2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-25323 | MEDIUM | 6.1 | 3.2% | Feb 18, 2022 | ZEROF Web Server 2.0 allows /admin.back XSS. |
| CVE-2022-23647 | MEDIUM | 6.1 | 1.5% | Feb 18, 2022 | Prism is a syntax highlighting library. Starting with version 1.14.0 and prior to version 1.27.0, Prism's command line p... |
| CVE-2022-0451 | MEDIUM | 6.5 | 1.0% | Feb 18, 2022 | Dart SDK contains the HTTPClient in dart:io library whcih includes authorization headers when handling cross origin redi... |
| CVE-2022-25321 | MEDIUM | 6.1 | 1.1% | Feb 18, 2022 | An issue was discovered in Cerebrate through 1.4. XSS could occur in the bookmarks component. |
| CVE-2022-25320 | MEDIUM | 5.3 | 0.9% | Feb 18, 2022 | An issue was discovered in Cerebrate through 1.4. Username enumeration could occur. |
| CVE-2022-25319 | MEDIUM | 5.3 | 1.3% | Feb 18, 2022 | An issue was discovered in Cerebrate through 1.4. Endpoints could be open even when not enabled. |
| CVE-2022-25318 | MEDIUM | 4.3 | 0.6% | Feb 18, 2022 | An issue was discovered in Cerebrate through 1.4. An incorrect sharing group ACL allowed an unprivileged user to edit an... |
| CVE-2022-25317 | MEDIUM | 6.1 | 0.6% | Feb 18, 2022 | An issue was discovered in Cerebrate through 1.4. genericForm allows reflected XSS in form descriptions via a user-contr... |
| CVE-2022-25313 | MEDIUM | 6.5 | 3.3% | Feb 18, 2022 | In Expat (aka libexpat) before 2.4.5, an attacker can trigger stack exhaustion in build_model via a large nesting depth ... |
| CVE-2022-0633 | MEDIUM | 6.5 | 2.0% | Feb 17, 2022 | The UpdraftPlus WordPress plugin Free before 1.22.3 and Premium before 2.22.3 do not properly validate a user has the re... |
| CVE-2022-0639 | MEDIUM | 5.3 | 1.5% | Feb 17, 2022 | Authorization Bypass Through User-Controlled Key in NPM url-parse prior to 1.5.7. |
| CVE-2022-0638 | MEDIUM | 4.3 | 0.4% | Feb 17, 2022 | Cross-Site Request Forgery (CSRF) in Packagist microweber/microweber prior to 1.2.11. |
| CVE-2022-20659 | MEDIUM | 6.1 | 1.2% | Feb 17, 2022 | A vulnerability in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Netwo... |
| CVE-2022-23319 | MEDIUM | 5.5 | 0.7% | Feb 17, 2022 | A segmentation fault during PCF file parsing in pcf2bdf versions >=1.05 allows an attacker to trigger a program crash vi... |
| CVE-2022-22899 | MEDIUM | 5.5 | 1.0% | Feb 17, 2022 | Core FTP / SFTP Server v2 Build 725 was discovered to allow unauthenticated attackers to cause a Denial of Service (DoS)... |
| CVE-2022-24953 | MEDIUM | 5.3 | 0.8% | Feb 17, 2022 | The Crypt_GPG extension before 1.6.7 for PHP does not prevent additional options in GPG calls, which presents a risk for... |
| CVE-2022-22901 | MEDIUM | 5.5 | 0.8% | Feb 17, 2022 | There is an Assertion in 'context_p->next_scanner_info_p->type == SCANNER_TYPE_FUNCTION' failed at parser_parse_function... |
| CVE-2022-0622 | MEDIUM | 5.3 | 1.0% | Feb 17, 2022 | Generation of Error Message Containing Sensitive Information in Packagist snipe/snipe-it prior to 5.3.11. |
| CVE-2022-25270 | MEDIUM | 6.5 | 0.8% | Feb 17, 2022 | The Quick Edit module does not properly check entity access in some circumstances. This could result in users with the "... |
| CVE-2022-24982 | MEDIUM | 6.5 | 1.2% | Feb 16, 2022 | Forms generated by JQueryForm.com before 2022-02-05 allows a remote authenticated attacker to access the cleartext crede... |
| CVE-2022-24981 | MEDIUM | 6.1 | 1.0% | Feb 16, 2022 | A reflected cross-site scripting (XSS) vulnerability in forms generated by JQueryForm.com before 2022-02-05 allows remot... |
| CVE-2022-25258 | MEDIUM | 4.6 | 0.9% | Feb 16, 2022 | An issue was discovered in drivers/usb/gadget/composite.c in the Linux kernel before 5.16.10. The USB Gadget subsystem l... |
| CVE-2022-22853 | MEDIUM | 5.4 | 0.8% | Feb 16, 2022 | A stored cross-site scripting (XSS) vulnerability in Hospital Patient Record Management System v1.0 allows attackers to ... |
| CVE-2022-23204 | MEDIUM | 5.5 | 1.9% | Feb 16, 2022 | Adobe Premiere Rush versions 2.0 and earlier are affected by an out-of-bounds read vulnerability that could lead to disc... |
| CVE-2022-23199 | MEDIUM | 5.5 | 1.7% | Feb 16, 2022 | Adobe Illustrator versions 25.4.3 (and earlier) and 26.0.2 (and earlier) are affected by a Null pointer dereference vuln... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now