can be accessed by a remote user. In addition...
CVE-2022-45292MEDIUM5.3User invites for Funkwhale v1.2.8 do not permanently expire after being used for signup and can be used again after an a...
CVE-2022-34297MEDIUM5.4Yii Yii2 Gii through 2.2.4 allows stored XSS by injecting a payload into any field.
CVE-2022-46166CRITICAL9.8Spring boot admins is an open source administrative user interface for management of spring boot applications. All users...
CVE-2022-46157HIGH8.8Akeneo PIM is an open source Product Information Management (PIM). Akeneo PIM Community Edition versions before v5.0.119...
CVE-2022-44790HIGH7.5Interspire Email Marketer through 6.5.1 allows SQL Injection via the surveys module. An unauthenticated attacker could s...
CVE-2022-4390CRITICAL10A network misconfiguration is present in versions prior to 1.0.9.90 of the NETGEAR RAX30 AX2400 series of routers. IPv6 ...
CVE-2022-2993CRITICAL9.8There is an error in the condition of the last if-statement in the function smp_check_keys. It was rejecting current key...
CVE-2022-45290CRITICAL9.1Kbase Doc v1.0 was discovered to contain an arbitrary file deletion vulnerability via the component /web/IndexController...
CVE-2022-41299MEDIUM5.4IBM Cloud Transformation Advisor 2.0.1 through 3.3.1 is vulnerable to cross-site scripting. This vulnerability allows us...
CVE-2022-4336MEDIUM5.4In BAOTA linux panel there exists a stored xss vulnerability attackers can use to obtain sensitive information via the l...
CVE-2022-4170CRITICAL9.8The rxvt-unicode package is vulnerable to a remote code execution, in the Perl background extension, when an attacker ca...
CVE-2022-3724HIGH7.5Crash in the USB HID protocol dissector in Wireshark 3.6.0 to 3.6.8 allows denial of service via packet injection or cra...
CVE-2022-3259HIGH7.4Openshift 4.9 does not use HTTP Strict Transport Security (HSTS) which may allow man-in-the-middle (MITM) attacks.
CVE-2022-29839MEDIUM5.5Insufficiently Protected Credentials vulnerability in the remote backups application on Western Digital My Cloud devices...
CVE-2022-29838MEDIUM4.6Improper Authentication vulnerability in the encrypted volumes and auto mount features of Western Digital My Cloud devic...
CVE-2022-25630MEDIUM5.4An authenticated user can embed malicious content with XSS into the admin group policy page.
CVE-2022-25629MEDIUM5.4An authenticated user who has the privilege to add/edit annotations on the Content tab, can craft a malicious annotation...
CVE-2022-23493CRITICAL9.1xrdp is an open source project which provides a graphical login to remote machines using Microsoft Remote Desktop Protoc...
CVE-2022-23484CRITICAL9.8xrdp is an open source project which provides a graphical login to remote machines using Microsoft Remote Desktop Protoc...
CVE-2022-23483CRITICAL9.1xrdp is an open source project which provides a graphical login to remote machines using Microsoft Remote Desktop Protoc...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now