2022 CVE Vulnerabilities
27,528 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-24198 | MEDIUM | 6.5 | 0.5% | Feb 1, 2022 | iText v7.1.17 was discovered to contain an out-of-bounds exception via the component ARCFOUREncryption.encryptARCFOUR, w... |
| CVE-2022-24197 | MEDIUM | 6.5 | 1.5% | Feb 1, 2022 | iText v7.1.17 was discovered to contain a stack-based buffer overflow via the component ByteBuffer.append, which allows ... |
| CVE-2022-24196 | MEDIUM | 6.5 | 1.6% | Feb 1, 2022 | iText v7.1.17, up to (exluding)": 7.1.18 and 7.2.2 was discovered to contain an out-of-memory error via the component re... |
| CVE-2022-0220 | MEDIUM | 6.1 | 2.3% | Feb 1, 2022 | The check_privacy_settings AJAX action of the WordPress GDPR WordPress plugin before 1.9.27, available to both unauthent... |
| CVE-2022-21687 | MEDIUM | 6.5 | 1.0% | Feb 1, 2022 | gh-ost is a triggerless online schema migration solution for MySQL. Versions prior to 1.1.3 are subject to an arbitrary ... |
| CVE-2022-23607 | MEDIUM | 6.5 | 1.1% | Feb 1, 2022 | treq is an HTTP library inspired by requests but written on top of Twisted's Agents. Treq's request methods (`treq.get`,... |
| CVE-2022-23603 | MEDIUM | 6.1 | 1.0% | Feb 1, 2022 | iTunesRPC-Remastered is a discord rich presence application for use with iTunes & Apple Music. In code before commit 24f... |
| CVE-2022-0419 | MEDIUM | 5.5 | 0.9% | Feb 1, 2022 | NULL Pointer Dereference in GitHub repository radareorg/radare2 prior to 5.6.0. |
| CVE-2022-23774 | MEDIUM | 5.3 | 0.9% | Feb 1, 2022 | Docker Desktop before 4.4.4 on Windows allows attackers to move arbitrary files. |
| CVE-2022-23872 | MEDIUM | 4.8 | 0.6% | Jan 31, 2022 | Emlog pro v1.1.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the component /admin/con... |
| CVE-2022-21659 | MEDIUM | 5.3 | 1.0% | Jan 31, 2022 | Flask-AppBuilder is an application development framework, built on top of the Flask web framework. In affected versions ... |
| CVE-2022-0286 | MEDIUM | 5.5 | 0.5% | Jan 31, 2022 | A flaw was found in the Linux kernel. A null pointer dereference in bond_ipsec_add_sa() may lead to local denial of serv... |
| CVE-2022-0414 | MEDIUM | 4.3 | 1.1% | Jan 31, 2022 | Improper Validation of Specified Quantity in Input in Packagist dolibarr/dolibarr prior to 16.0. |
| CVE-2022-23409 | MEDIUM | 4.9 | 13.8% | Jan 31, 2022 | The Logs plugin before 3.0.4 for Craft CMS allows remote attackers to read arbitrary files via input to actionStream in ... |
| CVE-2022-24130 | MEDIUM | 5.5 | 1.7% | Jan 31, 2022 | xterm through Patch 370, when Sixel support is enabled, allows attackers to trigger a buffer overflow in set_sixel in gr... |
| CVE-2022-0273 | MEDIUM | 6.5 | 0.7% | Jan 30, 2022 | Improper Access Control in Pypi calibreweb prior to 0.6.16. |
| CVE-2022-22919 | MEDIUM | 6.1 | 0.6% | Jan 30, 2022 | Adenza AxiomSL ControllerView through 10.8.1 allows redirection for SSO login URLs. |
| CVE-2022-24032 | MEDIUM | 5.3 | 1.0% | Jan 30, 2022 | Adenza AxiomSL ControllerView through 10.8.1 is vulnerable to user enumeration. An attacker can identify valid usernames... |
| CVE-2022-23599 | MEDIUM | 6.1 | 0.7% | Jan 28, 2022 | Products.ATContentTypes are the core content types for Plone 2.1 - 4.3. Versions of Plone that are dependent on Products... |
| CVE-2022-23598 | MEDIUM | 6.1 | 1.0% | Jan 28, 2022 | laminas-form is a package for validating and displaying simple and complex forms. When rendering validation error messag... |
| CVE-2022-0395 | MEDIUM | 5.4 | 0.6% | Jan 28, 2022 | Cross-site Scripting (XSS) - Stored in Packagist remdex/livehelperchat prior to 3.93v. |
| CVE-2022-0352 | MEDIUM | 6.1 | 0.9% | Jan 28, 2022 | Cross-site Scripting (XSS) - Reflected in Pypi calibreweb prior to 0.6.16. |
| CVE-2022-23889 | MEDIUM | 5.3 | 1.1% | Jan 28, 2022 | The comment function in YzmCMS v6.3 was discovered as being able to be operated concurrently, allowing attackers to crea... |
| CVE-2022-23887 | MEDIUM | 6.5 | 0.7% | Jan 28, 2022 | YzmCMS v6.3 was discovered to contain a Cross-Site Request Forgery (CSRF) which allows attackers to arbitrarily delete u... |
| CVE-2022-23979 | MEDIUM | 4.8 | 0.6% | Jan 28, 2022 | Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability discovered in Ultimate Reviews WordPress plugin (... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now