2022 CVE Vulnerabilities
27,528 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-0269 | HIGH | 8 | 0.5% | Jan 24, 2022 | Cross-Site Request Forgery (CSRF) in Packagist yetiforce/yetiforce-crm prior to 6.3.0. |
| CVE-2022-23858 | HIGH | 8.8 | 1.1% | Jan 24, 2022 | A flaw was found in the REST API. An improperly handled REST API call could allow any logged user to elevate privileges ... |
| CVE-2022-23850 | HIGH | 7.8 | 0.9% | Jan 23, 2022 | xhtml_translate_entity in xhtml.c in epub2txt (aka epub2txt2) through 2.02 allows a stack-based buffer overflow via a cr... |
| CVE-2022-21707 | HIGH | 8.1 | 0.9% | Jan 21, 2022 | wasmCloud Host Runtime is a server process that securely hosts and provides dispatch for web assembly (WASM) actors and ... |
| CVE-2022-23837 | HIGH | 7.5 | 5.3% | Jan 21, 2022 | In api.rb in Sidekiq before 5.2.10 and 6.4.0, there is no limit on the number of days when requesting stats for the grap... |
| CVE-2022-22551 | HIGH | 8.8 | 0.4% | Jan 21, 2022 | DELL EMC AppSync versions 3.9 to 4.3 use GET request method with sensitive query strings. An Adjacent, unauthenticated a... |
| CVE-2022-0323 | HIGH | 8.8 | 0.7% | Jan 21, 2022 | Improper Neutralization of Special Elements Used in a Template Engine in Packagist mustache/mustache prior to 2.14.1. |
| CVE-2022-23220 | HIGH | 7.8 | 0.5% | Jan 21, 2022 | USBView 2.1 before 2.2 allows some local users (e.g., ones logged in via SSH) to execute arbitrary code as root because ... |
| CVE-2022-21933 | HIGH | 7.8 | 0.3% | Jan 21, 2022 | ASUS VivoMini/Mini PC device has an improper input validation vulnerability. A local attacker with system privilege can ... |
| CVE-2022-22895 | HIGH | 7.8 | 0.8% | Jan 21, 2022 | Jerryscript 3.0.0 was discovered to contain a heap-buffer-overflow via ecma_utf8_string_to_number_by_radix in /jerry-cor... |
| CVE-2022-22894 | HIGH | 7.8 | 0.7% | Jan 21, 2022 | Jerryscript 3.0.0 was discovered to contain a stack overflow via ecma_lcache_lookup in /jerry-core/ecma/base/ecma-lcache... |
| CVE-2022-22893 | HIGH | 7.8 | 0.7% | Jan 21, 2022 | Jerryscript 3.0.0 was discovered to contain a stack overflow via vm_loop.lto_priv.304 in /jerry-core/vm/vm.c. |
| CVE-2022-22888 | HIGH | 7.8 | 0.7% | Jan 20, 2022 | Jerryscript 3.0.0 was discovered to contain a stack overflow via ecma_op_object_find_own in /ecma/operations/ecma-object... |
| CVE-2022-23120 | HIGH | 7.8 | 6.4% | Jan 20, 2022 | A code injection vulnerability in Trend Micro Deep Security and Cloud One - Workload Security Agent for Linux version 20... |
| CVE-2022-23119 | HIGH | 7.5 | 22.3% | Jan 20, 2022 | A directory traversal vulnerability in Trend Micro Deep Security and Cloud One - Workload Security Agent for Linux versi... |
| CVE-2022-0282 | HIGH | 7.5 | 1.6% | Jan 20, 2022 | Cross-site Scripting in Packagist microweber/microweber prior to 1.2.11. |
| CVE-2022-0281 | HIGH | 7.5 | 12.0% | Jan 20, 2022 | Exposure of Sensitive Information to an Unauthorized Actor in Packagist microweber/microweber prior to 1.2.11. |
| CVE-2022-21701 | HIGH | 8.8 | 0.8% | Jan 19, 2022 | Istio is an open platform to connect, manage, and secure microservices. In versions 1.12.0 and 1.12.1 Istio is vulnerabl... |
| CVE-2022-21699 | HIGH | 8.8 | 0.7% | Jan 19, 2022 | IPython (Interactive Python) is a command shell for interactive computing in multiple programming languages, originally ... |
| CVE-2022-23046 | HIGH | 7.2 | 25.2% | Jan 19, 2022 | PhpIPAM v1.4.4 allows an authenticated admin user to inject SQL sentences in the "subnet" parameter while searching a su... |
| CVE-2022-21395 | HIGH | 7.2 | 1.2% | Jan 19, 2022 | Vulnerability in the Oracle Communications Operations Monitor product of Oracle Communications (component: Mediation Eng... |
| CVE-2022-21392 | HIGH | 8.8 | 0.6% | Jan 19, 2022 | Vulnerability in the Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Policy Framework)... |
| CVE-2022-21382 | HIGH | 7.7 | 0.9% | Jan 19, 2022 | Vulnerability in the Oracle Enterprise Session Border Controller product of Oracle Communications (component: WebUI). Su... |
| CVE-2022-21371 | HIGH | 7.5 | 92.3% | Jan 19, 2022 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Container). Supported ve... |
| CVE-2022-21351 | HIGH | 7.1 | 1.3% | Jan 19, 2022 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are af... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now