2022 CVE Vulnerabilities

27,553 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-20622HIGH7.5A vulnerability in IP ingress packet processing of the Cisco Embedded Wireless Controller with Catalyst Access Points So...
CVE-2022-1231MEDIUM6.1XSS via Embedded SVG in SVG Diagram Format in GitHub repository plantuml/plantuml prior to 1.2022.4. Stored XSS in the c...
CVE-2022-28049MEDIUM5.5NGINX NJS 0.7.2 was discovered to contain a NULL pointer dereference via the component njs_vmcode_array at /src/njs_vmco...
CVE-2022-28048HIGH8.8STB v2.27 was discovered to contain an integer shift of invalid size in the component stbi__jpeg_decode_block_prog_ac.
CVE-2022-28044CRITICAL9.8Irzip v0.640 was discovered to contain a heap memory corruption via the component lrzip.c:initialise_control.
CVE-2022-28042HIGH8.8stb_image.h v2.27 was discovered to contain an heap-based use-after-free via the function stbi__jpeg_huff_decode.
CVE-2022-28041MEDIUM6.5stb_image.h v2.27 was discovered to contain an integer overflow via the function stbi__jpeg_decode_block_prog_dc. This v...
CVE-2022-27474HIGH7.2SuiteCRM v7.11.23 was discovered to allow remote code execution via a crafted payload injected into the FirstName text f...
CVE-2022-28870MEDIUM4.3A vulnerability affecting F-Secure SAFE browser was discovered. A maliciously crafted website could make a phishing atta...
CVE-2022-28869MEDIUM4.3A vulnerability affecting F-Secure SAFE browser was discovered. A maliciously crafted website could make a phishing atta...
CVE-2022-28868MEDIUM4.3An Address bar spoofing vulnerability was discovered in Safe Browser for Android. When user clicks on a specially crafte...
CVE-2022-28345HIGH7.5The Signal app before 5.34 for iOS allows URI spoofing via RTLO injection. It incorrectly renders RTLO encoded URLs begi...
CVE-2022-26651CRITICAL9.8An issue was discovered in Asterisk through 19.x and Certified Asterisk through 16.8-cert13. The func_odbc module provid...
CVE-2022-26499CRITICAL9.1An SSRF issue was discovered in Asterisk through 19.x. When using STIR/SHAKEN, it's possible to send arbitrary requests ...
CVE-2022-26498HIGH7.5An issue was discovered in Asterisk through 19.x. When using STIR/SHAKEN, it is possible to download files that are not ...
CVE-2022-27188HIGH7.8OS command injection vulnerability exists in CENTUM VP R4.01.00 to R4.03.00, CENTUM VP Small R4.01.00 to R4.03.00, CENTU...
CVE-2022-26034CRITICAL9.1Improper authentication vulnerability in the communication protocol provided by AD (Automation Design) server of CENTUM ...
CVE-2022-24855MEDIUM5.4Metabase is an open source business intelligence and analytics application. In affected versions Metabase ships with an ...
CVE-2022-24854HIGH8.8Metabase is an open source business intelligence and analytics application. SQLite has an FDW-like feature called `ATTAC...
CVE-2022-24853MEDIUM5.3Metabase is an open source business intelligence and analytics application. Metabase has a proxy to load arbitrary URLs ...
CVE-2022-24850MEDIUM4.3Discourse is an open source platform for community discussion. A category's group permissions settings can be viewed by ...
CVE-2022-24849MEDIUM6.5DisCatSharp is a Discord API wrapper for .NET. Users of versions 9.8.5, 9.8.6, 9.9.0 and previously published prerelease...
CVE-2022-24846HIGH7.2GeoWebCache is a tile caching server implemented in Java. The GeoWebCache disk quota mechanism can perform an unchecked ...
CVE-2022-24824MEDIUM5.3Discourse is an open source platform for community discussion. In affected versions an attacker can poison the cache for...
CVE-2022-27848MEDIUM4.8Authenticated (admin+ user) Stored Cross-Site Scripting (XSS) in Modern Events Calendar Lite (WordPress plugin) <= 6.5.1

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now