2022 CVE Vulnerabilities
27,553 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-20622 | HIGH | 7.5 | 1.3% | Apr 15, 2022 | A vulnerability in IP ingress packet processing of the Cisco Embedded Wireless Controller with Catalyst Access Points So... |
| CVE-2022-1231 | MEDIUM | 6.1 | 1.8% | Apr 15, 2022 | XSS via Embedded SVG in SVG Diagram Format in GitHub repository plantuml/plantuml prior to 1.2022.4. Stored XSS in the c... |
| CVE-2022-28049 | MEDIUM | 5.5 | 0.8% | Apr 15, 2022 | NGINX NJS 0.7.2 was discovered to contain a NULL pointer dereference via the component njs_vmcode_array at /src/njs_vmco... |
| CVE-2022-28048 | HIGH | 8.8 | 1.5% | Apr 15, 2022 | STB v2.27 was discovered to contain an integer shift of invalid size in the component stbi__jpeg_decode_block_prog_ac. |
| CVE-2022-28044 | CRITICAL | 9.8 | 1.8% | Apr 15, 2022 | Irzip v0.640 was discovered to contain a heap memory corruption via the component lrzip.c:initialise_control. |
| CVE-2022-28042 | HIGH | 8.8 | 1.5% | Apr 15, 2022 | stb_image.h v2.27 was discovered to contain an heap-based use-after-free via the function stbi__jpeg_huff_decode. |
| CVE-2022-28041 | MEDIUM | 6.5 | 2.0% | Apr 15, 2022 | stb_image.h v2.27 was discovered to contain an integer overflow via the function stbi__jpeg_decode_block_prog_dc. This v... |
| CVE-2022-27474 | HIGH | 7.2 | 22.5% | Apr 15, 2022 | SuiteCRM v7.11.23 was discovered to allow remote code execution via a crafted payload injected into the FirstName text f... |
| CVE-2022-28870 | MEDIUM | 4.3 | 0.4% | Apr 15, 2022 | A vulnerability affecting F-Secure SAFE browser was discovered. A maliciously crafted website could make a phishing atta... |
| CVE-2022-28869 | MEDIUM | 4.3 | 0.4% | Apr 15, 2022 | A vulnerability affecting F-Secure SAFE browser was discovered. A maliciously crafted website could make a phishing atta... |
| CVE-2022-28868 | MEDIUM | 4.3 | 0.5% | Apr 15, 2022 | An Address bar spoofing vulnerability was discovered in Safe Browser for Android. When user clicks on a specially crafte... |
| CVE-2022-28345 | HIGH | 7.5 | 2.1% | Apr 15, 2022 | The Signal app before 5.34 for iOS allows URI spoofing via RTLO injection. It incorrectly renders RTLO encoded URLs begi... |
| CVE-2022-26651 | CRITICAL | 9.8 | 6.6% | Apr 15, 2022 | An issue was discovered in Asterisk through 19.x and Certified Asterisk through 16.8-cert13. The func_odbc module provid... |
| CVE-2022-26499 | CRITICAL | 9.1 | 7.3% | Apr 15, 2022 | An SSRF issue was discovered in Asterisk through 19.x. When using STIR/SHAKEN, it's possible to send arbitrary requests ... |
| CVE-2022-26498 | HIGH | 7.5 | 15.5% | Apr 15, 2022 | An issue was discovered in Asterisk through 19.x. When using STIR/SHAKEN, it is possible to download files that are not ... |
| CVE-2022-27188 | HIGH | 7.8 | 0.5% | Apr 15, 2022 | OS command injection vulnerability exists in CENTUM VP R4.01.00 to R4.03.00, CENTUM VP Small R4.01.00 to R4.03.00, CENTU... |
| CVE-2022-26034 | CRITICAL | 9.1 | 0.9% | Apr 15, 2022 | Improper authentication vulnerability in the communication protocol provided by AD (Automation Design) server of CENTUM ... |
| CVE-2022-24855 | MEDIUM | 5.4 | 0.7% | Apr 14, 2022 | Metabase is an open source business intelligence and analytics application. In affected versions Metabase ships with an ... |
| CVE-2022-24854 | HIGH | 8.8 | 1.0% | Apr 14, 2022 | Metabase is an open source business intelligence and analytics application. SQLite has an FDW-like feature called `ATTAC... |
| CVE-2022-24853 | MEDIUM | 5.3 | 2.4% | Apr 14, 2022 | Metabase is an open source business intelligence and analytics application. Metabase has a proxy to load arbitrary URLs ... |
| CVE-2022-24850 | MEDIUM | 4.3 | 0.6% | Apr 14, 2022 | Discourse is an open source platform for community discussion. A category's group permissions settings can be viewed by ... |
| CVE-2022-24849 | MEDIUM | 6.5 | 0.8% | Apr 14, 2022 | DisCatSharp is a Discord API wrapper for .NET. Users of versions 9.8.5, 9.8.6, 9.9.0 and previously published prerelease... |
| CVE-2022-24846 | HIGH | 7.2 | 1.2% | Apr 14, 2022 | GeoWebCache is a tile caching server implemented in Java. The GeoWebCache disk quota mechanism can perform an unchecked ... |
| CVE-2022-24824 | MEDIUM | 5.3 | 0.9% | Apr 14, 2022 | Discourse is an open source platform for community discussion. In affected versions an attacker can poison the cache for... |
| CVE-2022-27848 | MEDIUM | 4.8 | 0.5% | Apr 14, 2022 | Authenticated (admin+ user) Stored Cross-Site Scripting (XSS) in Modern Events Calendar Lite (WordPress plugin) <= 6.5.1 |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now