2022 CVE Vulnerabilities

27,525 CVEs published in 2022.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2022-35649CRITICAL9.8The vulnerability was found in Moodle, occurs due to improper input validation when parsing PostScript code. An omitted ...
CVE-2022-33965CRITICAL9.8Multiple Unauthenticated SQL Injection (SQLi) vulnerabilities in Osamaesh WP Visitor Statistics plugin <= 5.7 at WordPre...
CVE-2022-2131CRITICAL9.8OpenKM Community Edition in its 6.3.10 version and before was using XMLReader parser in XMLTextExtractor.java file witho...
CVE-2022-1312CRITICAL9.6Use after free in storage in Google Chrome prior to 100.0.4896.88 allowed an attacker who convinced a user to install a ...
CVE-2022-1309CRITICAL9.6Insufficient policy enforcement in developer tools in Google Chrome prior to 100.0.4896.88 allowed a remote attacker to ...
CVE-2022-0670CRITICAL9.1A flaw was found in Openstack manilla owning a Ceph File system "share", which enables the owner to read/write any manil...
CVE-2022-36450CRITICAL9.8Obsidian 0.14.x and 0.15.x before 0.15.5 allows obsidian://hook-get-address remote code execution because window.open is...
CVE-2022-36446CRITICAL9.8software/apt-lib.pl in Webmin before 1.997 lacks HTML escaping for a UI command.
CVE-2022-36444CRITICAL9.8An issue was discovered in Atos Unify OpenScape SBC 9 and 10 before 10R2.2.1, Atos Unify OpenScape Branch 9 and 10 befor...
CVE-2022-34115CRITICAL9.8DataEase v1.11.1 was discovered to contain a arbitrary file write vulnerability via the parameter dataSourceId.
CVE-2022-34113CRITICAL9.8An issue in the component /api/plugin/upload of Dataease v1.11.1 allows attackers to execute arbitrary code via a crafte...
CVE-2022-25759CRITICAL9.8The package convert-svg-core before 0.6.2 are vulnerable to Remote Code Injection via sending an SVG file containing the...
CVE-2022-34839CRITICAL9.8Authentication Bypass vulnerability in CodexShaper's WP OAuth2 Server plugin <= 1.0.1 at WordPress.
CVE-2022-34983CRITICAL9.8The scu-captcha package in PyPI v0.0.1 to v0.0.4 included a code execution backdoor inserted by a third party.
CVE-2022-34982CRITICAL9.8The eziod package in PyPI before v0.0.1 included a code execution backdoor inserted by a third party.
CVE-2022-34981CRITICAL9.8The PyCrowdTangle package in PyPI before v0.0.1 included a code execution backdoor inserted by a third party.
CVE-2022-34509CRITICAL9.8The wikifaces package in PyPI v1.0 included a code execution backdoor inserted by a third party.
CVE-2022-34501CRITICAL9.8The bin-collection package in PyPI before v0.1 included a code execution backdoor inserted by a third party.
CVE-2022-34500CRITICAL9.8The bin-collect package in PyPI before v0.1 included a code execution backdoor inserted by a third party.
CVE-2022-2143CRITICAL9.8The affected product is vulnerable to two instances of command injection, which may allow an attacker to remotely execut...
CVE-2022-2139CRITICAL9.8The affected product is vulnerable to directory traversal, which may allow an attacker to access unauthorized files and ...
CVE-2022-0977CRITICAL9.6Use after free in Browser UI in Google Chrome on Chrome OS prior to 99.0.4844.74 allowed a remote attacker who convinced...
CVE-2022-0973CRITICAL9.6Use after free in Safe Browsing in Google Chrome prior to 99.0.4844.74 allowed a remote attacker to potentially exploit ...
CVE-2022-34767CRITICAL9.8Web page which "wizardpwd.asp" ALLNET Router model WR0500AC is prone to Authorization bypass vulnerability – the passwor...
CVE-2022-0902CRITICAL9.8Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Improper Neutralization of Special Eleme...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now