2022 CVE Vulnerabilities
27,525 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-35649 | CRITICAL | 9.8 | 6.3% | Jul 25, 2022 | The vulnerability was found in Moodle, occurs due to improper input validation when parsing PostScript code. An omitted ... |
| CVE-2022-33965 | CRITICAL | 9.8 | 3.3% | Jul 25, 2022 | Multiple Unauthenticated SQL Injection (SQLi) vulnerabilities in Osamaesh WP Visitor Statistics plugin <= 5.7 at WordPre... |
| CVE-2022-2131 | CRITICAL | 9.8 | 0.7% | Jul 25, 2022 | OpenKM Community Edition in its 6.3.10 version and before was using XMLReader parser in XMLTextExtractor.java file witho... |
| CVE-2022-1312 | CRITICAL | 9.6 | 0.5% | Jul 25, 2022 | Use after free in storage in Google Chrome prior to 100.0.4896.88 allowed an attacker who convinced a user to install a ... |
| CVE-2022-1309 | CRITICAL | 9.6 | 0.7% | Jul 25, 2022 | Insufficient policy enforcement in developer tools in Google Chrome prior to 100.0.4896.88 allowed a remote attacker to ... |
| CVE-2022-0670 | CRITICAL | 9.1 | 0.9% | Jul 25, 2022 | A flaw was found in Openstack manilla owning a Ceph File system "share", which enables the owner to read/write any manil... |
| CVE-2022-36450 | CRITICAL | 9.8 | 19.6% | Jul 25, 2022 | Obsidian 0.14.x and 0.15.x before 0.15.5 allows obsidian://hook-get-address remote code execution because window.open is... |
| CVE-2022-36446 | CRITICAL | 9.8 | 96.0% | Jul 25, 2022 | software/apt-lib.pl in Webmin before 1.997 lacks HTML escaping for a UI command. |
| CVE-2022-36444 | CRITICAL | 9.8 | 0.8% | Jul 25, 2022 | An issue was discovered in Atos Unify OpenScape SBC 9 and 10 before 10R2.2.1, Atos Unify OpenScape Branch 9 and 10 befor... |
| CVE-2022-34115 | CRITICAL | 9.8 | 1.0% | Jul 22, 2022 | DataEase v1.11.1 was discovered to contain a arbitrary file write vulnerability via the parameter dataSourceId. |
| CVE-2022-34113 | CRITICAL | 9.8 | 1.1% | Jul 22, 2022 | An issue in the component /api/plugin/upload of Dataease v1.11.1 allows attackers to execute arbitrary code via a crafte... |
| CVE-2022-25759 | CRITICAL | 9.8 | 9.0% | Jul 22, 2022 | The package convert-svg-core before 0.6.2 are vulnerable to Remote Code Injection via sending an SVG file containing the... |
| CVE-2022-34839 | CRITICAL | 9.8 | 0.9% | Jul 22, 2022 | Authentication Bypass vulnerability in CodexShaper's WP OAuth2 Server plugin <= 1.0.1 at WordPress. |
| CVE-2022-34983 | CRITICAL | 9.8 | 1.2% | Jul 22, 2022 | The scu-captcha package in PyPI v0.0.1 to v0.0.4 included a code execution backdoor inserted by a third party. |
| CVE-2022-34982 | CRITICAL | 9.8 | 1.1% | Jul 22, 2022 | The eziod package in PyPI before v0.0.1 included a code execution backdoor inserted by a third party. |
| CVE-2022-34981 | CRITICAL | 9.8 | 1.2% | Jul 22, 2022 | The PyCrowdTangle package in PyPI before v0.0.1 included a code execution backdoor inserted by a third party. |
| CVE-2022-34509 | CRITICAL | 9.8 | 1.0% | Jul 22, 2022 | The wikifaces package in PyPI v1.0 included a code execution backdoor inserted by a third party. |
| CVE-2022-34501 | CRITICAL | 9.8 | 1.1% | Jul 22, 2022 | The bin-collection package in PyPI before v0.1 included a code execution backdoor inserted by a third party. |
| CVE-2022-34500 | CRITICAL | 9.8 | 1.1% | Jul 22, 2022 | The bin-collect package in PyPI before v0.1 included a code execution backdoor inserted by a third party. |
| CVE-2022-2143 | CRITICAL | 9.8 | 59.2% | Jul 22, 2022 | The affected product is vulnerable to two instances of command injection, which may allow an attacker to remotely execut... |
| CVE-2022-2139 | CRITICAL | 9.8 | 14.8% | Jul 22, 2022 | The affected product is vulnerable to directory traversal, which may allow an attacker to access unauthorized files and ... |
| CVE-2022-0977 | CRITICAL | 9.6 | 0.7% | Jul 21, 2022 | Use after free in Browser UI in Google Chrome on Chrome OS prior to 99.0.4844.74 allowed a remote attacker who convinced... |
| CVE-2022-0973 | CRITICAL | 9.6 | 0.7% | Jul 21, 2022 | Use after free in Safe Browsing in Google Chrome prior to 99.0.4844.74 allowed a remote attacker to potentially exploit ... |
| CVE-2022-34767 | CRITICAL | 9.8 | 0.5% | Jul 21, 2022 | Web page which "wizardpwd.asp" ALLNET Router model WR0500AC is prone to Authorization bypass vulnerability – the passwor... |
| CVE-2022-0902 | CRITICAL | 9.8 | 16.4% | Jul 21, 2022 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Improper Neutralization of Special Eleme... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now