2022 CVE Vulnerabilities
27,553 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-24675 | HIGH | 7.5 | 5.3% | Apr 20, 2022 | encoding/pem in Go before 1.17.9 and 1.18.x before 1.18.1 has a Decode stack overflow via a large amount of PEM data. |
| CVE-2022-29266 | HIGH | 7.5 | 7.7% | Apr 20, 2022 | In APache APISIX before 3.13.1, the jwt-auth plugin has a security issue that leaks the user's secret key because the er... |
| CVE-2022-27629 | HIGH | 8.8 | 0.8% | Apr 20, 2022 | Cross-site request forgery (CSRF) vulnerability in 'MicroPayments - Paid Author Subscriptions, Content, Downloads, Membe... |
| CVE-2022-24860 | CRITICAL | 9.8 | 1.6% | Apr 20, 2022 | Databasir is a team-oriented relational database model document management platform. Databasir 1.01 has Use of Hard-code... |
| CVE-2022-24826 | HIGH | 7.8 | 2.1% | Apr 20, 2022 | On Windows, if Git LFS operates on a malicious repository with a `..exe` file as well as a file named `git.exe`, and `gi... |
| CVE-2022-24858 | MEDIUM | 6.1 | 0.7% | Apr 19, 2022 | next-auth v3 users before version 3.29.2 are impacted. next-auth version 4 users before version 4.3.2 are also impacted.... |
| CVE-2022-0071 | HIGH | 8.8 | 0.4% | Apr 19, 2022 | Incomplete fix for CVE-2021-3101. Hotdog, prior to v1.0.2, did not mimic the resource limits, device restrictions, or sy... |
| CVE-2022-0070 | HIGH | 8.8 | 0.4% | Apr 19, 2022 | Incomplete fix for CVE-2021-3100. The Apache Log4j hotpatch package starting with log4j-cve-2021-44228-hotpatch-1.1-16 w... |
| CVE-2022-28222 | MEDIUM | 6.1 | 3.0% | Apr 19, 2022 | The CleanTalk AntiSpam plugin <= 5.173 for WordPress is vulnerable to Reflected Cross-Site Scripting (XSS) via the $_REQ... |
| CVE-2022-28221 | MEDIUM | 6.1 | 2.4% | Apr 19, 2022 | The CleanTalk AntiSpam plugin <= 5.173 for WordPress is vulnerable to Reflected Cross-Site Scripting (XSS) via the $_REQ... |
| CVE-2022-27863 | MEDIUM | 5.3 | 1.0% | Apr 19, 2022 | Sensitive Information Exposure in E4J s.r.l. VikBooking Hotel Booking Engine & PMS plugin <= 1.5.3 on WordPress allows a... |
| CVE-2022-27862 | CRITICAL | 9.8 | 1.6% | Apr 19, 2022 | Arbitrary File Upload leading to RCE in E4J s.r.l. VikBooking Hotel Booking Engine & PMS plugin <= 1.5.3 on WordPress al... |
| CVE-2022-27527 | HIGH | 7.8 | 0.5% | Apr 19, 2022 | A Memory Corruption vulnerability may lead to code execution through maliciously crafted DLL files. It was fixed in PDFT... |
| CVE-2022-25788 | HIGH | 7.8 | 1.5% | Apr 19, 2022 | A maliciously crafted JT file in Autodesk AutoCAD 2022 may be used to write beyond the allocated buffer while parsing JT... |
| CVE-2022-21498 | MEDIUM | 6.5 | 0.7% | Apr 19, 2022 | Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 19c... |
| CVE-2022-21497 | HIGH | 8.1 | 1.6% | Apr 19, 2022 | Vulnerability in the Oracle Web Services Manager product of Oracle Fusion Middleware (component: Web Services Security).... |
| CVE-2022-21496 | MEDIUM | 5.3 | 2.7% | Apr 19, 2022 | Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JNDI). Supp... |
| CVE-2022-21494 | MEDIUM | 4 | 0.2% | Apr 19, 2022 | Vulnerability in the Oracle Solaris product of Oracle Systems (component: Kernel). The supported version that is affecte... |
| CVE-2022-21493 | MEDIUM | 5.9 | 0.2% | Apr 19, 2022 | Vulnerability in the Oracle Solaris product of Oracle Systems (component: Kernel). The supported version that is affecte... |
| CVE-2022-21492 | MEDIUM | 6.1 | 0.8% | Apr 19, 2022 | Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Ana... |
| CVE-2022-21491 | HIGH | 7.8 | 0.4% | Apr 19, 2022 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that... |
| CVE-2022-21490 | MEDIUM | 6.3 | 78.7% | Apr 19, 2022 | Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported versions that are af... |
| CVE-2022-21489 | MEDIUM | 6.3 | 78.9% | Apr 19, 2022 | Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported versions that are af... |
| CVE-2022-21488 | LOW | 3.8 | 0.4% | Apr 19, 2022 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that... |
| CVE-2022-21487 | LOW | 3.8 | 0.4% | Apr 19, 2022 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now