2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2022-0608HIGH8.8Integer overflow in Mojo in Google Chrome prior to 98.0.4758.102 allowed a remote attacker to potentially exploit heap c...
CVE-2022-0607HIGH8.8Use after free in GPU in Google Chrome prior to 98.0.4758.102 allowed a remote attacker to potentially exploit heap corr...
CVE-2022-0606HIGH8.8Use after free in ANGLE in Google Chrome prior to 98.0.4758.102 allowed a remote attacker to potentially exploit heap co...
CVE-2022-0605HIGH8.8Use after free in Webstore API in Google Chrome prior to 98.0.4758.102 allowed an attacker who convinced a user to insta...
CVE-2022-0604HIGH8.8Heap buffer overflow in Tab Groups in Google Chrome prior to 98.0.4758.102 allowed an attacker who convinced a user to i...
CVE-2022-0603HIGH8.8Use after free in File Manager in Google Chrome on Chrome OS prior to 98.0.4758.102 allowed a remote attacker to potenti...
CVE-2022-27442HIGH7.5TPCMS v3.2 allows attackers to access the ThinkPHP log directory and obtain sensitive information such as the administra...
CVE-2022-27650HIGH7.5A flaw was found in crun where containers were incorrectly started with non-empty default permissions. A vulnerability w...
CVE-2022-27649HIGH7.5A flaw was found in Podman, where containers were started incorrectly with non-empty default permissions. A vulnerabilit...
CVE-2022-23699HIGH7.8A local authentication restriction bypass vulnerability was discovered in HPE OneView version(s): Prior to 6.6. HPE has ...
CVE-2022-23698HIGH7.5A remote unauthenticated disclosure of information vulnerability was discovered in HPE OneView version(s): Prior to 6.6....
CVE-2022-1174HIGH7.5A potential DoS vulnerability was discovered in Gitlab CE/EE versions 13.7 before 14.7.7, all versions starting from 14....
CVE-2022-26572HIGH7.5Xerox ColorQube 8580 was discovered to contain an access control issue which allows attackers to print, view the status,...
CVE-2022-24801HIGH8.1Twisted is an event-based framework for internet applications, supporting Python 3.6+. Prior to version 22.4.0rc1, the T...
CVE-2022-24787HIGH7.5Vyper is a Pythonic Smart Contract Language for the Ethereum Virtual Machine. In version 0.3.1 and prior, bytestrings ca...
CVE-2022-24785HIGH7.5Moment.js is a JavaScript date library for parsing, validating, manipulating, and formatting dates. A path traversal vul...
CVE-2022-0887HIGH7.2The Easy Social Icons WordPress plugin before 3.1.4 does not sanitize the selected_icons attribute to the cnss_widget be...
CVE-2022-0709HIGH7.5The Booking Package WordPress plugin before 1.5.29 requires a token for exporting the ical representation of it's bookin...
CVE-2022-0537HIGH7.2The MapPress Maps for WordPress plugin before 2.73.13 allows a high privileged user to bypass the DISALLOW_FILE_EDIT and...
CVE-2022-0403HIGH8.1The Library File Manager WordPress plugin before 5.2.3 is using an outdated version of the elFinder library, which is kn...
CVE-2022-1026HIGH8.6Kyocera multifunction printers running vulnerable versions of Net View unintentionally expose sensitive user information...
CVE-2022-28062HIGH8.8Car Rental System v1.0 contains an arbitrary file upload vulnerability via the Add Car component which allows attackers ...
CVE-2022-27435HIGH8.8An unrestricted file upload at /public/admin/index.php?add_product of Ecommerce-Website v1.1.0 allows attackers to uploa...
CVE-2022-27249HIGH8.8An unrestricted file upload vulnerability in IdeaRE RefTree before 2021.09.17 allows remote authenticated users to execu...
CVE-2022-26233HIGH7.5Barco Control Room Management through Suite 2.9 Build 0275 was discovered to be vulnerable to directory traversal, allow...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now