2022 CVE Vulnerabilities
27,553 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-1279 | HIGH | 7.5 | 0.3% | Apr 14, 2022 | A vulnerability in the encryption implementation of EBICS messages in the open source librairy ebics-java/ebics-java-cli... |
| CVE-2022-1350 | HIGH | 7.8 | 0.8% | Apr 14, 2022 | A vulnerability classified as problematic was found in GhostPCL 9.55.0. This vulnerability affects the function chunk_fr... |
| CVE-2022-24847 | HIGH | 7.2 | 1.4% | Apr 13, 2022 | GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. The Geo... |
| CVE-2022-24845 | CRITICAL | 9.8 | 1.3% | Apr 13, 2022 | Vyper is a pythonic Smart Contract Language for the ethereum virtual machine. In affected versions, the return of `<ifac... |
| CVE-2022-24843 | HIGH | 7.5 | 1.4% | Apr 13, 2022 | Gin-vue-admin is a backstage management system based on vue and gin, which separates the front and rear of the full stac... |
| CVE-2022-24844 | HIGH | 8.8 | 1.4% | Apr 13, 2022 | Gin-vue-admin is a backstage management system based on vue and gin, which separates the front and rear of the full stac... |
| CVE-2022-24828 | HIGH | 8.8 | 1.8% | Apr 13, 2022 | Composer is a dependency manager for the PHP programming language. Integrators using Composer code to call `VcsDriver::g... |
| CVE-2022-24818 | HIGH | 7.2 | 2.3% | Apr 13, 2022 | GeoTools is an open source Java library that provides tools for geospatial data. The GeoTools library has a number of da... |
| CVE-2022-24816 | CRITICAL | 10 | 98.7% | Apr 13, 2022 | JAI-EXT is an open-source project which aims to extend the Java Advanced Imaging (JAI) API. Programs allowing Jiffle scr... |
| CVE-2022-27479 | CRITICAL | 9.8 | 2.7% | Apr 13, 2022 | Apache Superset before 1.4.2 is vulnerable to SQL injection in chart data requests. Users should update to 1.4.2 or high... |
| CVE-2022-24788 | CRITICAL | 9.8 | 0.9% | Apr 13, 2022 | Vyper is a pythonic Smart Contract Language for the ethereum virtual machine. Versions of vyper prior to 0.3.2 suffer fr... |
| CVE-2022-1347 | HIGH | 8.4 | 1.2% | Apr 13, 2022 | Stored XSS in the "Username" & "Email" input fields leads to account takeover of Admin & Co-admin users in GitHub reposi... |
| CVE-2022-1345 | CRITICAL | 9 | 1.0% | Apr 13, 2022 | Stored XSS viva .svg file upload in GitHub repository causefx/organizr prior to 2.1.1810. This allows attackers to execu... |
| CVE-2022-0023 | MEDIUM | 5.9 | 0.7% | Apr 13, 2022 | An improper handling of exceptional conditions vulnerability exists in the DNS proxy feature of Palo Alto Networks PAN-O... |
| CVE-2022-27847 | MEDIUM | 4.3 | 0.4% | Apr 13, 2022 | Cross-Site Request Forgery (CSRF) vulnerability in Yooslider Yoo Slider <= 2.0.0 on WordPress allows attackers to import... |
| CVE-2022-27846 | MEDIUM | 4.3 | 0.4% | Apr 13, 2022 | Cross-Site Request Forgery (CSRF) vulnerability in Yooslider Yoo Slider <= 2.0.0 on WordPress allows attackers to create... |
| CVE-2022-27524 | HIGH | 7.1 | 1.3% | Apr 13, 2022 | An out-of-bounds read can be exploited in Autodesk TrueView 2022 may lead to an exposure of sensitive information or a c... |
| CVE-2022-27523 | HIGH | 7.1 | 1.3% | Apr 13, 2022 | A buffer over-read can be exploited in Autodesk TrueView 2022 may lead to an exposure of sensitive information or a cras... |
| CVE-2022-27506 | LOW | 2.7 | 0.6% | Apr 13, 2022 | Hard-coded credentials allow administrators to access the shell via the SD-WAN CLI |
| CVE-2022-27505 | MEDIUM | 6.1 | 0.5% | Apr 13, 2022 | Reflected cross site scripting (XSS) |
| CVE-2022-27503 | MEDIUM | 6.1 | 0.5% | Apr 13, 2022 | Cross-site Scripting (XSS) vulnerability in Citrix StoreFront affects version 1912 before CU5 and version 3.12 before CU... |
| CVE-2022-25797 | HIGH | 7.8 | 1.1% | Apr 13, 2022 | A maliciously crafted PDF file in Autodesk AutoCAD 2022, 2021, 2020, 2019 can be used to dereference for a write beyond ... |
| CVE-2022-25795 | HIGH | 7.8 | 1.8% | Apr 13, 2022 | A Memory Corruption Vulnerability in Autodesk TrueView 2022 and 2021 may lead to remote code execution through malicious... |
| CVE-2022-22961 | MEDIUM | 5.3 | 0.8% | Apr 13, 2022 | VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an information disclosure vulnerability du... |
| CVE-2022-22960 | HIGH | 7.8 | 37.2% | Apr 13, 2022 | VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a privilege escalation vulnerability due t... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now