2022 CVE Vulnerabilities
27,553 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-25226 | CRITICAL | 10 | 10.9% | Apr 18, 2022 | ThinVNC version 1.0b1 allows an unauthenticated user to bypass the authentication process via 'http://thin-vnc:8080/cmd?... |
| CVE-2022-23976 | HIGH | 8.1 | 0.5% | Apr 18, 2022 | Cross-Site Request Forgery (CSRF) in Access Demo Importer <= 1.0.7 on WordPress allows an attacker to reset all data (po... |
| CVE-2022-23975 | MEDIUM | 6.5 | 0.5% | Apr 18, 2022 | Cross-Site Request Forgery (CSRF) in Access Demo Importer <= 1.0.7 on WordPress allows an attacker to activate any insta... |
| CVE-2022-1341 | HIGH | 7.5 | 1.1% | Apr 18, 2022 | An issue was discovered in in bwm-ng v0.6.2. An arbitrary null write exists in get_cmdln_options() function in src/optio... |
| CVE-2022-26665 | HIGH | 7.5 | 1.8% | Apr 18, 2022 | An Insecure Direct Object Reference issue exists in the Tyler Odyssey Portal platform before 17.1.20. This may allow an ... |
| CVE-2022-26631 | CRITICAL | 9.8 | 1.1% | Apr 18, 2022 | Automatic Question Paper Generator v1.0 contains a Time-Based Blind SQL injection vulnerability via the id GET parameter... |
| CVE-2022-28810 | MEDIUM | 6.8 | 70.4% | Apr 18, 2022 | Zoho ManageEngine ADSelfService Plus before build 6122 allows a remote authenticated administrator to execute arbitrary ... |
| CVE-2022-27908 | HIGH | 8.8 | 36.8% | Apr 18, 2022 | Zoho ManageEngine OpManager before 125588 (and before 125603) is vulnerable to authenticated SQL Injection in the Invent... |
| CVE-2022-1383 | MEDIUM | 6.1 | 0.7% | Apr 18, 2022 | Heap-based Buffer Overflow in GitHub repository radareorg/radare2 prior to 5.6.8. The bug causes the program reads data ... |
| CVE-2022-1382 | MEDIUM | 5.5 | 0.7% | Apr 18, 2022 | NULL Pointer Dereference in GitHub repository radareorg/radare2 prior to 5.6.8. This vulnerability is capable of making ... |
| CVE-2022-1381 | HIGH | 7.8 | 3.0% | Apr 18, 2022 | global heap buffer overflow in skip_range in GitHub repository vim/vim prior to 8.2.4763. This vulnerability is capable ... |
| CVE-2022-28966 | MEDIUM | 5.5 | 0.6% | Apr 16, 2022 | Wasm3 0.5.0 has a heap-based buffer overflow in NewCodePage in m3_code.c (called indirectly from Compile_BranchTable in ... |
| CVE-2022-26777 | MEDIUM | 5.3 | 2.0% | Apr 16, 2022 | Zoho ManageEngine Remote Access Plus before 10.1.2137.15 allows guest users to view license details. |
| CVE-2022-26653 | MEDIUM | 5.3 | 2.0% | Apr 16, 2022 | Zoho ManageEngine Remote Access Plus before 10.1.2137.15 allows guest users to view domain details (such as the username... |
| CVE-2022-1380 | MEDIUM | 5.4 | 0.8% | Apr 16, 2022 | Stored Cross Site Scripting vulnerability in Item name parameter in GitHub repository snipe/snipe-it prior to v5.4.3. Th... |
| CVE-2022-29287 | MEDIUM | 4.9 | 0.9% | Apr 16, 2022 | Kentico CMS before 13.0.66 has an Insecure Direct Object Reference vulnerability. It allows an attacker with user manage... |
| CVE-2022-29020 | MEDIUM | 6.1 | 0.5% | Apr 16, 2022 | ForestBlog through 2022-02-16 allows admin/profile/save userAvatar XSS during addition of a user avatar. |
| CVE-2022-1365 | MEDIUM | 6.5 | 1.1% | Apr 15, 2022 | Exposure of Private Personal Information to an Unauthorized Actor in GitHub repository lquixada/cross-fetch prior to 3.1... |
| CVE-2022-29281 | HIGH | 8.8 | 1.4% | Apr 15, 2022 | Notable before 1.9.0-beta.8 doesn't effectively prevent the opening of executable files when clicking on a link. There i... |
| CVE-2022-29072 | HIGH | 7.8 | 1.5% | Apr 15, 2022 | 7-Zip through 21.07 on Windows allows privilege escalation and command execution when a file with the .7z extension is d... |
| CVE-2022-27427 | — | — | — | Apr 15, 2022 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2021-38745. Reason: This candidate is a duplicate of ... |
| CVE-2022-27426 | HIGH | 8.8 | 0.8% | Apr 15, 2022 | A Server-Side Request Forgery (SSRF) in Chamilo LMS v1.11.13 allows attackers to enumerate the internal network and exec... |
| CVE-2022-27425 | MEDIUM | 6.1 | 0.6% | Apr 15, 2022 | Chamilo LMS v1.11.13 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /blog/blog.p... |
| CVE-2022-27423 | CRITICAL | 9.8 | 0.9% | Apr 15, 2022 | Chamilo LMS v1.11.13 was discovered to contain a SQL injection vulnerability via the blog_id parameter at /blog/blog.php... |
| CVE-2022-27422 | MEDIUM | 6.1 | 0.6% | Apr 15, 2022 | A reflected cross-site scripting (XSS) vulnerability in Chamilo LMS v1.11.13 allows attackers to execute arbitrary web s... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now