2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-0757 | HIGH | 8.8 | 1.2% | Mar 17, 2022 | Rapid7 Nexpose versions 6.6.93 and earlier are susceptible to an SQL Injection vulnerability, whereby valid search opera... |
| CVE-2022-0237 | HIGH | 7.8 | 0.5% | Mar 17, 2022 | Rapid7 Insight Agent versions 3.1.2.38 and earlier suffer from a privilege escalation vulnerability, whereby an attacker... |
| CVE-2022-26504 | HIGH | 8.8 | 2.5% | Mar 17, 2022 | Improper authentication in Veeam Backup & Replication 9.5U3, 9.5U4,10.x and 11.x component used for Microsoft System Cen... |
| CVE-2022-26500 | HIGH | 8.8 | 5.9% | Mar 17, 2022 | Improper limitation of path names in Veeam Backup & Replication 9.5U3, 9.5U4,10.x, and 11.x allows remote authenticated ... |
| CVE-2022-24770 | HIGH | 8.8 | 1.2% | Mar 17, 2022 | `gradio` is an open source framework for building interactive machine learning models and demos. Prior to version 2.8.11... |
| CVE-2022-21822 | HIGH | 7.5 | 1.0% | Mar 17, 2022 | NVIDIA FLARE contains a vulnerability in the admin interface, where an un-authorized attacker can cause Allocation of Re... |
| CVE-2022-26511 | HIGH | 7.8 | 0.6% | Mar 17, 2022 | WPS Presentation 11.8.0.5745 insecurely load d3dx9_41.dll when opening .pps files('current directory type' DLL loading). |
| CVE-2022-26081 | HIGH | 7.8 | 0.8% | Mar 17, 2022 | The installer of WPS Office Version 10.8.0.5745 insecurely load shcore.dll, allowing an attacker to execute arbitrary co... |
| CVE-2022-25969 | HIGH | 7.8 | 0.8% | Mar 17, 2022 | The installer of WPS Office Version 10.8.0.6186 insecurely load VERSION.DLL (or some other DLLs), allowing an attacker t... |
| CVE-2022-25949 | HIGH | 7.8 | 0.7% | Mar 17, 2022 | The kernel mode driver kwatch3 of KINGSOFT Internet Security 9 Plus Version 2010.06.23.247 fails to properly handle craf... |
| CVE-2022-26503 | HIGH | 7.8 | 0.7% | Mar 17, 2022 | Deserialization of untrusted data in Veeam Agent for Windows 2.0, 2.1, 2.2, 3.0.2, 4.x, and 5.x allows local users to ru... |
| CVE-2022-25364 | HIGH | 8.1 | 1.0% | Mar 17, 2022 | In Gradle Enterprise before 2021.4.2, the default built-in build cache configuration allowed anonymous write access. If ... |
| CVE-2022-24759 | HIGH | 7.4 | 0.5% | Mar 17, 2022 | `@chainsafe/libp2p-noise` contains TypeScript implementation of noise protocol, an encryption protocol used in libp2p. `... |
| CVE-2022-26526 | HIGH | 7.8 | 0.3% | Mar 17, 2022 | Anaconda Anaconda3 (Anaconda Distribution) through 2021.11.0.0 and Miniconda3 through 4.11.0.0 can create a world-writab... |
| CVE-2022-24761 | HIGH | 7.5 | 1.8% | Mar 17, 2022 | Waitress is a Web Server Gateway Interface server for Python 2 and 3. When using Waitress versions 2.1.0 and prior behin... |
| CVE-2022-25296 | HIGH | 7.3 | 1.0% | Mar 17, 2022 | The package bodymen from 0.0.0 are vulnerable to Prototype Pollution via the handler function which could be tricked int... |
| CVE-2022-21221 | HIGH | 7.5 | 2.5% | Mar 17, 2022 | The package github.com/valyala/fasthttp before 1.34.0 are vulnerable to Directory Traversal via the ServeFile function, ... |
| CVE-2022-24073 | HIGH | 7.1 | 0.6% | Mar 17, 2022 | The Web Request API in Whale browser before 3.12.129.18 allowed to deny access to the extension store or redirect to any... |
| CVE-2022-25514 | HIGH | 7.5 | 1.0% | Mar 17, 2022 | stb_truetype.h v1.26 was discovered to contain a heap-buffer-overflow via the function ttUSHORT() at stb_truetype.h. NOT... |
| CVE-2022-26534 | HIGH | 7.5 | 1.0% | Mar 17, 2022 | FISCO-BCOS release-3.0.0-rc2 was discovered to contain an issue where a malicious node, via a malicious viewchange packe... |
| CVE-2022-26300 | HIGH | 7.5 | 1.2% | Mar 17, 2022 | EOS v2.1.0 was discovered to contain a heap-buffer-overflow via the function txn_test_gen_plugin. |
| CVE-2022-23610 | HIGH | 8.1 | 0.7% | Mar 16, 2022 | wire-server provides back end services for Wire, an open source messenger. In versions of wire-server prior to the 2022-... |
| CVE-2022-24729 | HIGH | 7.5 | 2.4% | Mar 16, 2022 | CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. CKEditor4 prior to version 4.18.0 contains a vulne... |
| CVE-2022-21164 | HIGH | 7.5 | 1.3% | Mar 16, 2022 | The package node-lmdb before 0.9.7 are vulnerable to Denial of Service (DoS) when defining a non-invokable ToString valu... |
| CVE-2022-26660 | HIGH | 7.5 | 0.6% | Mar 16, 2022 | RunAsSpc 4.0 uses a universal and recoverable encryption key. In possession of a file encrypted by RunAsSpc, an attacker... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now