2022 CVE Vulnerabilities

27,553 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-22973HIGH7.8VMware Workspace ONE Access and Identity Manager contain a privilege escalation vulnerability. A malicious actor with lo...
CVE-2022-22972CRITICAL9.8VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an authentication bypass vulnerability aff...
CVE-2022-29448MEDIUM4.9Authenticated (admin or higher user role) Local File Inclusion (LFI) vulnerability in Wow-Company's Herd Effects plugin ...
CVE-2022-29425MEDIUM6.1Cross-Site Scripting (XSS) vulnerability in WP Wham's Checkout Files Upload for WooCommerce plugin <= 2.1.2 at WordPress...
CVE-2022-29424MEDIUM4.8Authenticated (admin or higher user role) Reflected Cross-Site Scripting (XSS) vulnerability in Biplob Adhikari's Image ...
CVE-2022-29185MEDIUM4.4totp-rs is a Rust library that permits the creation of 2FA authentification tokens per time-based one-time password (TOT...
CVE-2022-29184HIGH8.8GoCD is a continuous delivery server. In GoCD versions prior to 22.1.0, it is possible for existing authenticated users ...
CVE-2022-24434HIGH7.5This affects all versions of package dicer. A malicious attacker can send a modified form to server, and crash the nodej...
CVE-2022-21195HIGH7.5All versions of package url-regex are vulnerable to Regular Expression Denial of Service (ReDoS) which can cause the CPU...
CVE-2022-29183MEDIUM6.1GoCD is a continuous delivery server. GoCD versions 20.2.0 until 21.4.0 are vulnerable to reflected cross-site scripting...
CVE-2022-29182MEDIUM5.4GoCD is a continuous delivery server. GoCD versions 19.11.0 through 21.4.0 (inclusive) are vulnerable to a Document Obje...
CVE-2022-29181HIGH8.2Nokogiri is an open source XML and HTML library for Ruby. Nokogiri prior to version 1.13.6 does not type-check all input...
CVE-2022-29179HIGH8.2Cilium is open source software for providing and securing network connectivity and loadbalancing between application wor...
CVE-2022-29178HIGH8.2Cilium is open source software for providing and securing network connectivity and loadbalancing between application wor...
CVE-2022-28995CRITICAL9.8Rengine v1.0.2 was discovered to contain a remote code execution (RCE) vulnerability via the yaml configuration function...
CVE-2022-28990HIGH7.8WASM3 v0.5.0 was discovered to contain a heap overflow via the component /wabt/bin/poc.wasm.
CVE-2022-28531CRITICAL9.8Sourcecodester Covid-19 Directory on Vaccination System1.0 is vulnerable to SQL Injection via the admin/login.php txtuse...
CVE-2022-1770HIGH8.8Improper Privilege Management in GitHub repository polonel/trudesk prior to 1.2.2.
CVE-2022-29177MEDIUM5.9Go Ethereum is the official Golang implementation of the Ethereum protocol. Prior to version 1.10.17, a vulnerable node,...
CVE-2022-22365MEDIUM5.9IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0, with the Ajax Proxy Web Application (AjaxProxy.war) deployed, i...
CVE-2022-29170HIGH8.5Grafana is an open-source platform for monitoring and observability. In Grafana Enterprise, the Request security feature...
CVE-2022-29163MEDIUM4.3Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform. Prior to versions 22.2....
CVE-2022-29160LOW3.3Nextcloud Android is the Android client for Nextcloud, a self-hosted productivity platform. Prior to version 3.19.0, sen...
CVE-2022-29159MEDIUM4.3Nextcloud Deck is a Kanban-style project & personal management tool for Nextcloud. In versions prior to 1.4.8, 1.5.6, an...
CVE-2022-24906MEDIUM4.3Nextcloud Deck is a Kanban-style project & personal management tool for Nextcloud, similar to Trello. The full path of t...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now