2022 CVE Vulnerabilities

27,553 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-24299HIGH8.8Improper input validation vulnerability in pfSense CE and pfSense Plus (pfSense CE software versions prior to 2.6.0 and ...
CVE-2022-23183MEDIUM6.5Missing authorization vulnerability in Advanced Custom Fields versions prior to 5.12.1 and Advanced Custom Fields Pro ve...
CVE-2022-22986HIGH8.8Netcommunity OG410X and OG810X series (Netcommunity OG410Xa, OG410Xi, OG810Xa, and OG810Xi firmware Ver.2.28 and earlier...
CVE-2022-26646CRITICAL9.8Online Banking System Protect v1.0 was discovered to contain a local file inclusion (LFI) vulnerability via the pages pa...
CVE-2022-26645CRITICAL9.8A remote code execution (RCE) vulnerability in Online Banking System Protect v1.0 allows attackers to execute arbitrary ...
CVE-2022-26644MEDIUM6.1Online Banking System Protect v1.0 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities via par...
CVE-2022-25008HIGH8.8totolink EX300_v2 V4.0.3c.140_B20210429 and EX1200T V4.1.2cu.5230_B20210706 does not contain an authentication mechanism...
CVE-2022-24790HIGH7.5Puma is a simple, fast, multi-threaded, parallel HTTP 1.1 server for Ruby/Rack applications. When using Puma behind a pr...
CVE-2022-24763HIGH7.5PJSIP is a free and open source multimedia communication library written in the C language. Versions 2.12 and prior cont...
CVE-2022-1160HIGH7.8heap buffer overflow in get_one_sourceline in GitHub repository vim/vim prior to 8.2.4647.
CVE-2022-28223HIGH7.2Tekon KIO devices through 2022-03-30 allow an authenticated admin user to escalate privileges to root by uploading a mal...
CVE-2022-27772HIGH7.8spring-boot versions prior to version v2.2.11.RELEASE was vulnerable to temporary directory hijacking. This vulnerabilit...
CVE-2022-24135MEDIUM6.1QingScan 1.3.0 is affected by Cross Site Scripting (XSS) vulnerability in all search functions.
CVE-2022-24132HIGH7.5phpshe V1.8 is affected by a denial of service (DoS) attack in the registry's verification code, which can paralyze the ...
CVE-2022-22772HIGH7.5The cfsend, cfrecv, and CyberResp components of TIBCO Software Inc.'s TIBCO Managed File Transfer Platform Server for UN...
CVE-2022-27907MEDIUM4.3Sonatype Nexus Repository Manager 3.x before 3.38.0 allows SSRF.
CVE-2022-23801MEDIUM6.1An issue was discovered in Joomla! 4.0.0 through 4.1.0. Possible XSS atack vector through SVG embedding in com_media.
CVE-2022-23800MEDIUM6.1An issue was discovered in Joomla! 4.0.0 through 4.1.0. Inadequate content filtering leads to XSS vulnerabilities in var...
CVE-2022-23799CRITICAL9.8An issue was discovered in Joomla! 4.0.0 through 4.1.0. Under specific circumstances, JInput pollutes method-specific in...
CVE-2022-23798MEDIUM6.1An issue was discovered in Joomla! 2.5.0 through 3.10.6 & 4.0.0 through 4.1.0. Inadequate validation of URLs could resul...
CVE-2022-23797CRITICAL9.8An issue was discovered in Joomla! 3.0.0 through 3.10.6 & 4.0.0 through 4.1.0. Inadequate filtering on the selected Ids ...
CVE-2022-23796MEDIUM6.1An issue was discovered in Joomla! 3.7.0 through 3.10.6. Lack of input validation could allow an XSS attack using com_fi...
CVE-2022-23795CRITICAL9.8An issue was discovered in Joomla! 2.5.0 through 3.10.6 & 4.0.0 through 4.1.0. A user row was not bound to a specific au...
CVE-2022-23794MEDIUM5.3An issue was discovered in Joomla! 3.0.0 through 3.10.6 & 4.0.0 through 4.1.0. Uploading a file name of an excess length...
CVE-2022-23793HIGH7.5An issue was discovered in Joomla! 3.0.0 through 3.10.6 & 4.0.0 through 4.1.0. Extracting an specifilcy crafted tar pack...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now