2022 CVE Vulnerabilities

27,553 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-26111HIGH8.8The BeanShell components of IRISNext through 9.8.28 allow execution of arbitrary commands on the target server by creati...
CVE-2022-28586MEDIUM6.1XSS in edit page of Hoosk 1.8.0 allows attacker to execute javascript code in user browser via edit page with XSS payloa...
CVE-2022-28506MEDIUM5.5There is a heap-buffer-overflow in GIFLIB 5.2.1 function DumpScreen2RGB() in gif2rgb.c:298:45.
CVE-2022-28053HIGH8.8Typemill v1.5.3 was discovered to contain an arbitrary file upload vulnerability via the upload function. This vulnerabi...
CVE-2022-27429CRITICAL9.8Jizhicms v1.9.5 was discovered to contain a Server-Side Request Forgery (SSRF) vulnerability via /admin.php/Plugins/upda...
CVE-2022-27428MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in /index.php/album/add of GalleryCMS v2.0 allows attackers to execute...
CVE-2022-27311CRITICAL9.8Gibbon v3.4.4 and below allows attackers to execute a Server-Side Request Forgery (SSRF) via a crafted URL.
CVE-2022-27135MEDIUM5.5xpdf 4.03 has heap buffer overflow in the function readXRefTable located in XRef.cc. An attacker can exploit this bug to...
CVE-2022-27103MEDIUM6.1element-plus 2.0.5 is vulnerable to Cross Site Scripting (XSS) via el-table-column.
CVE-2022-28871HIGH7.5A Denial-of-Service (DoS) vulnerability was discovered in F-Secure Atlant whereby the fsicapd component used in certain ...
CVE-2022-1461MEDIUM6.5Non Privilege User can Enable or Disable Registered in GitHub repository openemr/openemr prior to 6.1.0.1.
CVE-2022-1459HIGH8.3Non-Privilege User Can View Patient’s Disclosures in GitHub repository openemr/openemr prior to 6.1.0.1.
CVE-2022-1458MEDIUM5.4Stored XSS Leads To Session Hijacking in GitHub repository openemr/openemr prior to 6.1.0.1.
CVE-2022-1457MEDIUM5.4Store XSS in title parameter executing at EditUser Page & EditProducto page in GitHub repository neorazorx/facturascript...
CVE-2022-29264CRITICAL9.8An issue was discovered in coreboot 4.13 through 4.16. On APs, arbitrary code execution in SMM may occur.
CVE-2022-29603HIGH8.1A SQL Injection vulnerability exists in UniverSIS UniverSIS-API through 1.2.1 via the $select parameter to multiple API ...
CVE-2022-29546HIGH7.5HtmlUnit NekoHtml Parser before 2.61.0 suffers from a denial of service vulnerability. Crafted input associated with the...
CVE-2022-29077CRITICAL9.8A heap-based buffer overflow exists in rippled before 1.8.5. The vulnerability allows attackers to cause a crash or exec...
CVE-2022-1452HIGH7.1Out-of-bounds Read in r_bin_java_bootstrap_methods_attr_new function in GitHub repository radareorg/radare2 prior to 5.7...
CVE-2022-1451HIGH7.1Out-of-bounds Read in r_bin_java_constant_value_attr_new function in GitHub repository radareorg/radare2 prior to 5.7.0....
CVE-2022-1445MEDIUM5.4Stored Cross Site Scripting vulnerability in the checked_out_to parameter in GitHub repository snipe/snipe-it prior to 5...
CVE-2022-1444MEDIUM5.5heap-use-after-free in GitHub repository radareorg/radare2 prior to 5.7.0. This vulnerability is capable of inducing den...
CVE-2022-1427HIGH7.8Out-of-bounds Read in mrb_obj_is_kind_of in in GitHub repository mruby/mruby prior to 3.2. # Impact: Possible arbitrary ...
CVE-2022-1108MEDIUM6.7A potential vulnerability due to improper buffer validation in the SMI handler LenovoFlashDeviceInterface in Thinkpad X1...
CVE-2022-1107MEDIUM6.7During an internal product security audit a potential vulnerability due to use of Boot Services in the SmmOEMInt15 SMI h...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now