2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-24775 | HIGH | 7.5 | 2.4% | Mar 21, 2022 | guzzlehttp/psr7 is a PSR-7 HTTP message library. Versions prior to 1.8.4 and 2.1.1 are vulnerable to improper header par... |
| CVE-2022-0687 | HIGH | 8.8 | 1.4% | Mar 21, 2022 | The Amelia WordPress plugin before 1.0.47 stores image blobs into actual files whose extension is controlled by the user... |
| CVE-2022-0229 | HIGH | 8.1 | 0.5% | Mar 21, 2022 | The miniOrange's Google Authenticator WordPress plugin before 5.5 does not have proper authorisation and CSRF checks whe... |
| CVE-2022-25766 | HIGH | 8.8 | 33.9% | Mar 21, 2022 | The package ungit before 1.5.20 are vulnerable to Remote Code Execution (RCE) via argument injection. The issue occurs w... |
| CVE-2022-24237 | HIGH | 8.8 | 25.3% | Mar 21, 2022 | The snaptPowered2 component of Snapt Aria v12.8 was discovered to contain a command injection vulnerability. This vulner... |
| CVE-2022-24235 | HIGH | 8.8 | 0.7% | Mar 21, 2022 | A Cross-Site Request Forgery (CSRF) in the management portal of Snapt Aria v12.8 allows attackers to escalate privileges... |
| CVE-2022-22394 | HIGH | 8.8 | 2.1% | Mar 21, 2022 | The IBM Spectrum Protect 8.1.14.000 server could allow a remote attacker to bypass security restrictions, caused by impr... |
| CVE-2022-0415 | HIGH | 8.8 | 65.2% | Mar 21, 2022 | Remote Command Execution in uploading repository file in GitHub repository gogs/gogs prior to 0.12.6. |
| CVE-2022-25481 | HIGH | 7.5 | 4.7% | Mar 21, 2022 | ThinkPHP Framework v5.0.24 was discovered to be configured without the PATHINFO parameter. This allows attackers to acce... |
| CVE-2022-25462 | HIGH | 7.5 | 0.9% | Mar 20, 2022 | Yafu v2.0 contains a segmentation fault via the component /factor/avx-ecm/vecarith52.c. This vulnerability allows attack... |
| CVE-2022-24125 | HIGH | 8.8 | 2.6% | Mar 20, 2022 | The matchmaking servers of Bandai Namco FromSoftware Dark Souls III through 2022-03-19 allow remote attackers to send ar... |
| CVE-2022-0991 | HIGH | 7.1 | 1.0% | Mar 19, 2022 | Insufficient Session Expiration in GitHub repository admidio/admidio prior to 4.1.9. |
| CVE-2022-27226 | HIGH | 8.8 | 34.5% | Mar 19, 2022 | A CSRF issue in /api/crontab on iRZ Mobile Routers through 2022-03-16 allows a threat actor to create a crontab entry in... |
| CVE-2022-26267 | HIGH | 7.5 | 1.4% | Mar 18, 2022 | Piwigo v12.2.0 was discovered to contain an information leak via the action parameter in /admin/maintenance_actions.php. |
| CVE-2022-26266 | HIGH | 8.8 | 1.3% | Mar 18, 2022 | Piwigo v12.2.0 was discovered to contain a SQL injection vulnerability via pwg.users.php. |
| CVE-2022-25581 | HIGH | 7.8 | 1.1% | Mar 18, 2022 | Classcms v2.5 and below contains an arbitrary file upload via the component \class\classupload. This vulnerability allow... |
| CVE-2022-25389 | HIGH | 7.5 | 0.9% | Mar 18, 2022 | DCN Firewall DCME-520 was discovered to contain an arbitrary file download vulnerability via the path parameter in the f... |
| CVE-2022-27245 | HIGH | 8.8 | 0.9% | Mar 18, 2022 | An issue was discovered in MISP before 2.4.156. app/Model/Server.php does not restrict generateServerSettings to the CLI... |
| CVE-2022-27243 | HIGH | 7.8 | 1.2% | Mar 18, 2022 | An issue was discovered in MISP before 2.4.156. app/View/Users/terms.ctp allows Local File Inclusion via the custom term... |
| CVE-2022-25607 | HIGH | 7.2 | 0.8% | Mar 18, 2022 | Authenticated (author or higher user role) SQL Injection (SQLi) vulnerability discovered in FV Flowplayer Video Player W... |
| CVE-2022-25602 | HIGH | 8.8 | 1.3% | Mar 18, 2022 | Nonce token leak vulnerability leading to arbitrary file upload, theme deletion, plugin settings change discovered in Re... |
| CVE-2022-24092 | HIGH | 7.8 | 4.2% | Mar 18, 2022 | Acrobat Reader DC version 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (and earlier) are affe... |
| CVE-2022-24091 | HIGH | 7.8 | 3.8% | Mar 18, 2022 | Acrobat Reader DC version 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (and earlier) are affe... |
| CVE-2022-22669 | HIGH | 7.8 | 0.3% | Mar 18, 2022 | A use after free issue was addressed with improved memory management. This issue is fixed in macOS Monterey 12.3. An app... |
| CVE-2022-22667 | HIGH | 7.8 | 1.0% | Mar 18, 2022 | A use after free issue was addressed with improved memory management. This issue is fixed in iOS 15.4 and iPadOS 15.4. A... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now