2022 CVE Vulnerabilities

27,528 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-22117MEDIUM5.4In Directus, versions 9.0.0-alpha.4 through 9.4.1 allow unrestricted file upload of .html files in the media upload func...
CVE-2022-22116MEDIUM5.4In Directus, versions 9.0.0-alpha.4 through 9.4.1 are vulnerable to stored Cross-Site Scripting (XSS) vulnerability via ...
CVE-2022-0157MEDIUM5.4phoronix-test-suite is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'...
CVE-2022-0156MEDIUM5.5vim is vulnerable to Use After Free
CVE-2022-22846MEDIUM5.3The dnslib package through 0.9.16 for Python does not verify that the ID value in a DNS reply matches an ID value in a q...
CVE-2022-22844MEDIUM5.5LibTIFF 4.3.0 has an out-of-bounds read in _TIFFmemcpy in tif_unix.c in certain situations involving a custom tag and 0x...
CVE-2022-22836MEDIUM6.5CoreFTP Server before 727 allows directory traversal (for file creation) by an authenticated attacker via ../ in an HTTP...
CVE-2022-22821MEDIUM4.4NVIDIA NeMo before 1.6.0 contains a vulnerability in ASR WebApp, in which ../ Path Traversal may lead to deletion of any...
CVE-2022-22816MEDIUM6.5path_getbbox in path.c in Pillow before 9.0.0 has a buffer over-read during initialization of ImagePath.Path.
CVE-2022-22815MEDIUM6.5path_getbbox in path.c in Pillow before 9.0.0 improperly initializes ImagePath.Path.
CVE-2022-22702MEDIUM4.3PartKeepr versions up to v1.4.0, in the functionality to upload attachments using a URL when creating a part does not va...
CVE-2022-22701MEDIUM6.5PartKeepr versions up to v1.4.0, loads attachments using a URL while creating a part and allows the use of the 'file://'...
CVE-2022-22289MEDIUM5.3Improper access control vulnerability in S Assistant prior to version 7.5 allows attacker to remotely get senstive infor...
CVE-2022-22287MEDIUM4.6Abitrary file access vulnerability in Samsung Email prior to 6.1.60.16 allows attacker to read isolated data in sandbox.
CVE-2022-22284MEDIUM5.5Improper authentication vulnerability in Samsung Internet prior to 16.0.2.19 allows attackers to bypass secret mode pass...
CVE-2022-22271MEDIUM5.5A missing input validation before memory copy in TIMA trustlet prior to SMR Jan-2022 Release 1 allows attackers to copy ...
CVE-2022-22268MEDIUM6.1Incorrect implementation of Knox Guard prior to SMR Jan-2022 Release 1 allows physically proximate attackers to temporar...
CVE-2022-22263MEDIUM5.5Unprotected dynamic receiver in SecSettings prior to SMR Jan-2022 Release 1 allows untrusted applications to launch arbi...
CVE-2022-21823MEDIUM5.5A insecure storage of sensitive information vulnerability exists in Ivanti Workspace Control <2021.2 (10.7.30.0) that co...
CVE-2022-21662MEDIUM5.4WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. Low-pri...
CVE-2022-22707MEDIUM5.9In lighttpd 1.4.46 through 1.4.63, the mod_extforward_Forwarded function of the mod_extforward plugin has a stack-based ...
CVE-2022-0122MEDIUM6.1forge is vulnerable to URL Redirection to Untrusted Site
CVE-2022-21651MEDIUM6.1Shopware is an open source e-commerce software platform. An open redirect vulnerability has been discovered. Users may b...
CVE-2022-21642MEDIUM4.3Discourse is an open source platform for community discussion. In affected versions when composing a message from topic ...
CVE-2022-22109MEDIUM5.4In Daybyday CRM, version 2.2.0 is vulnerable to Stored Cross-Site Scripting (XSS) vulnerability that allows low privileg...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now