2022 CVE Vulnerabilities
27,552 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-34060 | CRITICAL | 9.8 | 1.9% | Jun 24, 2022 | The Togglee package in PyPI version v0.0.8 was discovered to contain a code execution backdoor. This vulnerability allow... |
| CVE-2022-34059 | CRITICAL | 9.8 | 1.9% | Jun 24, 2022 | The Sixfab-Tool in PyPI v0.0.2 to v0.0.3 was discovered to contain a code execution backdoor via the request package. Th... |
| CVE-2022-34057 | CRITICAL | 9.8 | 1.3% | Jun 24, 2022 | The Scoptrial package in PyPI version v0.0.5 was discovered to contain a code execution backdoor via the request package... |
| CVE-2022-34056 | CRITICAL | 9.8 | 1.9% | Jun 24, 2022 | The Watertools package in PyPI v0.0.0 was discovered to contain a code execution backdoor via the request package. This ... |
| CVE-2022-34055 | CRITICAL | 9.8 | 1.9% | Jun 24, 2022 | The drxhello package in PyPI v0.0.1 was discovered to contain a code execution backdoor via the request package. This vu... |
| CVE-2022-34054 | CRITICAL | 9.8 | 1.9% | Jun 24, 2022 | The Perdido package in PyPI v0.0.1 to v0.0.2 was discovered to contain a code execution backdoor via the request package... |
| CVE-2022-34053 | CRITICAL | 9.8 | 1.9% | Jun 24, 2022 | The DR-Web-Engine package in PyPI v0.2.0b0 was discovered to contain a code execution backdoor via the request package. ... |
| CVE-2022-33122 | MEDIUM | 4.8 | 0.5% | Jun 24, 2022 | A stored cross-site scripting (XSS) vulnerability in eyoucms v1.5.6 allows attackers to execute arbitrary web scripts or... |
| CVE-2022-33121 | HIGH | 8.1 | 0.4% | Jun 24, 2022 | A Cross-Site Request Forgery (CSRF) in MiniCMS v1.11 allows attackers to arbitrarily delete local .dat files via clickin... |
| CVE-2022-33004 | CRITICAL | 9.8 | 1.9% | Jun 24, 2022 | The Beginner package in PyPI v0.0.2 to v0.0.4 was discovered to contain a code execution backdoor via the request packag... |
| CVE-2022-33003 | CRITICAL | 9.8 | 1.9% | Jun 24, 2022 | The watools package in PyPI v0.0.1 to v0.0.8 was discovered to contain a code execution backdoor via the request package... |
| CVE-2022-33002 | CRITICAL | 9.8 | 1.9% | Jun 24, 2022 | The KGExplore package in PyPI v0.1.1 to v0.1.2 was discovered to contain a code execution backdoor via the request packa... |
| CVE-2022-33001 | CRITICAL | 9.8 | 1.9% | Jun 24, 2022 | The AAmiles package in PyPI v0.1.0 was discovered to contain a code execution backdoor via the request package. This vul... |
| CVE-2022-33000 | CRITICAL | 9.8 | 1.9% | Jun 24, 2022 | The ML-Scanner package in PyPI v0.1.0 to v0.1.5 was discovered to contain a code execution backdoor via the request pack... |
| CVE-2022-32999 | CRITICAL | 9.8 | 1.9% | Jun 24, 2022 | The cloudlabeling package in PyPI v0.0.1 was discovered to contain a code execution backdoor via the request package. Th... |
| CVE-2022-32998 | CRITICAL | 9.8 | 1.9% | Jun 24, 2022 | The cryptoasset-data-downloader package in PyPI v1.0.0 to v1.0.1 was discovered to contain a code execution backdoor via... |
| CVE-2022-32997 | CRITICAL | 9.8 | 1.9% | Jun 24, 2022 | The RootInteractive package in PyPI v0.0.5 to v0.0.19b0 was discovered to contain a code execution backdoor via the requ... |
| CVE-2022-32996 | CRITICAL | 9.8 | 1.9% | Jun 24, 2022 | The django-navbar-client package of v0.9.50 to v1.0.1 was discovered to contain a code execution backdoor via the reques... |
| CVE-2022-30885 | CRITICAL | 9.8 | 2.0% | Jun 24, 2022 | The pyesasky for python, as distributed on PyPI, included a code-execution backdoor inserted by a third party. The curre... |
| CVE-2022-21231 | CRITICAL | 9.8 | 1.3% | Jun 24, 2022 | All versions of package deep-get-set are vulnerable to Prototype Pollution via the 'deep' function. **Note:** This vulne... |
| CVE-2022-33910 | MEDIUM | 5.4 | 0.9% | Jun 24, 2022 | An XSS vulnerability in MantisBT before 2.25.5 allows remote attackers to attach crafted SVG documents to issue reports ... |
| CVE-2022-30028 | MEDIUM | 5.9 | 0.5% | Jun 24, 2022 | Dradis Professional Edition before 4.3.0 allows attackers to change an account password via reusing a password reset tok... |
| CVE-2022-29578 | MEDIUM | 5.3 | 1.0% | Jun 24, 2022 | Meridian Cooperative Utility Software versions 22.02 and 22.03 allows remote attackers to obtain sensitive information s... |
| CVE-2022-29097 | MEDIUM | 4.9 | 1.2% | Jun 24, 2022 | Dell WMS 3.6.1 and below contains a Path Traversal vulnerability in Device API. A remote attacker could potentially expl... |
| CVE-2022-29096 | MEDIUM | 5.4 | 0.5% | Jun 24, 2022 | Dell Wyse Management Suite 3.6.1 and below contains a Reflected Cross-Site Scripting Vulnerability in saveGroupConfigura... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now