2022 CVE Vulnerabilities

27,553 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-25226CRITICAL10ThinVNC version 1.0b1 allows an unauthenticated user to bypass the authentication process via 'http://thin-vnc:8080/cmd?...
CVE-2022-23976HIGH8.1Cross-Site Request Forgery (CSRF) in Access Demo Importer <= 1.0.7 on WordPress allows an attacker to reset all data (po...
CVE-2022-23975MEDIUM6.5Cross-Site Request Forgery (CSRF) in Access Demo Importer <= 1.0.7 on WordPress allows an attacker to activate any insta...
CVE-2022-1341HIGH7.5An issue was discovered in in bwm-ng v0.6.2. An arbitrary null write exists in get_cmdln_options() function in src/optio...
CVE-2022-26665HIGH7.5An Insecure Direct Object Reference issue exists in the Tyler Odyssey Portal platform before 17.1.20. This may allow an ...
CVE-2022-26631CRITICAL9.8Automatic Question Paper Generator v1.0 contains a Time-Based Blind SQL injection vulnerability via the id GET parameter...
CVE-2022-28810MEDIUM6.8Zoho ManageEngine ADSelfService Plus before build 6122 allows a remote authenticated administrator to execute arbitrary ...
CVE-2022-27908HIGH8.8Zoho ManageEngine OpManager before 125588 (and before 125603) is vulnerable to authenticated SQL Injection in the Invent...
CVE-2022-1383MEDIUM6.1Heap-based Buffer Overflow in GitHub repository radareorg/radare2 prior to 5.6.8. The bug causes the program reads data ...
CVE-2022-1382MEDIUM5.5NULL Pointer Dereference in GitHub repository radareorg/radare2 prior to 5.6.8. This vulnerability is capable of making ...
CVE-2022-1381HIGH7.8global heap buffer overflow in skip_range in GitHub repository vim/vim prior to 8.2.4763. This vulnerability is capable ...
CVE-2022-28966MEDIUM5.5Wasm3 0.5.0 has a heap-based buffer overflow in NewCodePage in m3_code.c (called indirectly from Compile_BranchTable in ...
CVE-2022-26777MEDIUM5.3Zoho ManageEngine Remote Access Plus before 10.1.2137.15 allows guest users to view license details.
CVE-2022-26653MEDIUM5.3Zoho ManageEngine Remote Access Plus before 10.1.2137.15 allows guest users to view domain details (such as the username...
CVE-2022-1380MEDIUM5.4Stored Cross Site Scripting vulnerability in Item name parameter in GitHub repository snipe/snipe-it prior to v5.4.3. Th...
CVE-2022-29287MEDIUM4.9Kentico CMS before 13.0.66 has an Insecure Direct Object Reference vulnerability. It allows an attacker with user manage...
CVE-2022-29020MEDIUM6.1ForestBlog through 2022-02-16 allows admin/profile/save userAvatar XSS during addition of a user avatar.
CVE-2022-1365MEDIUM6.5Exposure of Private Personal Information to an Unauthorized Actor in GitHub repository lquixada/cross-fetch prior to 3.1...
CVE-2022-29281HIGH8.8Notable before 1.9.0-beta.8 doesn't effectively prevent the opening of executable files when clicking on a link. There i...
CVE-2022-29072HIGH7.87-Zip through 21.07 on Windows allows privilege escalation and command execution when a file with the .7z extension is d...
CVE-2022-27427Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2021-38745. Reason: This candidate is a duplicate of ...
CVE-2022-27426HIGH8.8A Server-Side Request Forgery (SSRF) in Chamilo LMS v1.11.13 allows attackers to enumerate the internal network and exec...
CVE-2022-27425MEDIUM6.1Chamilo LMS v1.11.13 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /blog/blog.p...
CVE-2022-27423CRITICAL9.8Chamilo LMS v1.11.13 was discovered to contain a SQL injection vulnerability via the blog_id parameter at /blog/blog.php...
CVE-2022-27422MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability in Chamilo LMS v1.11.13 allows attackers to execute arbitrary web s...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now