2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-3415MEDIUM6.1The Chat Bubble WordPress plugin before 2.3 does not sanitise and escape some contact parameters, which could allow unau...
CVE-2022-2450MEDIUM4.3The reSmush.it : the only free Image Optimizer & compress plugin WordPress plugin before 0.4.4 lacks authorization in va...
CVE-2022-2449MEDIUM6.5The reSmush.it : the only free Image Optimizer & compress plugin WordPress plugin before 0.4.4 does not perform CSRF che...
CVE-2022-45378CRITICAL9.8In the default configuration of Apache SOAP, an RPCRouterServlet is available without authentication. This gives an atta...
CVE-2022-3988MEDIUM6.1A vulnerability was found in Frappe. It has been rated as problematic. Affected by this issue is some unknown functional...
CVE-2022-40127HIGH8.8A vulnerability in Example Dags of Apache Airflow allows an attacker with UI access who can trigger DAGs, to execute arb...
CVE-2022-27949HIGH7.5A vulnerability in UI of Apache Airflow allows an attacker to view unmasked secrets in rendered template values for task...
CVE-2022-45184HIGH7.2The Web Server in Ironman Software PowerShell Universal v3.x and v2.x allows for directory traversal outside of the conf...
CVE-2022-45183HIGH8.8Escalation of privileges in the Web Server in Ironman Software PowerShell Universal 2.x and 3.x allows an attacker with ...
CVE-2022-37290MEDIUM5.5GNOME Nautilus 42.2 allows a NULL pointer dereference and get_basename application crash via a pasted ZIP archive.
CVE-2022-45199HIGH7.5Pillow before 9.3.0 allows denial of service via SAMPLESPERPIXEL.
CVE-2022-45198HIGH7.5Pillow before 9.2.0 performs Improper Handling of Highly Compressed GIF Data (Data Amplification).
CVE-2022-31630HIGH7.1In PHP versions prior to 7.4.33, 8.0.25 and 8.1.12, when using imageloadfont() function in gd extension, it is possible ...
CVE-2022-3979HIGH8.1A vulnerability was found in NagVis up to 1.9.33 and classified as problematic. This issue affects the function checkAut...
CVE-2022-3978MEDIUM4.3A vulnerability, which was classified as problematic, was found in NodeBB up to 2.5.7. This affects an unknown part of t...
CVE-2022-3976HIGH8.8A vulnerability has been found in MZ Automation libiec61850 up to 1.4 and classified as critical. This vulnerability aff...
CVE-2022-3975MEDIUM6.1A vulnerability, which was classified as problematic, has been found in NukeViet CMS. Affected by this issue is the func...
CVE-2022-3974HIGH8.8A vulnerability classified as critical was found in Axiomatic Bento4. Affected by this vulnerability is the function AP4...
CVE-2022-3973CRITICAL9.8A vulnerability classified as critical has been found in Pingkon HMS-PHP. Affected is an unknown function of the file /a...
CVE-2022-3972CRITICAL9.8A vulnerability was found in Pingkon HMS-PHP. It has been rated as critical. This issue affects some unknown processing ...
CVE-2022-3971MEDIUM5.6A vulnerability was found in matrix-appservice-irc up to 0.35.1. It has been declared as critical. This vulnerability af...
CVE-2022-3970HIGH8.8A vulnerability was found in LibTIFF. It has been classified as critical. This affects the function TIFFReadRGBATileExt ...
CVE-2022-3969MEDIUM5.5A vulnerability was found in OpenKM up to 6.3.11 and classified as problematic. Affected by this issue is the function g...
CVE-2022-3968MEDIUM6.1A vulnerability has been found in emlog and classified as problematic. Affected by this vulnerability is an unknown func...
CVE-2022-3967HIGH7.8A vulnerability, which was classified as critical, was found in Vesta Control Panel. Affected is an unknown function of ...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now