2022 CVE Vulnerabilities

27,553 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-1464MEDIUM5.4Stored xss bug in GitHub repository gogs/gogs prior to 0.12.7. As the repo is public , any user can view the report and ...
CVE-2022-29340HIGH7.5GPAC 2.1-DEV-rev87-g053aae8-master. has a Null Pointer Dereference vulnerability in gf_isom_parse_movie_boxes_internal d...
CVE-2022-29339HIGH7.5In GPAC 2.1-DEV-rev87-g053aae8-master, function BS_ReadByte() in utils/bitstream.c has a failed assertion, which causes ...
CVE-2022-28471MEDIUM6.5In ffjpeg (commit hash: caade60), the function bmp_load() in bmp.c contains an integer overflow vulnerability, which eve...
CVE-2022-28462HIGH7.5novel-plus 3.6.0 suffers from an Arbitrary file reading vulnerability.
CVE-2022-28461CRITICAL9.8mingyuefusu Library Management System all versions as of 03-27-2022 is vulnerable to SQL Injection.
CVE-2022-29940MEDIUM5.4In LibreHealth EHR 2.0.0, lack of sanitization of the GET parameters formseq and formid in interface\orders\find_order_p...
CVE-2022-29939MEDIUM5.4In LibreHealth EHR 2.0.0, lack of sanitization of the GET parameters debug and InsId in interface\billing\sl_eob_process...
CVE-2022-29938HIGH8.8In LibreHealth EHR 2.0.0, lack of sanitization of the GET parameter payment_id in interface\billing\new_payment.php via ...
CVE-2022-1575CRITICAL9.6Arbitrary Code Execution through Sanitizer Bypass in GitHub repository jgraph/drawio prior to 18.0.0. - Arbitrary (remot...
CVE-2022-1592HIGH8.2Server-Side Request Forgery in scout in GitHub repository clinical-genomics/scout prior to v4.42. An attacker could make...
CVE-2022-1411MEDIUM6.1Unrestructed file upload in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0. Attacker can send malicious ...
CVE-2022-1590MEDIUM5.4A vulnerability was found in Bludit 3.13.1. It has been declared as problematic. This vulnerability affects the endpoint...
CVE-2022-28890CRITICAL9.8A vulnerability in the RDF/XML parser of Apache Jena allows an attacker to cause an external DTD to be retrieved. This i...
CVE-2022-1588Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. Reason: This CVE has been rejected as it was incorrectly assigned. Al...
CVE-2022-30292CRITICAL10Heap-based buffer overflow in sqbaselib.cpp in SQUIRREL 3.2 due to lack of a certain sq_reservestack call.
CVE-2022-30288HIGH7.5Agoo before 2.14.3 does not reject GraphQL fragment spreads that form cycles, leading to an application crash. NOTE: the...
CVE-2022-30284CRITICAL9.8In the python-libnmap package through 0.7.2 for Python, remote command execution can occur (if used in a client applicat...
CVE-2022-29155CRITICAL9.8In OpenLDAP 2.x before 2.5.12 and 2.6.x before 2.6.2, a SQL injection vulnerability exists in the experimental back-sql ...
CVE-2022-30241MEDIUM6.1The jquery.json-viewer library through 1.4.0 for Node.js does not properly escape characters such as < in a JSON object,...
CVE-2022-29943MEDIUM6.5Talend Administration Center has a vulnerability that allows an authenticated user to use XML External Entity (XXE) proc...
CVE-2022-29942MEDIUM6.5Talend Administration Center has a vulnerability that allows an authenticated user to use the Service Registry 'Add' fun...
CVE-2022-25786MEDIUM4.9Unprotected Alternate Channel vulnerability in debug console of GateManager allows system administrator to obtain sensit...
CVE-2022-1584MEDIUM6.1Reflected XSS in GitHub repository microweber/microweber prior to 1.2.16. Executing JavaScript as the victim
CVE-2022-23724HIGH8.1Use of static encryption key material allows forging an authentication token to other users within a tenant organization...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now