2022 CVE Vulnerabilities

27,528 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-24198MEDIUM6.5iText v7.1.17 was discovered to contain an out-of-bounds exception via the component ARCFOUREncryption.encryptARCFOUR, w...
CVE-2022-24197MEDIUM6.5iText v7.1.17 was discovered to contain a stack-based buffer overflow via the component ByteBuffer.append, which allows ...
CVE-2022-24196MEDIUM6.5iText v7.1.17, up to (exluding)": 7.1.18 and 7.2.2 was discovered to contain an out-of-memory error via the component re...
CVE-2022-0220MEDIUM6.1The check_privacy_settings AJAX action of the WordPress GDPR WordPress plugin before 1.9.27, available to both unauthent...
CVE-2022-21687MEDIUM6.5gh-ost is a triggerless online schema migration solution for MySQL. Versions prior to 1.1.3 are subject to an arbitrary ...
CVE-2022-23607MEDIUM6.5treq is an HTTP library inspired by requests but written on top of Twisted's Agents. Treq's request methods (`treq.get`,...
CVE-2022-23603MEDIUM6.1iTunesRPC-Remastered is a discord rich presence application for use with iTunes & Apple Music. In code before commit 24f...
CVE-2022-0419MEDIUM5.5NULL Pointer Dereference in GitHub repository radareorg/radare2 prior to 5.6.0.
CVE-2022-23774MEDIUM5.3Docker Desktop before 4.4.4 on Windows allows attackers to move arbitrary files.
CVE-2022-23872MEDIUM4.8Emlog pro v1.1.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the component /admin/con...
CVE-2022-21659MEDIUM5.3Flask-AppBuilder is an application development framework, built on top of the Flask web framework. In affected versions ...
CVE-2022-0286MEDIUM5.5A flaw was found in the Linux kernel. A null pointer dereference in bond_ipsec_add_sa() may lead to local denial of serv...
CVE-2022-0414MEDIUM4.3Improper Validation of Specified Quantity in Input in Packagist dolibarr/dolibarr prior to 16.0.
CVE-2022-23409MEDIUM4.9The Logs plugin before 3.0.4 for Craft CMS allows remote attackers to read arbitrary files via input to actionStream in ...
CVE-2022-24130MEDIUM5.5xterm through Patch 370, when Sixel support is enabled, allows attackers to trigger a buffer overflow in set_sixel in gr...
CVE-2022-0273MEDIUM6.5Improper Access Control in Pypi calibreweb prior to 0.6.16.
CVE-2022-22919MEDIUM6.1Adenza AxiomSL ControllerView through 10.8.1 allows redirection for SSO login URLs.
CVE-2022-24032MEDIUM5.3Adenza AxiomSL ControllerView through 10.8.1 is vulnerable to user enumeration. An attacker can identify valid usernames...
CVE-2022-23599MEDIUM6.1Products.ATContentTypes are the core content types for Plone 2.1 - 4.3. Versions of Plone that are dependent on Products...
CVE-2022-23598MEDIUM6.1laminas-form is a package for validating and displaying simple and complex forms. When rendering validation error messag...
CVE-2022-0395MEDIUM5.4Cross-site Scripting (XSS) - Stored in Packagist remdex/livehelperchat prior to 3.93v.
CVE-2022-0352MEDIUM6.1Cross-site Scripting (XSS) - Reflected in Pypi calibreweb prior to 0.6.16.
CVE-2022-23889MEDIUM5.3The comment function in YzmCMS v6.3 was discovered as being able to be operated concurrently, allowing attackers to crea...
CVE-2022-23887MEDIUM6.5YzmCMS v6.3 was discovered to contain a Cross-Site Request Forgery (CSRF) which allows attackers to arbitrarily delete u...
CVE-2022-23979MEDIUM4.8Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability discovered in Ultimate Reviews WordPress plugin (...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now