2022 CVE Vulnerabilities

27,553 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-24802CRITICAL9.8deepmerge-ts is a typescript library providing functionality to deep merging of javascript objects. deepmerge-ts is vuln...
CVE-2022-27966MEDIUM6.5Xshell v7.0.0099 and below contains a binary hijack vulnerability which allows attackers to execute arbitrary code via a...
CVE-2022-27965MEDIUM6.5Xlpd v7.0.0094 and below contains a binary hijack vulnerability which allows attackers to execute arbitrary code via a c...
CVE-2022-27964MEDIUM6.5Xmanager v7.0.0096 and below contains a binary hijack vulnerability which allows attackers to execute arbitrary code via...
CVE-2022-27963MEDIUM6.5Xftp 7.0.0088p and below contains a binary hijack vulnerability which allows attackers to execute arbitrary code via a c...
CVE-2022-27052HIGH7.8FreeFtpd version 1.0.13 and below contains an unquoted service path vulnerability which allows local users to launch pro...
CVE-2022-27050HIGH7.8BitComet Service for Windows before version 1.8.6 contains an unquoted service path vulnerability which allows attackers...
CVE-2022-27049LOW2Raidrive before v2021.12.35 allows attackers to arbitrarily move log files by pre-creating a mountpoint and log files be...
CVE-2022-24798HIGH7.5Internet Routing Registry daemon version 4 is an IRR database server, processing IRR objects in the RPSL format. IRRd di...
CVE-2022-24797CRITICAL9.1Pomerium is an identity-aware access proxy. In distributed service mode, Pomerium's Authenticate service exposes pprof d...
CVE-2022-24796CRITICAL9.8RaspberryMatic is a free and open-source operating system for running a cloud-free smart-home using the homematicIP / Ho...
CVE-2022-24794MEDIUM6.1Express OpenID Connect is an Express JS middleware implementing sign on for Express web apps using OpenID Connect. Users...
CVE-2022-24791CRITICAL9.8Wasmtime is a standalone JIT-style runtime for WebAssembly, using Cranelift. There is a use after free vulnerability in ...
CVE-2022-24758HIGH7.5The Jupyter notebook is a web-based notebook environment for interactive computing. Prior to version 6.4.9, unauthorized...
CVE-2022-26546CRITICAL9.1Hospital Management System v1.0 was discovered to lack an authorization component, allowing attackers to access sensitiv...
CVE-2022-22311MEDIUM6.5IBM Security Verify Access could allow a user, using man in the middle techniques, to obtain sensitive information or po...
CVE-2022-0350MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository vanessa219/vditor prior to 3.8.13.
CVE-2022-24136CRITICAL9.8Hospital Management System v1.0 is affected by an unrestricted upload of dangerous file type vulerability in treatmentre...
CVE-2022-1176HIGH7.5Loose comparison causes IDOR on multiple endpoints in GitHub repository livehelperchat/livehelperchat prior to 3.96.
CVE-2022-25915HIGH8.8Improper access control vulnerability in ELECOM LAN routers (WRC-1167GST2 firmware v1.25 and prior, WRC-1167GST2A firmwa...
CVE-2022-1191HIGH8.1SSRF on index.php/cobrowse/proxycss/ in GitHub repository livehelperchat/livehelperchat prior to 3.96.
CVE-2022-28128HIGH7.8Untrusted search path vulnerability in AttacheCase ver.3.6.1.0 and earlier allows an attacker to gain privileges and exe...
CVE-2022-27496MEDIUM6.1Cross-site scripting vulnerability in Zero-channel BBS Plus v0.7.4 and earlier allows a remote attacker to inject an arb...
CVE-2022-26019HIGH8.8Improper access control vulnerability in pfSense CE and pfSense Plus (pfSense CE software versions prior to 2.6.0 and pf...
CVE-2022-25348HIGH7.8Untrusted search path vulnerability in AttacheCase ver.4.0.2.7 and earlier allows an attacker to gain privileges and exe...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now