2022 CVE Vulnerabilities
27,553 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-1223 | MEDIUM | 6.5 | 1.2% | Apr 4, 2022 | Incorrect Authorization in GitHub repository phpipam/phpipam prior to 1.4.6. |
| CVE-2022-1222 | MEDIUM | 5.5 | 0.8% | Apr 4, 2022 | Inf loop in GitHub repository gpac/gpac prior to 2.1.0-DEV. |
| CVE-2022-0939 | CRITICAL | 9.9 | 1.0% | Apr 4, 2022 | Server-Side Request Forgery (SSRF) in GitHub repository janeczku/calibre-web prior to 0.6.18. |
| CVE-2022-27249 | HIGH | 8.8 | 4.6% | Apr 3, 2022 | An unrestricted file upload vulnerability in IdeaRE RefTree before 2021.09.17 allows remote authenticated users to execu... |
| CVE-2022-27248 | MEDIUM | 6.5 | 2.8% | Apr 3, 2022 | A directory traversal vulnerability in IdeaRE RefTree before 2021.09.17 allows remote authenticated users to download ar... |
| CVE-2022-26530 | CRITICAL | 9.1 | 1.5% | Apr 3, 2022 | swaylock before 1.6 allows attackers to trigger a crash and achieve unlocked access to a Wayland compositor. |
| CVE-2022-26233 | HIGH | 7.5 | 15.0% | Apr 3, 2022 | Barco Control Room Management through Suite 2.9 Build 0275 was discovered to be vulnerable to directory traversal, allow... |
| CVE-2022-28391 | HIGH | 8.8 | 3.5% | Apr 3, 2022 | BusyBox through 1.35.0 allows remote attackers to execute arbitrary code if netstat is used to print a DNS PTR record's ... |
| CVE-2022-28390 | HIGH | 7.8 | 0.4% | Apr 3, 2022 | ems_usb_start_xmit in drivers/net/can/usb/ems_usb.c in the Linux kernel through 5.17.1 has a double free. |
| CVE-2022-28389 | MEDIUM | 5.5 | 0.3% | Apr 3, 2022 | mcba_usb_start_xmit in drivers/net/can/usb/mcba_usb.c in the Linux kernel through 5.17.1 has a double free. |
| CVE-2022-28388 | MEDIUM | 5.5 | 0.4% | Apr 3, 2022 | usb_8dev_start_xmit in drivers/net/can/usb/usb_8dev.c in the Linux kernel through 5.17.1 has a double free. |
| CVE-2022-28381 | CRITICAL | 9.8 | 68.7% | Apr 3, 2022 | Mediaserver.exe in ALLMediaServer 1.6 has a stack-based buffer overflow that allows remote attackers to execute arbitrar... |
| CVE-2022-0406 | MEDIUM | 4.3 | 0.7% | Apr 3, 2022 | Improper Authorization in GitHub repository janeczku/calibre-web prior to 0.6.16. |
| CVE-2022-0405 | MEDIUM | 4.3 | 0.7% | Apr 3, 2022 | Improper Access Control in GitHub repository janeczku/calibre-web prior to 0.6.16. |
| CVE-2022-28380 | HIGH | 7.5 | 1.5% | Apr 3, 2022 | The rc-httpd component through 2022-03-31 for 9front (Plan 9 fork) allows ..%2f directory traversal if serve-static is u... |
| CVE-2022-28379 | MEDIUM | 4.8 | 71.2% | Apr 3, 2022 | jc21.com Nginx Proxy Manager before 2.9.17 allows XSS during item deletion. |
| CVE-2022-28378 | MEDIUM | 6.1 | 0.6% | Apr 3, 2022 | Craft CMS before 3.7.29 allows XSS. |
| CVE-2022-1211 | MEDIUM | 6.5 | 0.9% | Apr 3, 2022 | A vulnerability classified as critical has been found in tildearrow Furnace dev73. This affects the FUR to VGM converter... |
| CVE-2022-1210 | MEDIUM | 6.5 | 1.9% | Apr 3, 2022 | A vulnerability classified as problematic was found in LibTIFF 4.3.0. Affected by this vulnerability is the TIFF File Ha... |
| CVE-2022-0088 | HIGH | 7.4 | 2.0% | Apr 3, 2022 | Cross-Site Request Forgery (CSRF) in GitHub repository yourls/yourls prior to 1.8.3. |
| CVE-2022-28376 | HIGH | 8.1 | 1.2% | Apr 3, 2022 | Verizon 5G Home LVSKIHP outside devices through 2022-02-15 allow anyone (knowing the device's serial number) to access a... |
| CVE-2022-28368 | CRITICAL | 9.8 | 82.4% | Apr 3, 2022 | Dompdf 1.2.1 allows remote code execution via a .php file in the src:url field of an @font-face Cascading Style Sheets (... |
| CVE-2022-28356 | MEDIUM | 5.5 | 0.6% | Apr 2, 2022 | In the Linux kernel before 5.17.1, a refcount leak bug was found in net/llc/af_llc.c. |
| CVE-2022-28355 | HIGH | 7.5 | 1.4% | Apr 2, 2022 | randomUUID in Scala.js before 1.10.0 generates predictable values. |
| CVE-2022-28352 | MEDIUM | 4.8 | 0.4% | Apr 2, 2022 | WeeChat (aka Wee Enhanced Environment for Chat) 3.2 to 3.4 before 3.4.1 does not properly verify the TLS certificate of ... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now