2022 CVE Vulnerabilities

27,553 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-23136MEDIUM5.4There is a stored XSS vulnerability in ZTE home gateway product. An attacker could modify the gateway name by inserting ...
CVE-2022-22996HIGH7.8The G-RAID 4/8 Software Utility setups for Windows were affected by a DLL hijacking vulnerability. Successful exploitati...
CVE-2022-20002HIGH7.8In incfs, there is a possible way of mounting on arbitrary paths due to a missing permission check. This could lead to l...
CVE-2022-0998HIGH7.8An integer overflow flaw was found in the Linux kernel’s virtio device driver code in the way a user triggers the vhost_...
CVE-2022-25620CRITICAL9Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Group Functionality of Pr...
CVE-2022-25619MEDIUM6.7Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in ping tool of Profel...
CVE-2022-1155HIGH7.4Old sessions are not blocked by the login enable function. in GitHub repository snipe/snipe-it prior to 5.3.10.
CVE-2022-24131MEDIUM6.1DouPHP v1.6 Release 20220121 is affected by Cross Site Scripting (XSS) through /admin/login.php in the background, which...
CVE-2022-1181MEDIUM5.4Stored Cross Site Scripting in GitHub repository openemr/openemr prior to 6.0.0.2.
CVE-2022-1180LOW3.5Reflected Cross Site Scripting in GitHub repository openemr/openemr prior to 6.0.0.4.
CVE-2022-1179MEDIUM5.4Non-Privilege User Can Created New Rule and Lead to Stored Cross Site Scripting in GitHub repository openemr/openemr pri...
CVE-2022-1178MEDIUM5.4Stored Cross Site Scripting in GitHub repository openemr/openemr prior to 6.0.0.4.
CVE-2022-1154HIGH7.8Use after free in utf_ptr2char in GitHub repository vim/vim prior to 8.2.4646.
CVE-2022-23869MEDIUM6.5In RuoYi v4.7.2 through the WebUI, user test1 does not have permission to reset the password of user test3, but the pass...
CVE-2022-23868HIGH7.8RuoYi v4.7.2 contains a CSV injection vulnerability through ruoyi-admin when a victim opens .xlsx log file.
CVE-2022-1177MEDIUM4.3Accounting User Can Download Patient Reports in openemr in GitHub repository openemr/openemr prior to 6.1.0.
CVE-2022-25598HIGH7.5Apache DolphinScheduler user registration is vulnerable to Regular express Denial of Service (ReDoS) attacks, Apache Dol...
CVE-2022-1172MEDIUM5Null Pointer Dereference Caused Segmentation Fault in GitHub repository gpac/gpac prior to 2.1.0-DEV.
CVE-2022-28209CRITICAL9.8An issue was discovered in Mediawiki through 1.37.1. The check for the override-antispoof permission in the AntiSpoof ex...
CVE-2022-28206CRITICAL9.8An issue was discovered in MediaWiki through 1.37.1. ImportPlanValidator.php in the FileImporter extension mishandles th...
CVE-2022-28205CRITICAL9.8An issue was discovered in MediaWiki through 1.37.1. The CentralAuth extension mishandles a ttl issue for groups expirin...
CVE-2022-1163MEDIUM4.8Cross-site Scripting (XSS) - Stored in GitHub repository mineweb/minewebcms prior to next.
CVE-2022-28202MEDIUM6.1An XSS issue was discovered in MediaWiki before 1.35.6, 1.36.x before 1.36.4, and 1.37.x before 1.37.2. The widthheight,...
CVE-2022-27816HIGH7.1SWHKD 1.1.5 unsafely uses the /tmp/swhks.pid pathname. There can be data loss or a denial of service.
CVE-2022-24693CRITICAL9.8Baicells Nova436Q and Neutrino 430 devices with firmware through QRTB 2.7.8 have hardcoded credentials that are easily d...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now