2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-1154 | HIGH | 7.8 | 1.5% | Mar 30, 2022 | Use after free in utf_ptr2char in GitHub repository vim/vim prior to 8.2.4646. |
| CVE-2022-23868 | HIGH | 7.8 | 0.7% | Mar 30, 2022 | RuoYi v4.7.2 contains a CSV injection vulnerability through ruoyi-admin when a victim opens .xlsx log file. |
| CVE-2022-25598 | HIGH | 7.5 | 1.9% | Mar 30, 2022 | Apache DolphinScheduler user registration is vulnerable to Regular express Denial of Service (ReDoS) attacks, Apache Dol... |
| CVE-2022-27816 | HIGH | 7.1 | 0.5% | Mar 30, 2022 | SWHKD 1.1.5 unsafely uses the /tmp/swhks.pid pathname. There can be data loss or a denial of service. |
| CVE-2022-27815 | HIGH | 7.8 | 0.5% | Mar 30, 2022 | SWHKD 1.1.5 unsafely uses the /tmp/swhkd.pid pathname. There can be an information leak or denial of service. |
| CVE-2022-27432 | HIGH | 8.8 | 0.6% | Mar 30, 2022 | A Cross-Site Request Forgery (CSRF) in Pluck CMS v4.7.15 allows attackers to change the password of any given user by ex... |
| CVE-2022-26948 | HIGH | 7.5 | 0.6% | Mar 30, 2022 | The Archer RSS feed integration for Archer 6.x through 6.9 SP1 (6.9.1.0) is affected by an insecure credential storage v... |
| CVE-2022-21821 | HIGH | 7.8 | 2.0% | Mar 29, 2022 | NVIDIA CUDA Toolkit SDK contains an integer overflow vulnerability in cuobjdump.To exploit this vulnerability, a remote ... |
| CVE-2022-26839 | HIGH | 7.8 | 0.2% | Mar 29, 2022 | Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) is vulnerable to an incorrect default permission in the ... |
| CVE-2022-25347 | HIGH | 7.5 | 11.1% | Mar 29, 2022 | Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) is vulnerable to path traversal attacks, which may allow... |
| CVE-2022-22941 | HIGH | 8.8 | 1.3% | Mar 29, 2022 | An issue was discovered in SaltStack Salt in versions before 3002.8, 3003.4, 3004.1. When configured as a Master-of-Mast... |
| CVE-2022-22936 | HIGH | 8.8 | 0.8% | Mar 29, 2022 | An issue was discovered in SaltStack Salt in versions before 3002.8, 3003.4, 3004.1. Job publishes and file server repli... |
| CVE-2022-22934 | HIGH | 8.8 | 0.9% | Mar 29, 2022 | An issue was discovered in SaltStack Salt in versions before 3002.8, 3003.4, 3004.1. Salt Masters do not sign pillar dat... |
| CVE-2022-1050 | HIGH | 8.8 | 0.4% | Mar 29, 2022 | A flaw was found in the QEMU implementation of VMWare's paravirtual RDMA device. This flaw allows a crafted guest driver... |
| CVE-2022-0343 | HIGH | 7.8 | 0.1% | Mar 29, 2022 | A local attacker, as a different local user, may be able to send a HTTP request to 127.0.0.1:10000 after the user (typic... |
| CVE-2022-1055 | HIGH | 7.8 | 0.5% | Mar 29, 2022 | A use-after-free exists in the Linux Kernel in tc_new_tfilter that could allow a local attacker to gain privilege escala... |
| CVE-2022-28155 | HIGH | 8.1 | 0.8% | Mar 29, 2022 | Jenkins Pipeline: Phoenix AutoTest Plugin 1.3 and earlier does not configure its XML parser to prevent XML external enti... |
| CVE-2022-28154 | HIGH | 8.1 | 1.0% | Mar 29, 2022 | Jenkins Coverage/Complexity Scatter Plot Plugin 1.1.1 and earlier does not configure its XML parser to prevent XML exter... |
| CVE-2022-28150 | HIGH | 8.8 | 0.7% | Mar 29, 2022 | A cross-site request forgery (CSRF) vulnerability in Jenkins Job and Node ownership Plugin 0.13.0 and earlier allows att... |
| CVE-2022-28142 | HIGH | 7.5 | 0.6% | Mar 29, 2022 | Jenkins Proxmox Plugin 0.6.0 and earlier disables SSL/TLS certificate validation globally for the Jenkins controller JVM... |
| CVE-2022-28140 | HIGH | 8.1 | 1.0% | Mar 29, 2022 | Jenkins Flaky Test Handler Plugin 1.2.1 and earlier does not configure its XML parser to prevent XML external entity (XX... |
| CVE-2022-28136 | HIGH | 8.8 | 0.7% | Mar 29, 2022 | A cross-site request forgery (CSRF) vulnerability in Jenkins JiraTestResultReporter Plugin 165.v817928553942 and earlier... |
| CVE-2022-1032 | HIGH | 7.2 | 1.6% | Mar 29, 2022 | Insecure deserialization of not validated module file in GitHub repository crater-invoice/crater prior to 6.0.6. |
| CVE-2022-1077 | HIGH | 7.5 | 2.5% | Mar 29, 2022 | A vulnerability was found in TEM FLEX-1080 and FLEX-1085 1.6.0. It has been declared as problematic. This vulnerability ... |
| CVE-2022-23937 | HIGH | 7.5 | 1.0% | Mar 29, 2022 | In Wind River VxWorks 6.9 and 7, a specific crafted packet may lead to an out-of-bounds read during an IKE initial excha... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now