2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2022-25298HIGH7.5This affects the package sprinfall/webcc before 0.3.0. It is possible to traverse directories to fetch arbitrary files f...
CVE-2022-0660HIGH7.5Generation of Error Message Containing Sensitive Information in Packagist microweber/microweber prior to 1.2.11.
CVE-2022-25314HIGH7.5In Expat (aka libexpat) before 2.4.5, there is an integer overflow in copyString.
CVE-2022-23646HIGH7.5Next.js is a React framework. Starting with version 10.0.0 and prior to version 12.1.0, Next.js is vulnerable to User In...
CVE-2022-22914HIGH7.5An incorrect access control issue in the component FileManager of Ovidentia CMS 6.0 allows authenticated attackers to to...
CVE-2022-24683HIGH7.5HashiCorp Nomad and Nomad Enterprise 0.9.2 through 1.0.17, 1.1.11, and 1.2.5 allow operators with read-fs and alloc-exec...
CVE-2022-23632HIGH7.5Traefik is an HTTP reverse proxy and load balancer. Prior to version 2.6.1, Traefik skips the router transport layer sec...
CVE-2022-20750HIGH7.5A vulnerability in the checkpoint manager implementation of Cisco Redundancy Configuration Manager (RCM) for Cisco StarO...
CVE-2022-20653HIGH7.5A vulnerability in the DNS-based Authentication of Named Entities (DANE) email verification component of Cisco AsyncOS S...
CVE-2022-23318HIGH7.1A heap-buffer-overflow in pcf2bdf, versions >= 1.05 allows an attacker to trigger unsafe memory access via a specially c...
CVE-2022-0629HIGH7.8Stack-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.
CVE-2022-25271HIGH7.5Drupal core's form API has a vulnerability where certain contributed or custom modules' forms may be vulnerable to impro...
CVE-2022-24985HIGH8.8Forms generated by JQueryForm.com before 2022-02-05 allows a remote authenticated attacker to bypass authentication and ...
CVE-2022-24983HIGH7.5Forms generated by JQueryForm.com before 2022-02-05 allow remote attackers to obtain the URI to any uploaded file by cap...
CVE-2022-23636HIGH8.1Wasmtime is an open source runtime for WebAssembly & WASI. Prior to versions 0.34.1 and 0.33.1, there exists a bug in th...
CVE-2022-25265HIGH7.8In the Linux kernel through 5.16.10, certain binary files may have the exec-all attribute if they were built in approxim...
CVE-2022-25255HIGH7.8In Qt 5.9.x through 5.15.x before 5.15.9 and 6.x before 6.2.4 on Linux and UNIX, QProcess could execute a binary from th...
CVE-2022-23644HIGH8.8BookWyrm is a decentralized social network for tracking reading habits and reviewing books. The functionality to load a ...
CVE-2022-24665HIGH8.8PHP Everywhere <= 2.0.3 included functionality that allowed execution of PHP Code Snippets via a WordPress gutenberg blo...
CVE-2022-24664HIGH8.8PHP Everywhere <= 2.0.3 included functionality that allowed execution of PHP Code Snippets via WordPress metaboxes, whic...
CVE-2022-24663HIGH8.8PHP Everywhere <= 2.0.3 included functionality that allowed execution of PHP Code Snippets via WordPress shortcodes, whi...
CVE-2022-23804HIGH7.8A stack-based buffer overflow vulnerability exists in the Gerber Viewer gerber and excellon ReadIJCoord coordinate parsi...
CVE-2022-23803HIGH7.8A stack-based buffer overflow vulnerability exists in the Gerber Viewer gerber and excellon ReadXYCoord coordinate parsi...
CVE-2022-23203HIGH7.8Adobe Photoshop versions 22.5.4 (and earlier) and 23.1 (and earlier) are affected by a buffer overflow vulnerability due...
CVE-2022-23202HIGH7Adobe Creative Cloud Desktop version 2.7.0.13 (and earlier) is affected by an Uncontrolled Search Path Element vulnerabi...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now