2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-26353 | HIGH | 7.5 | 2.7% | Mar 16, 2022 | A flaw was found in the virtio-net device of QEMU. This flaw was inadvertently introduced with the fix for CVE-2021-3748... |
| CVE-2022-25252 | HIGH | 7.5 | 1.5% | Mar 16, 2022 | When connecting to a certain port Axeda agent (All versions) and Axeda Desktop Server for Windows (All versions) when re... |
| CVE-2022-25250 | HIGH | 7.5 | 1.6% | Mar 16, 2022 | When connecting to a certain port Axeda agent (All versions) and Axeda Desktop Server for Windows (All versions) may all... |
| CVE-2022-25249 | HIGH | 7.5 | 2.4% | Mar 16, 2022 | When connecting to a certain port Axeda agent (All versions) and Axeda Desktop Server for Windows (All versions) (disreg... |
| CVE-2022-25246 | HIGH | 8.8 | 1.7% | Mar 16, 2022 | Axeda agent (All versions) and Axeda Desktop Server for Windows (All versions) uses hard-coded credentials for its Ultra... |
| CVE-2022-0918 | HIGH | 7.5 | 5.9% | Mar 16, 2022 | A vulnerability was discovered in the 389 Directory Server that allows an unauthenticated attacker with network access t... |
| CVE-2022-0811 | HIGH | 8.8 | 18.6% | Mar 16, 2022 | A flaw was found in CRI-O in the way it set kernel options for a pod. This issue allows anyone with rights to deploy a p... |
| CVE-2022-24751 | HIGH | 7.4 | 0.9% | Mar 16, 2022 | Zulip is an open source group chat application. Starting with version 4.0 and prior to version 4.11, Zulip is vulnerable... |
| CVE-2022-27223 | HIGH | 8.8 | 2.1% | Mar 16, 2022 | In drivers/usb/gadget/udc/udc-xilinx.c in the Linux kernel before 5.16.12, the endpoint index is not validated and might... |
| CVE-2022-23989 | HIGH | 7.5 | 0.9% | Mar 15, 2022 | In Stormshield Network Security (SNS) before 3.7.25, 3.8.x through 3.11.x before 3.11.13, 4.x before 4.2.10, and 4.3.x b... |
| CVE-2022-25491 | HIGH | 7.5 | 1.5% | Mar 15, 2022 | HMS v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter in appointment.php. |
| CVE-2022-25486 | HIGH | 7.8 | 10.0% | Mar 15, 2022 | CuppaCMS v1.0 was discovered to contain a local file inclusion via the url parameter in /alerts/alertConfigField.php. |
| CVE-2022-25485 | HIGH | 7.8 | 7.9% | Mar 15, 2022 | CuppaCMS v1.0 was discovered to contain a local file inclusion via the url parameter in /alerts/alertLightbox.php. |
| CVE-2022-27204 | HIGH | 8.8 | 0.6% | Mar 15, 2022 | A cross-site request forgery vulnerability in Jenkins Extended Choice Parameter Plugin 346.vd87693c5a_86c and earlier al... |
| CVE-2022-27198 | HIGH | 8 | 0.5% | Mar 15, 2022 | A cross-site request forgery (CSRF) vulnerability in Jenkins CloudBees AWS Credentials Plugin 189.v3551d5642995 and earl... |
| CVE-2022-22771 | HIGH | 8.8 | 2.1% | Mar 15, 2022 | The Server component of TIBCO Software Inc.'s TIBCO JasperReports Library, TIBCO JasperReports Library for ActiveMatrix ... |
| CVE-2022-0778 | HIGH | 7.5 | 70.6% | Mar 15, 2022 | The BN_mod_sqrt() function, which computes a modular square root, contains a bug that can cause it to loop forever for n... |
| CVE-2022-26779 | HIGH | 7.5 | 2.8% | Mar 15, 2022 | Apache CloudStack prior to 4.16.1.0 used insecure random number generation for project invitation tokens. If a project i... |
| CVE-2022-24756 | HIGH | 7.5 | 1.9% | Mar 15, 2022 | Bareos is open source software for backup, archiving, and recovery of data for operating systems. When Bareos Director >... |
| CVE-2022-24721 | HIGH | 8.1 | 1.1% | Mar 15, 2022 | CometD is a scalable comet implementation for web messaging. In any version prior to 5.0.11, 6.0.6, and 7.0.6, internal ... |
| CVE-2022-0944 | HIGH | 7.2 | 8.7% | Mar 15, 2022 | Template injection in connection test endpoint leads to RCE in GitHub repository sqlpad/sqlpad prior to 6.10.1. |
| CVE-2022-24740 | HIGH | 7.5 | 0.6% | Mar 14, 2022 | Volto is a ReactJS-based frontend for the Plone Content Management System. Between versions 14.0.0-alpha.5 and 15.0.0-al... |
| CVE-2022-24743 | HIGH | 8.2 | 1.2% | Mar 14, 2022 | Sylius is an open source eCommerce platform. Prior to versions 1.10.11 and 1.11.2, the reset password token was not set ... |
| CVE-2022-0943 | HIGH | 7.8 | 0.7% | Mar 14, 2022 | Heap-based Buffer Overflow occurs in vim in GitHub repository vim/vim prior to 8.2.4563. |
| CVE-2022-24578 | HIGH | 7.8 | 0.9% | Mar 14, 2022 | GPAC 1.0.1 is affected by a heap-based buffer overflow in SFS_AddString () at bifs/script_dec.c. |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now