2022 CVE Vulnerabilities

27,531 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-40739MEDIUM5.4Ragic report generation page has insufficient filtering for special characters. A remote attacker with general user priv...
CVE-2022-39027MEDIUM5.4U-Office Force Forum function has insufficient filtering for special characters. A remote attacker with general user pri...
CVE-2022-39026MEDIUM5.4U-Office Force UserDefault page has insufficient filtering for special characters in the HTTP header fields. A remote at...
CVE-2022-39025MEDIUM6.1U-Office Force PrintMessage function has insufficient filtering for special characters. An unauthenticated remote attack...
CVE-2022-39024MEDIUM6.1U-Office Force Bulletin function has insufficient filtering for special characters. An unauthenticated remote attacker c...
CVE-2022-39023MEDIUM6.5U-Office Force Download function has a path traversal vulnerability. A remote attacker with general user privilege can e...
CVE-2022-39022MEDIUM6.5U-Office Force Download function has a path traversal vulnerability. A remote attacker with general user privilege can e...
CVE-2022-39021MEDIUM6.1U-Office Force login function has an Open Redirect vulnerability. An unauthenticated remote attacker can exploit this vu...
CVE-2022-40617HIGH7.5strongSwan before 5.9.8 allows remote attackers to cause a denial of service in the revocation plugin by sending a craft...
CVE-2022-44034MEDIUM6.4An issue was discovered in the Linux kernel through 6.0.6. drivers/char/pcmcia/scr24x_cs.c has a race condition and resu...
CVE-2022-44033MEDIUM6.4An issue was discovered in the Linux kernel through 6.0.6. drivers/char/pcmcia/cm4040_cs.c has a race condition and resu...
CVE-2022-44032MEDIUM6.4An issue was discovered in the Linux kernel through 6.0.6. drivers/char/pcmcia/cm4000_cs.c has a race condition and resu...
CVE-2022-44023MEDIUM5.3PwnDoc through 0.5.3 might allow remote attackers to identify disabled user account names by leveraging response message...
CVE-2022-44022MEDIUM5.3PwnDoc through 0.5.3 might allow remote attackers to identify valid user account names by leveraging response timings fo...
CVE-2022-44020MEDIUM5.5An issue was discovered in OpenStack Sushy-Tools through 0.21.0 and VirtualBMC through 2.2.2. Changing the boot device c...
CVE-2022-44019HIGH8.8In Total.js 4 before 0e5ace7, /api/common/ping can achieve remote command execution via shell metacharacters in the host...
CVE-2022-42915HIGH8.1curl before 7.86.0 has a double free. If curl is told to use an HTTP proxy for a transfer with a non-HTTP(S) URL, it set...
CVE-2022-41974HIGH7.8multipath-tools 0.7.0 through 0.9.x before 0.9.2 allows local users to obtain root access, as exploited alone or in conj...
CVE-2022-41973HIGH7.8multipath-tools 0.7.7 through 0.9.x before 0.9.2 allows local users to obtain root access, as exploited in conjunction w...
CVE-2022-3757Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2022-3756Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2022-3755Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2022-3754CRITICAL9.8Weak Password Requirements in GitHub repository thorsten/phpmyfaq prior to 3.1.8.
CVE-2022-42916HIGH7.5In curl before 7.86.0, the HSTS check could be bypassed to trick it into staying with HTTP. Using its HSTS support, curl...
CVE-2022-2826CRITICAL9.8An issue has been discovered in GitLab affecting all versions starting from 10.0 before 12.9.8, all versions starting fr...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now