2022 CVE Vulnerabilities
27,543 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-27235 | HIGH | 8.8 | 0.7% | Jul 22, 2022 | Multiple Broken Access Control vulnerabilities in Social Share Buttons by Supsystic plugin <= 2.2.3 at WordPress. |
| CVE-2022-0980 | HIGH | 8.8 | 0.5% | Jul 22, 2022 | Use after free in New Tab Page in Google Chrome prior to 99.0.4844.74 allowed an attacker who convinced a user to instal... |
| CVE-2022-0979 | HIGH | 8.8 | 0.7% | Jul 22, 2022 | Use after free in Safe Browsing in Google Chrome on Android prior to 99.0.4844.74 allowed a remote attacker who convince... |
| CVE-2022-0978 | HIGH | 8.8 | 0.7% | Jul 22, 2022 | Use after free in ANGLE in Google Chrome prior to 99.0.4844.74 allowed a remote attacker to potentially exploit heap cor... |
| CVE-2022-2511 | MEDIUM | 6.1 | 0.4% | Jul 22, 2022 | Cross-site Scripting (XSS) vulnerability in the "commonuserinterface" component of BlueSpice allows an attacker to injec... |
| CVE-2022-2510 | MEDIUM | 6.1 | 0.4% | Jul 22, 2022 | Cross-site Scripting (XSS) vulnerability in "Extension:ExtendedSearch" of Hallo Welt! GmbH BlueSpice allows attacker to ... |
| CVE-2022-28879 | HIGH | 7.5 | 0.4% | Jul 22, 2022 | A Denial-of-Service (DoS) vulnerability was discovered in F-Secure Atlant and in certain WithSecure products whereby the... |
| CVE-2022-28878 | HIGH | 7.5 | 0.4% | Jul 22, 2022 | A Denial-of-Service vulnerability was discovered in the F-Secure Atlant and in certain WithSecure products while scannin... |
| CVE-2022-34983 | CRITICAL | 9.8 | 1.2% | Jul 22, 2022 | The scu-captcha package in PyPI v0.0.1 to v0.0.4 included a code execution backdoor inserted by a third party. |
| CVE-2022-34982 | CRITICAL | 9.8 | 1.1% | Jul 22, 2022 | The eziod package in PyPI before v0.0.1 included a code execution backdoor inserted by a third party. |
| CVE-2022-34981 | CRITICAL | 9.8 | 1.2% | Jul 22, 2022 | The PyCrowdTangle package in PyPI before v0.0.1 included a code execution backdoor inserted by a third party. |
| CVE-2022-34520 | MEDIUM | 5.5 | 0.3% | Jul 22, 2022 | Radare2 v5.7.2 was discovered to contain a NULL pointer dereference via the function r_bin_file_xtr_load_buffer at bin/b... |
| CVE-2022-34509 | CRITICAL | 9.8 | 1.0% | Jul 22, 2022 | The wikifaces package in PyPI v1.0 included a code execution backdoor inserted by a third party. |
| CVE-2022-34503 | MEDIUM | 6.5 | 0.7% | Jul 22, 2022 | QPDF v8.4.2 was discovered to contain a heap buffer overflow via the function QPDF::processXRefStream. This vulnerabilit... |
| CVE-2022-34502 | MEDIUM | 5.5 | 0.3% | Jul 22, 2022 | Radare2 v5.7.0 was discovered to contain a heap buffer overflow via the function consume_encoded_name_new at format/wasm... |
| CVE-2022-34501 | CRITICAL | 9.8 | 1.1% | Jul 22, 2022 | The bin-collection package in PyPI before v0.1 included a code execution backdoor inserted by a third party. |
| CVE-2022-34500 | CRITICAL | 9.8 | 1.1% | Jul 22, 2022 | The bin-collect package in PyPI before v0.1 included a code execution backdoor inserted by a third party. |
| CVE-2022-34037 | HIGH | 7.5 | 1.0% | Jul 22, 2022 | An out-of-bounds read in the rewrite function at /modules/caddyhttp/rewrite/rewrite.go in Caddy v2.5.1 allows attackers ... |
| CVE-2022-2470 | MEDIUM | 6.1 | 0.8% | Jul 22, 2022 | Cross-site Scripting (XSS) - Reflected in GitHub repository microweber/microweber prior to 1.2.21. |
| CVE-2022-2143 | CRITICAL | 9.8 | 59.2% | Jul 22, 2022 | The affected product is vulnerable to two instances of command injection, which may allow an attacker to remotely execut... |
| CVE-2022-2142 | MEDIUM | 5.9 | 0.7% | Jul 22, 2022 | The affected product is vulnerable to a SQL injection with high attack complexity, which may allow an unauthorized attac... |
| CVE-2022-2139 | CRITICAL | 9.8 | 14.8% | Jul 22, 2022 | The affected product is vulnerable to directory traversal, which may allow an attacker to access unauthorized files and ... |
| CVE-2022-2138 | HIGH | 7.5 | 10.9% | Jul 22, 2022 | The affected product is vulnerable due to missing authentication, which may allow an attacker to read or modify sensitiv... |
| CVE-2022-2137 | MEDIUM | 4.9 | 0.7% | Jul 22, 2022 | The affected product is vulnerable to two SQL injections that require high privileges for exploitation and may allow an ... |
| CVE-2022-2136 | MEDIUM | 6.5 | 9.0% | Jul 22, 2022 | The affected product is vulnerable to multiple SQL injections that require low privileges for exploitation and may allow... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now