2022 CVE Vulnerabilities
27,528 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-22117 | MEDIUM | 5.4 | 0.6% | Jan 10, 2022 | In Directus, versions 9.0.0-alpha.4 through 9.4.1 allow unrestricted file upload of .html files in the media upload func... |
| CVE-2022-22116 | MEDIUM | 5.4 | 0.6% | Jan 10, 2022 | In Directus, versions 9.0.0-alpha.4 through 9.4.1 are vulnerable to stored Cross-Site Scripting (XSS) vulnerability via ... |
| CVE-2022-0157 | MEDIUM | 5.4 | 1.1% | Jan 10, 2022 | phoronix-test-suite is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'... |
| CVE-2022-0156 | MEDIUM | 5.5 | 1.7% | Jan 10, 2022 | vim is vulnerable to Use After Free |
| CVE-2022-22846 | MEDIUM | 5.3 | 0.8% | Jan 10, 2022 | The dnslib package through 0.9.16 for Python does not verify that the ID value in a DNS reply matches an ID value in a q... |
| CVE-2022-22844 | MEDIUM | 5.5 | 1.3% | Jan 10, 2022 | LibTIFF 4.3.0 has an out-of-bounds read in _TIFFmemcpy in tif_unix.c in certain situations involving a custom tag and 0x... |
| CVE-2022-22836 | MEDIUM | 6.5 | 5.4% | Jan 10, 2022 | CoreFTP Server before 727 allows directory traversal (for file creation) by an authenticated attacker via ../ in an HTTP... |
| CVE-2022-22821 | MEDIUM | 4.4 | 0.3% | Jan 10, 2022 | NVIDIA NeMo before 1.6.0 contains a vulnerability in ASR WebApp, in which ../ Path Traversal may lead to deletion of any... |
| CVE-2022-22816 | MEDIUM | 6.5 | 2.0% | Jan 10, 2022 | path_getbbox in path.c in Pillow before 9.0.0 has a buffer over-read during initialization of ImagePath.Path. |
| CVE-2022-22815 | MEDIUM | 6.5 | 2.6% | Jan 10, 2022 | path_getbbox in path.c in Pillow before 9.0.0 improperly initializes ImagePath.Path. |
| CVE-2022-22702 | MEDIUM | 4.3 | 0.7% | Jan 10, 2022 | PartKeepr versions up to v1.4.0, in the functionality to upload attachments using a URL when creating a part does not va... |
| CVE-2022-22701 | MEDIUM | 6.5 | 1.0% | Jan 10, 2022 | PartKeepr versions up to v1.4.0, loads attachments using a URL while creating a part and allows the use of the 'file://'... |
| CVE-2022-22289 | MEDIUM | 5.3 | 0.8% | Jan 10, 2022 | Improper access control vulnerability in S Assistant prior to version 7.5 allows attacker to remotely get senstive infor... |
| CVE-2022-22287 | MEDIUM | 4.6 | 0.2% | Jan 10, 2022 | Abitrary file access vulnerability in Samsung Email prior to 6.1.60.16 allows attacker to read isolated data in sandbox. |
| CVE-2022-22284 | MEDIUM | 5.5 | 0.2% | Jan 10, 2022 | Improper authentication vulnerability in Samsung Internet prior to 16.0.2.19 allows attackers to bypass secret mode pass... |
| CVE-2022-22271 | MEDIUM | 5.5 | 0.1% | Jan 10, 2022 | A missing input validation before memory copy in TIMA trustlet prior to SMR Jan-2022 Release 1 allows attackers to copy ... |
| CVE-2022-22268 | MEDIUM | 6.1 | 0.1% | Jan 10, 2022 | Incorrect implementation of Knox Guard prior to SMR Jan-2022 Release 1 allows physically proximate attackers to temporar... |
| CVE-2022-22263 | MEDIUM | 5.5 | 0.1% | Jan 10, 2022 | Unprotected dynamic receiver in SecSettings prior to SMR Jan-2022 Release 1 allows untrusted applications to launch arbi... |
| CVE-2022-21823 | MEDIUM | 5.5 | 0.3% | Jan 10, 2022 | A insecure storage of sensitive information vulnerability exists in Ivanti Workspace Control <2021.2 (10.7.30.0) that co... |
| CVE-2022-21662 | MEDIUM | 5.4 | 64.7% | Jan 6, 2022 | WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. Low-pri... |
| CVE-2022-22707 | MEDIUM | 5.9 | 9.0% | Jan 6, 2022 | In lighttpd 1.4.46 through 1.4.63, the mod_extforward_Forwarded function of the mod_extforward plugin has a stack-based ... |
| CVE-2022-0122 | MEDIUM | 6.1 | 0.8% | Jan 6, 2022 | forge is vulnerable to URL Redirection to Untrusted Site |
| CVE-2022-21651 | MEDIUM | 6.1 | 0.8% | Jan 5, 2022 | Shopware is an open source e-commerce software platform. An open redirect vulnerability has been discovered. Users may b... |
| CVE-2022-21642 | MEDIUM | 4.3 | 0.7% | Jan 5, 2022 | Discourse is an open source platform for community discussion. In affected versions when composing a message from topic ... |
| CVE-2022-22109 | MEDIUM | 5.4 | 0.5% | Jan 5, 2022 | In Daybyday CRM, version 2.2.0 is vulnerable to Stored Cross-Site Scripting (XSS) vulnerability that allows low privileg... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now