2022 CVE Vulnerabilities

27,552 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-2020MEDIUM4.8A vulnerability, which was classified as problematic, has been found in SourceCodester Prison Management System 1.0. Aff...
CVE-2022-2019HIGH7.5A vulnerability classified as critical was found in SourceCodester Prison Management System 1.0. Affected by this vulner...
CVE-2022-2018HIGH7.2A vulnerability classified as critical has been found in SourceCodester Prison Management System 1.0. Affected is an unk...
CVE-2022-2017HIGH7.2A vulnerability was found in SourceCodester Prison Management System 1.0. It has been rated as critical. This issue affe...
CVE-2022-2016MEDIUM5.4Cross-site Scripting (XSS) - Reflected in GitHub repository neorazorx/facturascripts prior to 2022.1.
CVE-2022-2000HIGH7.8Out-of-bounds Write in GitHub repository vim/vim prior to 8.2.
CVE-2022-24969MEDIUM6.1bypass CVE-2021-25640 > In Apache Dubbo prior to 2.6.12 and 2.7.15, the usage of parseURL method will lead to the bypass...
CVE-2022-0823MEDIUM6.2An improper control of interaction frequency vulnerability in Zyxel GS1200 series switches could allow a local attacker ...
CVE-2022-32272CRITICAL9.8OPSWAT MetaDefender Core before 5.1.2, MetaDefender ICAP before 4.12.1, and MetaDefender Email Gateway Security before 5...
CVE-2022-2035MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability exists in the playerConfUrl parameter in the /defaultui/player/mode...
CVE-2022-23138HIGH7.5ZTE's MF297D product has cryptographic issues vulnerability. Due to the use of weak random values, the security of the d...
CVE-2022-1998HIGH7.8A use after free in the Linux kernel File System notify functionality was found in the way user triggers copy_info_recor...
CVE-2022-31830CRITICAL9.1Kity Minder v1.3.5 was discovered to contain a Server-Side Request Forgery (SSRF) via the init function at ImageCapture....
CVE-2022-31827CRITICAL9.1MonstaFTP v2.10.3 was discovered to contain a Server-Side Request Forgery (SSRF) via the function performFetchRequest at...
CVE-2022-31393CRITICAL9.1Jizhicms v2.2.5 was discovered to contain a Server-Side Request Forgery (SSRF) vulnerability via the Index function in a...
CVE-2022-31390CRITICAL9.1Jizhicms v2.2.5 was discovered to contain a Server-Side Request Forgery (SSRF) vulnerability via the Update function in ...
CVE-2022-31386CRITICAL9.1A Server-Side Request Forgery (SSRF) in the getFileBinary function of nbnbk cms 3 allows attackers to force the applicat...
CVE-2022-31030MEDIUM5.5containerd is an open source container runtime. A bug was found in the containerd's CRI implementation where programs in...
CVE-2022-31027MEDIUM6.5OAuthenticator is an OAuth token library for the JupyerHub login handler. CILogonOAuthenticator is provided by the OAuth...
CVE-2022-31026HIGH7.5Trilogy is a client library for MySQL. When authenticating, a malicious server could return a specially crafted authenti...
CVE-2022-31019HIGH7.5Vapor is a server-side Swift HTTP web framework. When using automatic content decoding an attacker can craft a request b...
CVE-2022-29255HIGH7.5Vyper is a Pythonic Smart Contract Language for the ethereum virtual machine. In versions prior to 0.3.4 when a calling ...
CVE-2022-29254MEDIUM6.5silverstripe-omnipay is a SilverStripe integration with Omnipay PHP payments library. For a subset of Omnipay gateways (...
CVE-2022-24896MEDIUM4.3Tuleap is a Free & Open Source Suite to manage software developments and collaboration. In versions prior to 13.7.99.239...
CVE-2022-32195MEDIUM6.1Open edX platform before 2022-06-06 allows XSS via the "next" parameter in the logout URL.

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now