2022 CVE Vulnerabilities

27,553 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-0330HIGH7.8A random memory access flaw was found in the Linux kernel's GPU i915 kernel driver functionality in the way a user may r...
CVE-2022-0322MEDIUM5.5A flaw was found in the sctp_make_strreset_req function in net/sctp/sm_make_chunk.c in the SCTP network protocol in the ...
CVE-2022-27882HIGH7.5slaacd in OpenBSD 6.9 and 7.0 before 2022-03-22 has an integer signedness error and resultant heap-based buffer overflow...
CVE-2022-27881HIGH7.5engine.c in slaacd in OpenBSD 6.9 and 7.0 before 2022-02-21 has a buffer overflow triggerable by an IPv6 router advertis...
CVE-2022-24778HIGH7.5The imgcrypt library provides API exensions for containerd to support encrypted container images and implements the ctd-...
CVE-2022-26263MEDIUM6.1Yonyou u8 v13.0 was discovered to contain a DOM-based cross-site scripting (XSS) vulnerability via the component /u8sl/W...
CVE-2022-25582MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in the Column module of ClassCMS v2.5 and below allows attackers to ex...
CVE-2022-25577CRITICAL9.1ALF-BanCO v8.2.5 and below was discovered to use a hardcoded password to encrypt the SQLite database containing the user...
CVE-2022-24777HIGH7.5grpc-swift is the Swift language implementation of gRPC, a remote procedure call (RPC) framework. Prior to version 1.7.2...
CVE-2022-25574MEDIUM4.8A stored cross-site scripting (XSS) vulnerability in the upload function of /admin/show.php allows attackers to execute ...
CVE-2022-27227HIGH7.5In PowerDNS Authoritative Server before 4.4.3, 4.5.x before 4.5.4, and 4.6.x before 4.6.1 and PowerDNS Recursor before 4...
CVE-2022-1064HIGH8.8SQL injection through marking blog comments on bulk as spam in GitHub repository forkcms/forkcms prior to 5.11.1.
CVE-2022-1040CRITICAL9.8An authentication bypass vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sopho...
CVE-2022-22688HIGH8.8Improper neutralization of special elements used in a command ('Command Injection') vulnerability in File service functi...
CVE-2022-22687CRITICAL9.8Buffer copy without checking size of input ('Classic Buffer Overflow') vulnerability in Authentication functionality in ...
CVE-2022-25576MEDIUM4.5Anchor CMS v0.12.7 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component anchor/routes/posts.p...
CVE-2022-26301CRITICAL9.8TuziCMS v2.0.6 was discovered to contain a SQL injection vulnerability via the component App\Manage\Controller\ZhuantiCo...
CVE-2022-26279CRITICAL9.8EyouCMS v1.5.5 was discovered to have no access control in the component /data/sqldata.
CVE-2022-26272CRITICAL9.8A remote code execution (RCE) vulnerability in Ionize v1.0.8.1 allows attackers to execute arbitrary code via a crafted ...
CVE-2022-26249CRITICAL9.8Survey King v0.3.0 does not filter data properly when exporting excel files, allowing attackers to execute arbitrary cod...
CVE-2022-25575MEDIUM6.1Multiple cross-site scripting (XSS) vulnerabilities in Parking Management System v1.0 allows attackers to execute arbitr...
CVE-2022-25571HIGH7.5Bluedon Information Security Technologies Co.,Ltd Internet Access Detector v1.0 was discovered to contain an information...
CVE-2022-24782MEDIUM4.3Discourse is an open source discussion platform. Versions 2.8.2 and prior in the `stable` branch, 2.9.0.beta3 and prior ...
CVE-2022-24781HIGH7.1Geon is a board game based on solving questions about the Pythagorean Theorem. Malicious users can obtain the uuid from ...
CVE-2022-24776MEDIUM6.1Flask-AppBuilder is an application development framework, built on top of the Flask web framework. Flask-AppBuilder cont...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now