2022 CVE Vulnerabilities

27,553 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-1279HIGH7.5A vulnerability in the encryption implementation of EBICS messages in the open source librairy ebics-java/ebics-java-cli...
CVE-2022-1350HIGH7.8A vulnerability classified as problematic was found in GhostPCL 9.55.0. This vulnerability affects the function chunk_fr...
CVE-2022-24847HIGH7.2GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. The Geo...
CVE-2022-24845CRITICAL9.8Vyper is a pythonic Smart Contract Language for the ethereum virtual machine. In affected versions, the return of `<ifac...
CVE-2022-24843HIGH7.5Gin-vue-admin is a backstage management system based on vue and gin, which separates the front and rear of the full stac...
CVE-2022-24844HIGH8.8Gin-vue-admin is a backstage management system based on vue and gin, which separates the front and rear of the full stac...
CVE-2022-24828HIGH8.8Composer is a dependency manager for the PHP programming language. Integrators using Composer code to call `VcsDriver::g...
CVE-2022-24818HIGH7.2GeoTools is an open source Java library that provides tools for geospatial data. The GeoTools library has a number of da...
CVE-2022-24816CRITICAL10JAI-EXT is an open-source project which aims to extend the Java Advanced Imaging (JAI) API. Programs allowing Jiffle scr...
CVE-2022-27479CRITICAL9.8Apache Superset before 1.4.2 is vulnerable to SQL injection in chart data requests. Users should update to 1.4.2 or high...
CVE-2022-24788CRITICAL9.8Vyper is a pythonic Smart Contract Language for the ethereum virtual machine. Versions of vyper prior to 0.3.2 suffer fr...
CVE-2022-1347HIGH8.4Stored XSS in the "Username" & "Email" input fields leads to account takeover of Admin & Co-admin users in GitHub reposi...
CVE-2022-1345CRITICAL9Stored XSS viva .svg file upload in GitHub repository causefx/organizr prior to 2.1.1810. This allows attackers to execu...
CVE-2022-0023MEDIUM5.9An improper handling of exceptional conditions vulnerability exists in the DNS proxy feature of Palo Alto Networks PAN-O...
CVE-2022-27847MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in Yooslider Yoo Slider <= 2.0.0 on WordPress allows attackers to import...
CVE-2022-27846MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in Yooslider Yoo Slider <= 2.0.0 on WordPress allows attackers to create...
CVE-2022-27524HIGH7.1An out-of-bounds read can be exploited in Autodesk TrueView 2022 may lead to an exposure of sensitive information or a c...
CVE-2022-27523HIGH7.1A buffer over-read can be exploited in Autodesk TrueView 2022 may lead to an exposure of sensitive information or a cras...
CVE-2022-27506LOW2.7Hard-coded credentials allow administrators to access the shell via the SD-WAN CLI
CVE-2022-27505MEDIUM6.1Reflected cross site scripting (XSS)
CVE-2022-27503MEDIUM6.1Cross-site Scripting (XSS) vulnerability in Citrix StoreFront affects version 1912 before CU5 and version 3.12 before CU...
CVE-2022-25797HIGH7.8A maliciously crafted PDF file in Autodesk AutoCAD 2022, 2021, 2020, 2019 can be used to dereference for a write beyond ...
CVE-2022-25795HIGH7.8A Memory Corruption Vulnerability in Autodesk TrueView 2022 and 2021 may lead to remote code execution through malicious...
CVE-2022-22961MEDIUM5.3VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an information disclosure vulnerability du...
CVE-2022-22960HIGH7.8VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a privilege escalation vulnerability due t...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now