2022 CVE Vulnerabilities

27,553 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-28451HIGH7.5nopCommerce 4.50.1 is vulnerable to Directory Traversal via the backup file in the Maintenance feature.
CVE-2022-25301CRITICAL9.8All versions of package jsgui-lang-essentials are vulnerable to Prototype Pollution due to allowing all Object attribute...
CVE-2022-26068HIGH7.5This affects the package pistacheio/pistache before 0.0.3.20220425. It is possible to traverse directories to fetch arbi...
CVE-2022-25850HIGH7.5The package github.com/hoppscotch/proxyscotch before 1.0.0 are vulnerable to Server-side Request Forgery (SSRF) when int...
CVE-2022-25844HIGH7.5The package angular after 1.7.0 are vulnerable to Regular Expression Denial of Service (ReDoS) by providing a custom loc...
CVE-2022-25842CRITICAL9.8All versions of package com.alibaba.oneagent:one-java-agent-plugin are vulnerable to Arbitrary File Write via Archive Ex...
CVE-2022-25767CRITICAL9.8All versions of package com.bstek.ureport:ureport2-console are vulnerable to Remote Code Execution by connecting to a ma...
CVE-2022-25647HIGH7.5The package com.google.code.gson:gson before 2.8.9 are vulnerable to Deserialization of Untrusted Data via the writeRepl...
CVE-2022-25645HIGH8.1All versions of package dset are vulnerable to Prototype Pollution via 'dset/merge' mode, as the dset function checks fo...
CVE-2022-25349MEDIUM5.4All versions of package materialize-css are vulnerable to Cross-site Scripting (XSS) due to improper escape of user inpu...
CVE-2022-24437CRITICAL9.8The package git-pull-or-clone before 2.0.2 are vulnerable to Command Injection due to the use of the --upload-pack featu...
CVE-2022-23923CRITICAL9.8All versions of package jailed are vulnerable to Sandbox Bypass via an exported alert() method which can access the main...
CVE-2022-22143CRITICAL9.8The package convict before 6.2.2 are vulnerable to Prototype Pollution via the convict function due to missing validatio...
CVE-2022-21230MEDIUM5.5This affects all versions of package org.nanohttpd:nanohttpd. Whenever an HTTP Session is parsing the body of an HTTP re...
CVE-2022-21227HIGH7.5The package sqlite3 before 5.0.3 are vulnerable to Denial of Service (DoS) which will invoke the toString function of th...
CVE-2022-21189CRITICAL9.8The package dexie before 3.2.2, from 4.0.0-alpha.1 and before 4.0.0-alpha.3 are vulnerable to Prototype Pollution in the...
CVE-2022-21167CRITICAL9.8All versions of package masuit.tools.core are vulnerable to Arbitrary Code Execution via the ReceiveVarData<T> function ...
CVE-2022-21149LOW3.5The package s-cart/s-cart before 6.9; the package s-cart/core before 6.9 are vulnerable to Cross-site Scripting (XSS) wh...
CVE-2022-21144HIGH7.5This affects all versions of package libxmljs. When invoking the libxmljs.parseXml function with a non-buffer argument t...
CVE-2022-28481CRITICAL9.8CSV-Safe gem < 3.0.0 doesn't filter out special characters which could trigger CSV Injection.
CVE-2022-23061MEDIUM6.5In Shopizer versions 2.0 to 2.17.0 a regular admin can permanently delete a superadmin (although this cannot happen acco...
CVE-2022-23060MEDIUM4.8A Stored Cross Site Scripting (XSS) vulnerability exists in Shopizer versions 2.0 through 2.17.0, where a privileged use...
CVE-2022-1544HIGH7.8Formula Injection/CSV Injection due to Improper Neutralization of Formula Elements in CSV File in GitHub repository luya...
CVE-2022-28323HIGH7.5An issue was discovered in MediaWiki through 1.37.2. The SecurePoll extension allows a leak because sorting by timestamp...
CVE-2022-29265HIGH7.5Multiple components in Apache NiFi 0.0.1 to 1.16.0 do not restrict XML External Entity references in the default configu...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now