2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2022-0411HIGH8.8The Asgaros Forum WordPress plugin before 2.0.0 does not sanitise and escape the post_id parameter before using it in a ...
CVE-2022-0383HIGH7.2The WP Review Slider WordPress plugin before 11.0 does not sanitise and escape the pid parameter when copying a Twitter ...
CVE-2022-26149HIGH7.2MODX Revolution through 2.8.3-pl allows remote authenticated administrators to execute arbitrary code by uploading an ex...
CVE-2022-24986HIGH7.8KDE KCron through 21.12.2 uses a temporary file in /tmp when saving, but reuses the filename during an editing session. ...
CVE-2022-23308HIGH7.5valid.c in libxml2 before 2.9.13 has a use-after-free of ID and IDREF attributes.
CVE-2022-25094HIGH8.8Home Owners Collection Management System v1.0 was discovered to contain a remote code execution (RCE) vulnerability via ...
CVE-2022-25264HIGH7.5In JetBrains TeamCity before 2021.2.3, environment variables of the "password" type could be logged in some cases.
CVE-2022-25062HIGH7.5TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain an integer overflow via the function dm_checkString. This v...
CVE-2022-25170HIGH7.8The affected product is vulnerable to a stack-based buffer overflow while processing project files, which may allow an a...
CVE-2022-23985HIGH7.8The affected product is vulnerable to an out-of-bounds write while processing project files, which allows an attacker to...
CVE-2022-23921HIGH7.8Exploitation of this vulnerability may result in local privilege escalation and code execution. GE maintains exploitatio...
CVE-2022-21209HIGH7.8The affected product is vulnerable to an out-of-bounds read while processing project files, which allows an attacker to ...
CVE-2022-0615HIGH7.5Use-after-free in eset_rtp kernel module used in ESET products for Linux allows potential attacker to trigger denial-of-...
CVE-2022-24346HIGH7.8In JetBrains IntelliJ IDEA before 2021.3.1, local code execution via RLO (Right-to-Left Override) characters was possibl...
CVE-2022-24345HIGH7.8In JetBrains IntelliJ IDEA before 2021.2.4, local code execution (without permission from a user) upon opening a project...
CVE-2022-24342HIGH8.8In JetBrains TeamCity before 2021.2.1, URL injection leading to CSRF was possible.
CVE-2022-24341HIGH7.5In JetBrains TeamCity before 2021.2.1, editing a user account to change its password didn't terminate sessions of the ed...
CVE-2022-24335HIGH8.1JetBrains TeamCity before 2021.2 was vulnerable to a Time-of-check/Time-of-use (TOCTOU) race-condition attack in agent r...
CVE-2022-24327HIGH7.5In JetBrains Hub before 2021.1.13890, integration with JetBrains Account exposed an API key with excessive permissions.
CVE-2022-25374HIGH7.5HashiCorp Terraform Enterprise v202112-1, v202112-2, v202201-1, and v202201-2 were configured to log inbound HTTP reques...
CVE-2022-25328HIGH7.3The bash_completion script for fscrypt allows injection of commands via crafted mountpoint paths, allowing privilege esc...
CVE-2022-24947HIGH8.8Apache JSPWiki user preferences form is vulnerable to CSRF attacks, which can lead to account takeover. Apache JSPWiki u...
CVE-2022-24288HIGH8.8In Apache Airflow, prior to version 2.2.4, some example DAGs did not properly sanitize user-provided params, making them...
CVE-2022-23835HIGH8.1The Visual Voice Mail (VVM) application through 2022-02-24 for Android allows persistent access if an attacker temporari...
CVE-2022-25149HIGH7.5The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of t...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now