2022 CVE Vulnerabilities
27,528 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-21689 | HIGH | 7.5 | 1.4% | Jan 18, 2022 | OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with frien... |
| CVE-2022-22691 | HIGH | 7.4 | 1.0% | Jan 18, 2022 | The password reset component deployed within Umbraco uses the hostname supplied within the request host header when buil... |
| CVE-2022-22690 | HIGH | 7.5 | 1.1% | Jan 18, 2022 | Within the Umbraco CMS, a configuration element named "UmbracoApplicationUrl" (or just "ApplicationUrl") is used wheneve... |
| CVE-2022-0244 | HIGH | 7.5 | 1.7% | Jan 18, 2022 | An issue has been discovered in GitLab CE/EE affecting all versions starting with 14.5. Arbitrary file read was possible... |
| CVE-2022-0236 | HIGH | 7.5 | 4.3% | Jan 18, 2022 | The WP Import Export WordPress plugin (both free and premium versions) is vulnerable to unauthenticated sensitive data d... |
| CVE-2022-0215 | HIGH | 8.8 | 0.8% | Jan 18, 2022 | The Login/Signup Popup, Waitlist Woocommerce ( Back in stock notifier ), and Side Cart Woocommerce (Ajax) WordPress plug... |
| CVE-2022-0154 | HIGH | 8 | 0.5% | Jan 18, 2022 | An issue has been discovered in GitLab affecting all versions starting from 7.7 before 14.4.5, all versions starting fro... |
| CVE-2022-23307 | HIGH | 8.8 | 52.5% | Jan 18, 2022 | CVE-2020-9493 identified a deserialization issue that was present in Apache Chainsaw. Prior to Chainsaw V2.0 Chainsaw wa... |
| CVE-2022-23302 | HIGH | 8.8 | 61.8% | Jan 18, 2022 | JMSSink in all versions of Log4j 1.x is vulnerable to deserialization of untrusted data when the attacker has write acce... |
| CVE-2022-0263 | HIGH | 7.8 | 1.1% | Jan 18, 2022 | Unrestricted Upload of File with Dangerous Type in Packagist pimcore/pimcore prior to 10.2.7. |
| CVE-2022-0261 | HIGH | 7.8 | 1.7% | Jan 18, 2022 | Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2. |
| CVE-2022-0242 | HIGH | 7.2 | 1.4% | Jan 17, 2022 | Unrestricted Upload of File with Dangerous Type in GitHub repository crater-invoice/crater prior to 6.0. |
| CVE-2022-0258 | HIGH | 8.8 | 1.6% | Jan 17, 2022 | pimcore is vulnerable to Improper Neutralization of Special Elements used in an SQL Command |
| CVE-2022-0240 | HIGH | 7.5 | 1.0% | Jan 17, 2022 | mruby is vulnerable to NULL Pointer Dereference |
| CVE-2022-0180 | HIGH | 8.8 | 0.7% | Jan 17, 2022 | Cross-site request forgery (CSRF) vulnerability in Quiz And Survey Master versions prior to 7.3.7 allows a remote attack... |
| CVE-2022-23095 | HIGH | 7.8 | 1.1% | Jan 15, 2022 | Open Design Alliance Drawings SDK before 2022.12.1 mishandles the loading of JPG files. Unchecked input data from a craf... |
| CVE-2022-23094 | HIGH | 7.5 | 2.7% | Jan 15, 2022 | Libreswan 4.2 through 4.5 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon cras... |
| CVE-2022-22531 | HIGH | 8.1 | 0.8% | Jan 14, 2022 | The F0743 Create Single Payment application of SAP S/4HANA - versions 100, 101, 102, 103, 104, 105, 106, does not check ... |
| CVE-2022-22530 | HIGH | 8.1 | 0.9% | Jan 14, 2022 | The F0743 Create Single Payment application of SAP S/4HANA - versions 100, 101, 102, 103, 104, 105, 106, does not check ... |
| CVE-2022-21137 | HIGH | 7.8 | 9.3% | Jan 14, 2022 | Omron CX-One Versions 4.60 and prior are vulnerable to a stack-based buffer overflow while processing specific project f... |
| CVE-2022-0130 | HIGH | 8.1 | 1.6% | Jan 14, 2022 | Tenable.sc versions 5.14.0 through 5.19.1 were found to contain a remote code execution vulnerability which could allow ... |
| CVE-2022-21681 | HIGH | 7.5 | 2.7% | Jan 14, 2022 | Marked is a markdown parser and compiler. Prior to version 4.0.10, the regular expression `inline.reflinkSearch` may cau... |
| CVE-2022-21680 | HIGH | 7.5 | 2.8% | Jan 14, 2022 | Marked is a markdown parser and compiler. Prior to version 4.0.10, the regular expression `block.def` may cause catastro... |
| CVE-2022-23222 | HIGH | 7.8 | 1.9% | Jan 14, 2022 | kernel/bpf/verifier.c in the Linux kernel through 5.15.14 allows local users to gain privileges because of the availabil... |
| CVE-2022-20698 | HIGH | 7.5 | 3.1% | Jan 14, 2022 | A vulnerability in the OOXML parsing module in Clam AntiVirus (ClamAV) Software version 0.104.1 and LTS version 0.103.4 ... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now