2022 CVE Vulnerabilities

27,525 CVEs published in 2022.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2022-4809HIGH8.8Improper Access Control in GitHub repository usememos/memos prior to 0.9.1.
CVE-2022-4808HIGH8.8Improper Privilege Management in GitHub repository usememos/memos prior to 0.9.1.
CVE-2022-4803HIGH8.8Authorization Bypass Through User-Controlled Key in GitHub repository usememos/memos prior to 0.9.1.
CVE-2022-4796HIGH8.1Incorrect Use of Privileged APIs in GitHub repository usememos/memos prior to 0.9.1.
CVE-2022-46179HIGH7.8LiuOS is a small Python project meant to imitate the functions of a regular operating system. Version 0.1.0 and prior of...
CVE-2022-3347HIGH7.5DNSSEC validation is not performed correctly. An attacker can cause this package to report successful validation for inv...
CVE-2022-23555HIGH8.8authentik is an open-source Identity Provider focused on flexibility and versatility. Versions prior to 2022.11.4 and 20...
CVE-2022-41967HIGH7.5Dragonfly is a Java runtime dependency management library. Dragonfly v0.3.0-SNAPSHOT does not configure DocumentBuilderF...
CVE-2022-41966HIGH7.5XStream serializes Java objects to XML and back again. Versions prior to 1.4.20 may allow a remote attacker to terminate...
CVE-2022-4772HIGH7.8A vulnerability was found in Widoco and classified as critical. Affected by this issue is the function unZipIt of the fi...
CVE-2022-3064HIGH7.5Parsing malicious or large YAML documents can consume excessive amounts of CPU or memory.
CVE-2022-2584HIGH7.5The dag-pb codec can panic when decoding invalid blocks.
CVE-2022-3156HIGH7.8A remote code execution vulnerability exists in Rockwell Automation Studio 5000 Logix Emulate software.  Users are grant...
CVE-2022-45431HIGH7.5Some Dahua software products have a vulnerability of unauthenticated restart of remote DSS Server. After bypassing the f...
CVE-2022-45429HIGH7.5Some Dahua software products have a vulnerability of server-side request forgery (SSRF). An Attacker can access internal...
CVE-2022-45427HIGH7.2Some Dahua software products have a vulnerability of unrestricted upload of file. After obtaining the permissions of adm...
CVE-2022-45425HIGH7.5Some Dahua software products have a vulnerability of using of hard-coded cryptographic key. An attacker can obtain the A...
CVE-2022-45423HIGH7.5Some Dahua software products have a vulnerability of unauthenticated request of MQTT credentials. An attacker can obtain...
CVE-2022-4767HIGH7.5Denial of Service in GitHub repository usememos/memos prior to 0.9.1.
CVE-2022-4732HIGH7.2Unrestricted Upload of File with Dangerous Type in GitHub repository microweber/microweber prior to 1.3.2.
CVE-2022-4722HIGH7.2Authentication Bypass by Primary Weakness in GitHub repository ikus060/rdiffweb prior to 2.5.5.
CVE-2022-46763HIGH8.8A SQL injection issue in a database stored function in TrueConf Server 5.2.0.10225 (fixed in 5.2.6.10025) allows a low-p...
CVE-2022-4268HIGH7.2The Plugin Logic WordPress plugin before 1.0.8 does not sanitise and escape a parameter before using it in a SQL stateme...
CVE-2022-4158HIGH7.5The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape...
CVE-2022-4156HIGH7.5The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now