2022 CVE Vulnerabilities

27,543 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-27235HIGH8.8Multiple Broken Access Control vulnerabilities in Social Share Buttons by Supsystic plugin <= 2.2.3 at WordPress.
CVE-2022-0980HIGH8.8Use after free in New Tab Page in Google Chrome prior to 99.0.4844.74 allowed an attacker who convinced a user to instal...
CVE-2022-0979HIGH8.8Use after free in Safe Browsing in Google Chrome on Android prior to 99.0.4844.74 allowed a remote attacker who convince...
CVE-2022-0978HIGH8.8Use after free in ANGLE in Google Chrome prior to 99.0.4844.74 allowed a remote attacker to potentially exploit heap cor...
CVE-2022-2511MEDIUM6.1Cross-site Scripting (XSS) vulnerability in the "commonuserinterface" component of BlueSpice allows an attacker to injec...
CVE-2022-2510MEDIUM6.1Cross-site Scripting (XSS) vulnerability in "Extension:ExtendedSearch" of Hallo Welt! GmbH BlueSpice allows attacker to ...
CVE-2022-28879HIGH7.5A Denial-of-Service (DoS) vulnerability was discovered in F-Secure Atlant and in certain WithSecure products whereby the...
CVE-2022-28878HIGH7.5A Denial-of-Service vulnerability was discovered in the F-Secure Atlant and in certain WithSecure products while scannin...
CVE-2022-34983CRITICAL9.8The scu-captcha package in PyPI v0.0.1 to v0.0.4 included a code execution backdoor inserted by a third party.
CVE-2022-34982CRITICAL9.8The eziod package in PyPI before v0.0.1 included a code execution backdoor inserted by a third party.
CVE-2022-34981CRITICAL9.8The PyCrowdTangle package in PyPI before v0.0.1 included a code execution backdoor inserted by a third party.
CVE-2022-34520MEDIUM5.5Radare2 v5.7.2 was discovered to contain a NULL pointer dereference via the function r_bin_file_xtr_load_buffer at bin/b...
CVE-2022-34509CRITICAL9.8The wikifaces package in PyPI v1.0 included a code execution backdoor inserted by a third party.
CVE-2022-34503MEDIUM6.5QPDF v8.4.2 was discovered to contain a heap buffer overflow via the function QPDF::processXRefStream. This vulnerabilit...
CVE-2022-34502MEDIUM5.5Radare2 v5.7.0 was discovered to contain a heap buffer overflow via the function consume_encoded_name_new at format/wasm...
CVE-2022-34501CRITICAL9.8The bin-collection package in PyPI before v0.1 included a code execution backdoor inserted by a third party.
CVE-2022-34500CRITICAL9.8The bin-collect package in PyPI before v0.1 included a code execution backdoor inserted by a third party.
CVE-2022-34037HIGH7.5An out-of-bounds read in the rewrite function at /modules/caddyhttp/rewrite/rewrite.go in Caddy v2.5.1 allows attackers ...
CVE-2022-2470MEDIUM6.1Cross-site Scripting (XSS) - Reflected in GitHub repository microweber/microweber prior to 1.2.21.
CVE-2022-2143CRITICAL9.8The affected product is vulnerable to two instances of command injection, which may allow an attacker to remotely execut...
CVE-2022-2142MEDIUM5.9The affected product is vulnerable to a SQL injection with high attack complexity, which may allow an unauthorized attac...
CVE-2022-2139CRITICAL9.8The affected product is vulnerable to directory traversal, which may allow an attacker to access unauthorized files and ...
CVE-2022-2138HIGH7.5The affected product is vulnerable due to missing authentication, which may allow an attacker to read or modify sensitiv...
CVE-2022-2137MEDIUM4.9The affected product is vulnerable to two SQL injections that require high privileges for exploitation and may allow an ...
CVE-2022-2136MEDIUM6.5The affected product is vulnerable to multiple SQL injections that require low privileges for exploitation and may allow...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now