2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-23043 | HIGH | 7.2 | 1.4% | Feb 24, 2022 | Zenario CMS 9.2 allows an authenticated admin user to bypass the file upload restriction by creating a new 'File/MIME Ty... |
| CVE-2022-25331 | HIGH | 7.5 | 3.0% | Feb 24, 2022 | Uncaught exceptions that can be generated in Trend Micro ServerProtection 6.0/5.8 Information Server could allow a remot... |
| CVE-2022-24680 | HIGH | 7.8 | 0.5% | Feb 24, 2022 | A security link following local privilege escalation vulnerability in Trend Micro Apex One, Trend Micro Apex One as a Se... |
| CVE-2022-24679 | HIGH | 7.8 | 0.5% | Feb 24, 2022 | A security link following local privilege escalation vulnerability in Trend Micro Apex One, Trend Micro Apex One as a Se... |
| CVE-2022-24678 | HIGH | 7.5 | 2.3% | Feb 24, 2022 | An security agent resource exhaustion denial-of-service vulnerability in Trend Micro Apex One, Trend Micro Apex One as a... |
| CVE-2022-24671 | HIGH | 7.8 | 0.4% | Feb 24, 2022 | A link following privilege escalation vulnerability in Trend Micro Antivirus for Max 11.0.2150 and below could allow a l... |
| CVE-2022-24409 | HIGH | 7.5 | 1.1% | Feb 23, 2022 | Dell BSAFE SSL-J contains remediation for a covert timing channel vulnerability that may be exploited by malicious users... |
| CVE-2022-22336 | HIGH | 7.5 | 2.0% | Feb 23, 2022 | IBM Sterling External Authentication Server and IBM Sterling Secure Proxy 6.0.3.0, 6.0.2.0, and 3.4.3.2 could allow a re... |
| CVE-2022-21705 | HIGH | 7.2 | 8.7% | Feb 23, 2022 | Octobercms is a self-hosted CMS platform based on the Laravel PHP Framework. In affected versions user input was not pro... |
| CVE-2022-20650 | HIGH | 8.8 | 14.5% | Feb 23, 2022 | A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an authenticated, remote attacker to execute a... |
| CVE-2022-20624 | HIGH | 7.5 | 12.4% | Feb 23, 2022 | A vulnerability in the Cisco Fabric Services over IP (CFSoIP) feature of Cisco NX-OS Software could allow an unauthentic... |
| CVE-2022-20623 | HIGH | 7.5 | 12.3% | Feb 23, 2022 | A vulnerability in the rate limiter for Bidirectional Forwarding Detection (BFD) traffic of Cisco NX-OS Software for Cis... |
| CVE-2022-0729 | HIGH | 8.8 | 1.6% | Feb 23, 2022 | Use of Out-of-range Pointer Offset in GitHub repository vim/vim prior to 8.2.4440. |
| CVE-2022-0736 | HIGH | 7.5 | 1.6% | Feb 23, 2022 | Insecure Temporary File in GitHub repository mlflow/mlflow prior to 1.23.1. |
| CVE-2022-0654 | HIGH | 7.5 | 1.4% | Feb 23, 2022 | Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository fgribreau/node-request-retry prior to 7.... |
| CVE-2022-23612 | HIGH | 7.5 | 1.9% | Feb 22, 2022 | OpenMRS is a patient-based medical record system focusing on giving providers a free customizable electronic medical rec... |
| CVE-2022-21655 | HIGH | 7.5 | 1.1% | Feb 22, 2022 | Envoy is an open source edge and service proxy, designed for cloud-native applications. The envoy common router will seg... |
| CVE-2022-23635 | HIGH | 7.5 | 1.6% | Feb 22, 2022 | Istio is an open platform to connect, manage, and secure microservices. In affected versions the Istio control plane, `i... |
| CVE-2022-23652 | HIGH | 8.8 | 1.4% | Feb 22, 2022 | capsule-proxy is a reverse proxy for Capsule Operator which provides multi-tenancy in Kubernetes. In versions prior to 0... |
| CVE-2022-0713 | HIGH | 7.1 | 1.0% | Feb 22, 2022 | Heap-based Buffer Overflow in GitHub repository radareorg/radare2 prior to 5.6.4. |
| CVE-2022-0676 | HIGH | 7.8 | 1.2% | Feb 22, 2022 | Heap-based Buffer Overflow in GitHub repository radareorg/radare2 prior to 5.6.4. |
| CVE-2022-24295 | HIGH | 8.8 | 17.9% | Feb 21, 2022 | Okta Advanced Server Access Client for Windows prior to version 1.57.0 was found to be vulnerable to command injection v... |
| CVE-2022-23984 | HIGH | 7.5 | 1.1% | Feb 21, 2022 | Sensitive information disclosure discovered in wpDiscuz WordPress plugin (versions <= 7.3.11). |
| CVE-2022-23983 | HIGH | 8.8 | 0.4% | Feb 21, 2022 | Cross-Site Request Forgery (CSRF) vulnerability leading to plugin Settings Update discovered in WP Content Copy Protecti... |
| CVE-2022-22308 | HIGH | 7.8 | 0.7% | Feb 21, 2022 | IBM Planning Analytics 2.0 is vulnerable to a Remote File Include (RFI) attack. User input could be passed into file inc... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now