2022 CVE Vulnerabilities

27,528 CVEs published in 2022.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2022-0269HIGH8Cross-Site Request Forgery (CSRF) in Packagist yetiforce/yetiforce-crm prior to 6.3.0.
CVE-2022-23858HIGH8.8A flaw was found in the REST API. An improperly handled REST API call could allow any logged user to elevate privileges ...
CVE-2022-23850HIGH7.8xhtml_translate_entity in xhtml.c in epub2txt (aka epub2txt2) through 2.02 allows a stack-based buffer overflow via a cr...
CVE-2022-21707HIGH8.1wasmCloud Host Runtime is a server process that securely hosts and provides dispatch for web assembly (WASM) actors and ...
CVE-2022-23837HIGH7.5In api.rb in Sidekiq before 5.2.10 and 6.4.0, there is no limit on the number of days when requesting stats for the grap...
CVE-2022-22551HIGH8.8DELL EMC AppSync versions 3.9 to 4.3 use GET request method with sensitive query strings. An Adjacent, unauthenticated a...
CVE-2022-0323HIGH8.8Improper Neutralization of Special Elements Used in a Template Engine in Packagist mustache/mustache prior to 2.14.1.
CVE-2022-23220HIGH7.8USBView 2.1 before 2.2 allows some local users (e.g., ones logged in via SSH) to execute arbitrary code as root because ...
CVE-2022-21933HIGH7.8ASUS VivoMini/Mini PC device has an improper input validation vulnerability. A local attacker with system privilege can ...
CVE-2022-22895HIGH7.8Jerryscript 3.0.0 was discovered to contain a heap-buffer-overflow via ecma_utf8_string_to_number_by_radix in /jerry-cor...
CVE-2022-22894HIGH7.8Jerryscript 3.0.0 was discovered to contain a stack overflow via ecma_lcache_lookup in /jerry-core/ecma/base/ecma-lcache...
CVE-2022-22893HIGH7.8Jerryscript 3.0.0 was discovered to contain a stack overflow via vm_loop.lto_priv.304 in /jerry-core/vm/vm.c.
CVE-2022-22888HIGH7.8Jerryscript 3.0.0 was discovered to contain a stack overflow via ecma_op_object_find_own in /ecma/operations/ecma-object...
CVE-2022-23120HIGH7.8A code injection vulnerability in Trend Micro Deep Security and Cloud One - Workload Security Agent for Linux version 20...
CVE-2022-23119HIGH7.5A directory traversal vulnerability in Trend Micro Deep Security and Cloud One - Workload Security Agent for Linux versi...
CVE-2022-0282HIGH7.5Cross-site Scripting in Packagist microweber/microweber prior to 1.2.11.
CVE-2022-0281HIGH7.5Exposure of Sensitive Information to an Unauthorized Actor in Packagist microweber/microweber prior to 1.2.11.
CVE-2022-21701HIGH8.8Istio is an open platform to connect, manage, and secure microservices. In versions 1.12.0 and 1.12.1 Istio is vulnerabl...
CVE-2022-21699HIGH8.8IPython (Interactive Python) is a command shell for interactive computing in multiple programming languages, originally ...
CVE-2022-23046HIGH7.2PhpIPAM v1.4.4 allows an authenticated admin user to inject SQL sentences in the "subnet" parameter while searching a su...
CVE-2022-21395HIGH7.2Vulnerability in the Oracle Communications Operations Monitor product of Oracle Communications (component: Mediation Eng...
CVE-2022-21392HIGH8.8Vulnerability in the Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Policy Framework)...
CVE-2022-21382HIGH7.7Vulnerability in the Oracle Enterprise Session Border Controller product of Oracle Communications (component: WebUI). Su...
CVE-2022-21371HIGH7.5Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Container). Supported ve...
CVE-2022-21351HIGH7.1Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are af...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now