2022 CVE Vulnerabilities

27,553 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-24780HIGH8.8Combodo iTop is a web based IT Service Management tool. In versions prior to 2.7.6 and 3.0.0, users of the iTop user por...
CVE-2022-1244MEDIUM5.5heap-buffer-overflow in GitHub repository radareorg/radare2 prior to 5.6.8. This vulnerability is capable of inducing de...
CVE-2022-28651MEDIUM5.5In JetBrains IntelliJ IDEA before 2021.3.3 it was possible to get passwords from protected fields
CVE-2022-28650MEDIUM5.4In JetBrains YouTrack before 2022.1.43700 it was possible to inject JavaScript into Markdown in the YouTrack Classic UI
CVE-2022-28649MEDIUM5.4In JetBrains YouTrack before 2022.1.43563 it was possible to include an iframe from a third-party domain in the issue de...
CVE-2022-28648MEDIUM5.4In JetBrains YouTrack before 2022.1.43563 HTML code from the issue description was being rendered
CVE-2022-26630HIGH8.8Jellycms v3.8.1 and below was discovered to contain an arbitrary file upload vulnerability via \app.\admin\Controllers\d...
CVE-2022-26635CRITICAL9.8PHP-Memcached v2.2.0 and below contains an improper NULL termination which allows attackers to execute CLRF injection. N...
CVE-2022-22356MEDIUM6.5IBM MQ Appliance 9.2 CD and 9.2 LTS could allow an attacker to enumerate account credentials due to an observable discre...
CVE-2022-22355MEDIUM5.3IBM MQ Appliance 9.2 CD and 9.2 LTS are vulnerable to a denial of service in the Login component of the application whic...
CVE-2022-27463MEDIUM6.1Open redirect vulnerability in objects/login.json.php in WWBN AVideo through 11.6, allows attackers to arbitrarily redir...
CVE-2022-27462MEDIUM6.1Cross Site Scripting (XSS) vulnerability in objects/function.php in function getDeviceID in WWBN AVideo through 11.6, vi...
CVE-2022-24795HIGH7.5yajl-ruby is a C binding to the YAJL JSON parsing and generation library. The 1.x branch and the 2.x branch of `yajl` co...
CVE-2022-0602MEDIUM5.4Cross-site Scripting (XSS) - DOM in GitHub repository tastyigniter/tastyigniter prior to 3.3.0.
CVE-2022-26986HIGH7.2SQL Injection in ImpressCMS 1.4.3 and earlier allows remote attackers to inject into the code in unintended way, this al...
CVE-2022-26982HIGH7.2SimpleMachinesForum 2.1.1 and earlier allows remote authenticated administrators to execute arbitrary code by inserting ...
CVE-2022-1243MEDIUM6.1CRHTLF can lead to invalid protocol extraction potentially leading to XSS in GitHub repository medialize/uri.js prior to...
CVE-2022-26361HIGH7.8IOMMU: RMRR (VT-d) and unity map (AMD-Vi) handling issues T[his CNA information record relates to multiple CVEs; the tex...
CVE-2022-26360HIGH7.8IOMMU: RMRR (VT-d) and unity map (AMD-Vi) handling issues T[his CNA information record relates to multiple CVEs; the tex...
CVE-2022-26359HIGH7.8IOMMU: RMRR (VT-d) and unity map (AMD-Vi) handling issues T[his CNA information record relates to multiple CVEs; the tex...
CVE-2022-26358HIGH7.8IOMMU: RMRR (VT-d) and unity map (AMD-Vi) handling issues T[his CNA information record relates to multiple CVEs; the tex...
CVE-2022-26357HIGH7race in VT-d domain ID cleanup Xen domain IDs are up to 15 bits wide. VT-d hardware may allow for only less than 15 bits...
CVE-2022-26356MEDIUM5.6Racy interactions between dirty vram tracking and paging log dirty hypercalls Activation of log dirty mode done by XEN_D...
CVE-2022-1236MEDIUM6.5Weak Password Requirements in GitHub repository weseek/growi prior to v5.0.0.
CVE-2022-1235HIGH8.2Weak secrethash can be brute-forced in GitHub repository livehelperchat/livehelperchat prior to 3.96.

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now