2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-0411 | HIGH | 8.8 | 1.5% | Feb 28, 2022 | The Asgaros Forum WordPress plugin before 2.0.0 does not sanitise and escape the post_id parameter before using it in a ... |
| CVE-2022-0383 | HIGH | 7.2 | 1.4% | Feb 28, 2022 | The WP Review Slider WordPress plugin before 11.0 does not sanitise and escape the pid parameter when copying a Twitter ... |
| CVE-2022-26149 | HIGH | 7.2 | 9.3% | Feb 26, 2022 | MODX Revolution through 2.8.3-pl allows remote authenticated administrators to execute arbitrary code by uploading an ex... |
| CVE-2022-24986 | HIGH | 7.8 | 0.2% | Feb 26, 2022 | KDE KCron through 21.12.2 uses a temporary file in /tmp when saving, but reuses the filename during an editing session. ... |
| CVE-2022-23308 | HIGH | 7.5 | 6.0% | Feb 26, 2022 | valid.c in libxml2 before 2.9.13 has a use-after-free of ID and IDREF attributes. |
| CVE-2022-25094 | HIGH | 8.8 | 23.3% | Feb 26, 2022 | Home Owners Collection Management System v1.0 was discovered to contain a remote code execution (RCE) vulnerability via ... |
| CVE-2022-25264 | HIGH | 7.5 | 0.9% | Feb 25, 2022 | In JetBrains TeamCity before 2021.2.3, environment variables of the "password" type could be logged in some cases. |
| CVE-2022-25062 | HIGH | 7.5 | 4.5% | Feb 25, 2022 | TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain an integer overflow via the function dm_checkString. This v... |
| CVE-2022-25170 | HIGH | 7.8 | 0.9% | Feb 25, 2022 | The affected product is vulnerable to a stack-based buffer overflow while processing project files, which may allow an a... |
| CVE-2022-23985 | HIGH | 7.8 | 1.8% | Feb 25, 2022 | The affected product is vulnerable to an out-of-bounds write while processing project files, which allows an attacker to... |
| CVE-2022-23921 | HIGH | 7.8 | 0.2% | Feb 25, 2022 | Exploitation of this vulnerability may result in local privilege escalation and code execution. GE maintains exploitatio... |
| CVE-2022-21209 | HIGH | 7.8 | 1.8% | Feb 25, 2022 | The affected product is vulnerable to an out-of-bounds read while processing project files, which allows an attacker to ... |
| CVE-2022-0615 | HIGH | 7.5 | 0.8% | Feb 25, 2022 | Use-after-free in eset_rtp kernel module used in ESET products for Linux allows potential attacker to trigger denial-of-... |
| CVE-2022-24346 | HIGH | 7.8 | 0.4% | Feb 25, 2022 | In JetBrains IntelliJ IDEA before 2021.3.1, local code execution via RLO (Right-to-Left Override) characters was possibl... |
| CVE-2022-24345 | HIGH | 7.8 | 0.4% | Feb 25, 2022 | In JetBrains IntelliJ IDEA before 2021.2.4, local code execution (without permission from a user) upon opening a project... |
| CVE-2022-24342 | HIGH | 8.8 | 3.2% | Feb 25, 2022 | In JetBrains TeamCity before 2021.2.1, URL injection leading to CSRF was possible. |
| CVE-2022-24341 | HIGH | 7.5 | 0.7% | Feb 25, 2022 | In JetBrains TeamCity before 2021.2.1, editing a user account to change its password didn't terminate sessions of the ed... |
| CVE-2022-24335 | HIGH | 8.1 | 0.7% | Feb 25, 2022 | JetBrains TeamCity before 2021.2 was vulnerable to a Time-of-check/Time-of-use (TOCTOU) race-condition attack in agent r... |
| CVE-2022-24327 | HIGH | 7.5 | 0.9% | Feb 25, 2022 | In JetBrains Hub before 2021.1.13890, integration with JetBrains Account exposed an API key with excessive permissions. |
| CVE-2022-25374 | HIGH | 7.5 | 0.9% | Feb 25, 2022 | HashiCorp Terraform Enterprise v202112-1, v202112-2, v202201-1, and v202201-2 were configured to log inbound HTTP reques... |
| CVE-2022-25328 | HIGH | 7.3 | 0.2% | Feb 25, 2022 | The bash_completion script for fscrypt allows injection of commands via crafted mountpoint paths, allowing privilege esc... |
| CVE-2022-24947 | HIGH | 8.8 | 1.1% | Feb 25, 2022 | Apache JSPWiki user preferences form is vulnerable to CSRF attacks, which can lead to account takeover. Apache JSPWiki u... |
| CVE-2022-24288 | HIGH | 8.8 | 77.9% | Feb 25, 2022 | In Apache Airflow, prior to version 2.2.4, some example DAGs did not properly sanitize user-provided params, making them... |
| CVE-2022-23835 | HIGH | 8.1 | 1.4% | Feb 25, 2022 | The Visual Voice Mail (VVM) application through 2022-02-24 for Android allows persistent access if an attacker temporari... |
| CVE-2022-25149 | HIGH | 7.5 | 78.0% | Feb 24, 2022 | The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of t... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now