2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2022-24775HIGH7.5guzzlehttp/psr7 is a PSR-7 HTTP message library. Versions prior to 1.8.4 and 2.1.1 are vulnerable to improper header par...
CVE-2022-0687HIGH8.8The Amelia WordPress plugin before 1.0.47 stores image blobs into actual files whose extension is controlled by the user...
CVE-2022-0229HIGH8.1The miniOrange's Google Authenticator WordPress plugin before 5.5 does not have proper authorisation and CSRF checks whe...
CVE-2022-25766HIGH8.8The package ungit before 1.5.20 are vulnerable to Remote Code Execution (RCE) via argument injection. The issue occurs w...
CVE-2022-24237HIGH8.8The snaptPowered2 component of Snapt Aria v12.8 was discovered to contain a command injection vulnerability. This vulner...
CVE-2022-24235HIGH8.8A Cross-Site Request Forgery (CSRF) in the management portal of Snapt Aria v12.8 allows attackers to escalate privileges...
CVE-2022-22394HIGH8.8The IBM Spectrum Protect 8.1.14.000 server could allow a remote attacker to bypass security restrictions, caused by impr...
CVE-2022-0415HIGH8.8Remote Command Execution in uploading repository file in GitHub repository gogs/gogs prior to 0.12.6.
CVE-2022-25481HIGH7.5ThinkPHP Framework v5.0.24 was discovered to be configured without the PATHINFO parameter. This allows attackers to acce...
CVE-2022-25462HIGH7.5Yafu v2.0 contains a segmentation fault via the component /factor/avx-ecm/vecarith52.c. This vulnerability allows attack...
CVE-2022-24125HIGH8.8The matchmaking servers of Bandai Namco FromSoftware Dark Souls III through 2022-03-19 allow remote attackers to send ar...
CVE-2022-0991HIGH7.1Insufficient Session Expiration in GitHub repository admidio/admidio prior to 4.1.9.
CVE-2022-27226HIGH8.8A CSRF issue in /api/crontab on iRZ Mobile Routers through 2022-03-16 allows a threat actor to create a crontab entry in...
CVE-2022-26267HIGH7.5Piwigo v12.2.0 was discovered to contain an information leak via the action parameter in /admin/maintenance_actions.php.
CVE-2022-26266HIGH8.8Piwigo v12.2.0 was discovered to contain a SQL injection vulnerability via pwg.users.php.
CVE-2022-25581HIGH7.8Classcms v2.5 and below contains an arbitrary file upload via the component \class\classupload. This vulnerability allow...
CVE-2022-25389HIGH7.5DCN Firewall DCME-520 was discovered to contain an arbitrary file download vulnerability via the path parameter in the f...
CVE-2022-27245HIGH8.8An issue was discovered in MISP before 2.4.156. app/Model/Server.php does not restrict generateServerSettings to the CLI...
CVE-2022-27243HIGH7.8An issue was discovered in MISP before 2.4.156. app/View/Users/terms.ctp allows Local File Inclusion via the custom term...
CVE-2022-25607HIGH7.2Authenticated (author or higher user role) SQL Injection (SQLi) vulnerability discovered in FV Flowplayer Video Player W...
CVE-2022-25602HIGH8.8Nonce token leak vulnerability leading to arbitrary file upload, theme deletion, plugin settings change discovered in Re...
CVE-2022-24092HIGH7.8Acrobat Reader DC version 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (and earlier) are affe...
CVE-2022-24091HIGH7.8Acrobat Reader DC version 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (and earlier) are affe...
CVE-2022-22669HIGH7.8A use after free issue was addressed with improved memory management. This issue is fixed in macOS Monterey 12.3. An app...
CVE-2022-22667HIGH7.8A use after free issue was addressed with improved memory management. This issue is fixed in iOS 15.4 and iPadOS 15.4. A...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now