2022 CVE Vulnerabilities
27,553 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-28451 | HIGH | 7.5 | 1.5% | May 2, 2022 | nopCommerce 4.50.1 is vulnerable to Directory Traversal via the backup file in the Maintenance feature. |
| CVE-2022-25301 | CRITICAL | 9.8 | 1.2% | May 1, 2022 | All versions of package jsgui-lang-essentials are vulnerable to Prototype Pollution due to allowing all Object attribute... |
| CVE-2022-26068 | HIGH | 7.5 | 1.5% | May 1, 2022 | This affects the package pistacheio/pistache before 0.0.3.20220425. It is possible to traverse directories to fetch arbi... |
| CVE-2022-25850 | HIGH | 7.5 | 1.3% | May 1, 2022 | The package github.com/hoppscotch/proxyscotch before 1.0.0 are vulnerable to Server-side Request Forgery (SSRF) when int... |
| CVE-2022-25844 | HIGH | 7.5 | 4.7% | May 1, 2022 | The package angular after 1.7.0 are vulnerable to Regular Expression Denial of Service (ReDoS) by providing a custom loc... |
| CVE-2022-25842 | CRITICAL | 9.8 | 3.6% | May 1, 2022 | All versions of package com.alibaba.oneagent:one-java-agent-plugin are vulnerable to Arbitrary File Write via Archive Ex... |
| CVE-2022-25767 | CRITICAL | 9.8 | 2.9% | May 1, 2022 | All versions of package com.bstek.ureport:ureport2-console are vulnerable to Remote Code Execution by connecting to a ma... |
| CVE-2022-25647 | HIGH | 7.5 | 11.6% | May 1, 2022 | The package com.google.code.gson:gson before 2.8.9 are vulnerable to Deserialization of Untrusted Data via the writeRepl... |
| CVE-2022-25645 | HIGH | 8.1 | 1.8% | May 1, 2022 | All versions of package dset are vulnerable to Prototype Pollution via 'dset/merge' mode, as the dset function checks fo... |
| CVE-2022-25349 | MEDIUM | 5.4 | 1.0% | May 1, 2022 | All versions of package materialize-css are vulnerable to Cross-site Scripting (XSS) due to improper escape of user inpu... |
| CVE-2022-24437 | CRITICAL | 9.8 | 3.9% | May 1, 2022 | The package git-pull-or-clone before 2.0.2 are vulnerable to Command Injection due to the use of the --upload-pack featu... |
| CVE-2022-23923 | CRITICAL | 9.8 | 1.3% | May 1, 2022 | All versions of package jailed are vulnerable to Sandbox Bypass via an exported alert() method which can access the main... |
| CVE-2022-22143 | CRITICAL | 9.8 | 2.0% | May 1, 2022 | The package convict before 6.2.2 are vulnerable to Prototype Pollution via the convict function due to missing validatio... |
| CVE-2022-21230 | MEDIUM | 5.5 | 0.3% | May 1, 2022 | This affects all versions of package org.nanohttpd:nanohttpd. Whenever an HTTP Session is parsing the body of an HTTP re... |
| CVE-2022-21227 | HIGH | 7.5 | 2.0% | May 1, 2022 | The package sqlite3 before 5.0.3 are vulnerable to Denial of Service (DoS) which will invoke the toString function of th... |
| CVE-2022-21189 | CRITICAL | 9.8 | 1.9% | May 1, 2022 | The package dexie before 3.2.2, from 4.0.0-alpha.1 and before 4.0.0-alpha.3 are vulnerable to Prototype Pollution in the... |
| CVE-2022-21167 | CRITICAL | 9.8 | 1.3% | May 1, 2022 | All versions of package masuit.tools.core are vulnerable to Arbitrary Code Execution via the ReceiveVarData<T> function ... |
| CVE-2022-21149 | LOW | 3.5 | 0.6% | May 1, 2022 | The package s-cart/s-cart before 6.9; the package s-cart/core before 6.9 are vulnerable to Cross-site Scripting (XSS) wh... |
| CVE-2022-21144 | HIGH | 7.5 | 1.8% | May 1, 2022 | This affects all versions of package libxmljs. When invoking the libxmljs.parseXml function with a non-buffer argument t... |
| CVE-2022-28481 | CRITICAL | 9.8 | 1.7% | May 1, 2022 | CSV-Safe gem < 3.0.0 doesn't filter out special characters which could trigger CSV Injection. |
| CVE-2022-23061 | MEDIUM | 6.5 | 1.1% | May 1, 2022 | In Shopizer versions 2.0 to 2.17.0 a regular admin can permanently delete a superadmin (although this cannot happen acco... |
| CVE-2022-23060 | MEDIUM | 4.8 | 0.6% | May 1, 2022 | A Stored Cross Site Scripting (XSS) vulnerability exists in Shopizer versions 2.0 through 2.17.0, where a privileged use... |
| CVE-2022-1544 | HIGH | 7.8 | 2.3% | May 1, 2022 | Formula Injection/CSV Injection due to Improper Neutralization of Formula Elements in CSV File in GitHub repository luya... |
| CVE-2022-28323 | HIGH | 7.5 | 1.3% | Apr 30, 2022 | An issue was discovered in MediaWiki through 1.37.2. The SecurePoll extension allows a leak because sorting by timestamp... |
| CVE-2022-29265 | HIGH | 7.5 | 2.4% | Apr 30, 2022 | Multiple components in Apache NiFi 0.0.1 to 1.16.0 do not restrict XML External Entity references in the default configu... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now