2022 CVE Vulnerabilities
27,553 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-24802 | CRITICAL | 9.8 | 1.6% | Apr 1, 2022 | deepmerge-ts is a typescript library providing functionality to deep merging of javascript objects. deepmerge-ts is vuln... |
| CVE-2022-27966 | MEDIUM | 6.5 | 0.5% | Mar 31, 2022 | Xshell v7.0.0099 and below contains a binary hijack vulnerability which allows attackers to execute arbitrary code via a... |
| CVE-2022-27965 | MEDIUM | 6.5 | 0.5% | Mar 31, 2022 | Xlpd v7.0.0094 and below contains a binary hijack vulnerability which allows attackers to execute arbitrary code via a c... |
| CVE-2022-27964 | MEDIUM | 6.5 | 0.5% | Mar 31, 2022 | Xmanager v7.0.0096 and below contains a binary hijack vulnerability which allows attackers to execute arbitrary code via... |
| CVE-2022-27963 | MEDIUM | 6.5 | 0.4% | Mar 31, 2022 | Xftp 7.0.0088p and below contains a binary hijack vulnerability which allows attackers to execute arbitrary code via a c... |
| CVE-2022-27052 | HIGH | 7.8 | 0.3% | Mar 31, 2022 | FreeFtpd version 1.0.13 and below contains an unquoted service path vulnerability which allows local users to launch pro... |
| CVE-2022-27050 | HIGH | 7.8 | 0.3% | Mar 31, 2022 | BitComet Service for Windows before version 1.8.6 contains an unquoted service path vulnerability which allows attackers... |
| CVE-2022-27049 | LOW | 2 | 0.3% | Mar 31, 2022 | Raidrive before v2021.12.35 allows attackers to arbitrarily move log files by pre-creating a mountpoint and log files be... |
| CVE-2022-24798 | HIGH | 7.5 | 1.4% | Mar 31, 2022 | Internet Routing Registry daemon version 4 is an IRR database server, processing IRR objects in the RPSL format. IRRd di... |
| CVE-2022-24797 | CRITICAL | 9.1 | 1.3% | Mar 31, 2022 | Pomerium is an identity-aware access proxy. In distributed service mode, Pomerium's Authenticate service exposes pprof d... |
| CVE-2022-24796 | CRITICAL | 9.8 | 3.5% | Mar 31, 2022 | RaspberryMatic is a free and open-source operating system for running a cloud-free smart-home using the homematicIP / Ho... |
| CVE-2022-24794 | MEDIUM | 6.1 | 0.7% | Mar 31, 2022 | Express OpenID Connect is an Express JS middleware implementing sign on for Express web apps using OpenID Connect. Users... |
| CVE-2022-24791 | CRITICAL | 9.8 | 1.1% | Mar 31, 2022 | Wasmtime is a standalone JIT-style runtime for WebAssembly, using Cranelift. There is a use after free vulnerability in ... |
| CVE-2022-24758 | HIGH | 7.5 | 1.1% | Mar 31, 2022 | The Jupyter notebook is a web-based notebook environment for interactive computing. Prior to version 6.4.9, unauthorized... |
| CVE-2022-26546 | CRITICAL | 9.1 | 1.4% | Mar 31, 2022 | Hospital Management System v1.0 was discovered to lack an authorization component, allowing attackers to access sensitiv... |
| CVE-2022-22311 | MEDIUM | 6.5 | 0.7% | Mar 31, 2022 | IBM Security Verify Access could allow a user, using man in the middle techniques, to obtain sensitive information or po... |
| CVE-2022-0350 | MEDIUM | 5.4 | 0.5% | Mar 31, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository vanessa219/vditor prior to 3.8.13. |
| CVE-2022-24136 | CRITICAL | 9.8 | 1.9% | Mar 31, 2022 | Hospital Management System v1.0 is affected by an unrestricted upload of dangerous file type vulerability in treatmentre... |
| CVE-2022-1176 | HIGH | 7.5 | 1.2% | Mar 31, 2022 | Loose comparison causes IDOR on multiple endpoints in GitHub repository livehelperchat/livehelperchat prior to 3.96. |
| CVE-2022-25915 | HIGH | 8.8 | 0.4% | Mar 31, 2022 | Improper access control vulnerability in ELECOM LAN routers (WRC-1167GST2 firmware v1.25 and prior, WRC-1167GST2A firmwa... |
| CVE-2022-1191 | HIGH | 8.1 | 0.9% | Mar 31, 2022 | SSRF on index.php/cobrowse/proxycss/ in GitHub repository livehelperchat/livehelperchat prior to 3.96. |
| CVE-2022-28128 | HIGH | 7.8 | 0.4% | Mar 31, 2022 | Untrusted search path vulnerability in AttacheCase ver.3.6.1.0 and earlier allows an attacker to gain privileges and exe... |
| CVE-2022-27496 | MEDIUM | 6.1 | 0.7% | Mar 31, 2022 | Cross-site scripting vulnerability in Zero-channel BBS Plus v0.7.4 and earlier allows a remote attacker to inject an arb... |
| CVE-2022-26019 | HIGH | 8.8 | 4.2% | Mar 31, 2022 | Improper access control vulnerability in pfSense CE and pfSense Plus (pfSense CE software versions prior to 2.6.0 and pf... |
| CVE-2022-25348 | HIGH | 7.8 | 0.4% | Mar 31, 2022 | Untrusted search path vulnerability in AttacheCase ver.4.0.2.7 and earlier allows an attacker to gain privileges and exe... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now