2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-0724 | MEDIUM | 6.5 | 1.3% | Feb 23, 2022 | Insecure Storage of Sensitive Information in GitHub repository microweber/microweber prior to 1.3. |
| CVE-2022-0721 | MEDIUM | 6.5 | 1.4% | Feb 23, 2022 | Insertion of Sensitive Information Into Debugging Code in GitHub repository microweber/microweber prior to 1.3. |
| CVE-2022-0719 | MEDIUM | 5.4 | 0.9% | Feb 23, 2022 | Cross-site Scripting (XSS) - Reflected in GitHub repository microweber/microweber prior to 1.3. |
| CVE-2022-23606 | MEDIUM | 6.5 | 1.0% | Feb 22, 2022 | Envoy is an open source edge and service proxy, designed for cloud-native applications. When a cluster is deleted via Cl... |
| CVE-2022-21657 | MEDIUM | 6.5 | 0.5% | Feb 22, 2022 | Envoy is an open source edge and service proxy, designed for cloud-native applications. In affected versions Envoy does ... |
| CVE-2022-21656 | MEDIUM | 5.9 | 0.8% | Feb 22, 2022 | Envoy is an open source edge and service proxy, designed for cloud-native applications. The default_validator.cc impleme... |
| CVE-2022-23654 | MEDIUM | 6.5 | 0.7% | Feb 22, 2022 | Wiki.js is a wiki app built on Node.js. In affected versions an authenticated user with write access on a restricted set... |
| CVE-2022-0714 | MEDIUM | 5.5 | 12.8% | Feb 22, 2022 | Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.4436. |
| CVE-2022-0712 | MEDIUM | 5.5 | 0.9% | Feb 22, 2022 | NULL Pointer Dereference in GitHub repository radareorg/radare2 prior to 5.6.4. |
| CVE-2022-0665 | MEDIUM | 6.5 | 1.5% | Feb 22, 2022 | Path Traversal in GitHub repository pimcore/pimcore prior to 10.3.2. |
| CVE-2022-24564 | MEDIUM | 6.1 | 0.7% | Feb 21, 2022 | Checkmk <=2.0.0p19 contains a Cross Site Scripting (XSS) vulnerability. While creating or editing a user attribute, the ... |
| CVE-2022-0696 | MEDIUM | 5.5 | 1.5% | Feb 21, 2022 | NULL Pointer Dereference in GitHub repository vim/vim prior to 8.2.4428. |
| CVE-2022-0563 | MEDIUM | 5.5 | 0.4% | Feb 21, 2022 | A flaw was found in the util-linux chfn and chsh utilities when compiled with Readline support. The Readline library use... |
| CVE-2022-25599 | MEDIUM | 4.3 | 0.4% | Feb 21, 2022 | Cross-Site Request Forgery (CSRF) vulnerability leading to event deletion was discovered in Spiffy Calendar WordPress pl... |
| CVE-2022-0708 | MEDIUM | 6.5 | 0.8% | Feb 21, 2022 | Mattermost 6.3.0 and earlier fails to protect email addresses of the creator of the team via one of the APIs, which allo... |
| CVE-2022-0564 | MEDIUM | 5.3 | 1.4% | Feb 21, 2022 | A vulnerability in Qlik Sense Enterprise on Windows could allow an remote attacker to enumerate domain user accounts. An... |
| CVE-2022-0692 | MEDIUM | 6.1 | 3.4% | Feb 21, 2022 | Open Redirect on Rudloff/alltube in Packagist rudloff/alltube prior to 3.0.1. |
| CVE-2022-0313 | MEDIUM | 4.3 | 0.5% | Feb 21, 2022 | The Float menu WordPress plugin before 4.3.1 does not have CSRF check in place when deleting menu, which could allow att... |
| CVE-2022-0288 | MEDIUM | 6.1 | 2.4% | Feb 21, 2022 | The Ad Inserter WordPress plugin before 2.7.10, Ad Inserter Pro WordPress plugin before 2.7.10 do not sanitise and escap... |
| CVE-2022-0252 | MEDIUM | 6.1 | 0.9% | Feb 21, 2022 | The GiveWP WordPress plugin before 2.17.3 does not escape the json parameter before outputting it back in an attribute i... |
| CVE-2022-0234 | MEDIUM | 6.1 | 1.8% | Feb 21, 2022 | The WOOCS WordPress plugin before 1.3.7.5 does not sanitise and escape the woocs_in_order_currency parameter of the wooc... |
| CVE-2022-0211 | MEDIUM | 4.8 | 0.6% | Feb 21, 2022 | The Shield Security WordPress plugin before 13.0.6 does not sanitise and escape admin notes, which could allow high priv... |
| CVE-2022-0199 | MEDIUM | 4.3 | 0.5% | Feb 21, 2022 | The Coming soon and Maintenance mode WordPress plugin before 3.6.8 does not have CSRF check in its coming_soon_send_mail... |
| CVE-2022-0186 | MEDIUM | 5.4 | 0.6% | Feb 21, 2022 | The Image Photo Gallery Final Tiles Grid WordPress plugin before 3.5.3 does not sanitise and escape the Description fiel... |
| CVE-2022-0164 | MEDIUM | 4.3 | 0.3% | Feb 21, 2022 | The Coming soon and Maintenance mode WordPress plugin before 3.5.3 does not have authorisation and CSRF checks in its co... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now