2022 CVE Vulnerabilities

27,553 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-24675HIGH7.5encoding/pem in Go before 1.17.9 and 1.18.x before 1.18.1 has a Decode stack overflow via a large amount of PEM data.
CVE-2022-29266HIGH7.5In APache APISIX before 3.13.1, the jwt-auth plugin has a security issue that leaks the user's secret key because the er...
CVE-2022-27629HIGH8.8Cross-site request forgery (CSRF) vulnerability in 'MicroPayments - Paid Author Subscriptions, Content, Downloads, Membe...
CVE-2022-24860CRITICAL9.8Databasir is a team-oriented relational database model document management platform. Databasir 1.01 has Use of Hard-code...
CVE-2022-24826HIGH7.8On Windows, if Git LFS operates on a malicious repository with a `..exe` file as well as a file named `git.exe`, and `gi...
CVE-2022-24858MEDIUM6.1next-auth v3 users before version 3.29.2 are impacted. next-auth version 4 users before version 4.3.2 are also impacted....
CVE-2022-0071HIGH8.8Incomplete fix for CVE-2021-3101. Hotdog, prior to v1.0.2, did not mimic the resource limits, device restrictions, or sy...
CVE-2022-0070HIGH8.8Incomplete fix for CVE-2021-3100. The Apache Log4j hotpatch package starting with log4j-cve-2021-44228-hotpatch-1.1-16 w...
CVE-2022-28222MEDIUM6.1The CleanTalk AntiSpam plugin <= 5.173 for WordPress is vulnerable to Reflected Cross-Site Scripting (XSS) via the $_REQ...
CVE-2022-28221MEDIUM6.1The CleanTalk AntiSpam plugin <= 5.173 for WordPress is vulnerable to Reflected Cross-Site Scripting (XSS) via the $_REQ...
CVE-2022-27863MEDIUM5.3Sensitive Information Exposure in E4J s.r.l. VikBooking Hotel Booking Engine & PMS plugin <= 1.5.3 on WordPress allows a...
CVE-2022-27862CRITICAL9.8Arbitrary File Upload leading to RCE in E4J s.r.l. VikBooking Hotel Booking Engine & PMS plugin <= 1.5.3 on WordPress al...
CVE-2022-27527HIGH7.8A Memory Corruption vulnerability may lead to code execution through maliciously crafted DLL files. It was fixed in PDFT...
CVE-2022-25788HIGH7.8A maliciously crafted JT file in Autodesk AutoCAD 2022 may be used to write beyond the allocated buffer while parsing JT...
CVE-2022-21498MEDIUM6.5Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 19c...
CVE-2022-21497HIGH8.1Vulnerability in the Oracle Web Services Manager product of Oracle Fusion Middleware (component: Web Services Security)....
CVE-2022-21496MEDIUM5.3Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JNDI). Supp...
CVE-2022-21494MEDIUM4Vulnerability in the Oracle Solaris product of Oracle Systems (component: Kernel). The supported version that is affecte...
CVE-2022-21493MEDIUM5.9Vulnerability in the Oracle Solaris product of Oracle Systems (component: Kernel). The supported version that is affecte...
CVE-2022-21492MEDIUM6.1Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Ana...
CVE-2022-21491HIGH7.8Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that...
CVE-2022-21490MEDIUM6.3Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported versions that are af...
CVE-2022-21489MEDIUM6.3Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported versions that are af...
CVE-2022-21488LOW3.8Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that...
CVE-2022-21487LOW3.8Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now