2022 CVE Vulnerabilities
27,553 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-0330 | HIGH | 7.8 | 0.4% | Mar 25, 2022 | A random memory access flaw was found in the Linux kernel's GPU i915 kernel driver functionality in the way a user may r... |
| CVE-2022-0322 | MEDIUM | 5.5 | 0.3% | Mar 25, 2022 | A flaw was found in the sctp_make_strreset_req function in net/sctp/sm_make_chunk.c in the SCTP network protocol in the ... |
| CVE-2022-27882 | HIGH | 7.5 | 1.9% | Mar 25, 2022 | slaacd in OpenBSD 6.9 and 7.0 before 2022-03-22 has an integer signedness error and resultant heap-based buffer overflow... |
| CVE-2022-27881 | HIGH | 7.5 | 1.9% | Mar 25, 2022 | engine.c in slaacd in OpenBSD 6.9 and 7.0 before 2022-02-21 has a buffer overflow triggerable by an IPv6 router advertis... |
| CVE-2022-24778 | HIGH | 7.5 | 2.7% | Mar 25, 2022 | The imgcrypt library provides API exensions for containerd to support encrypted container images and implements the ctd-... |
| CVE-2022-26263 | MEDIUM | 6.1 | 37.7% | Mar 25, 2022 | Yonyou u8 v13.0 was discovered to contain a DOM-based cross-site scripting (XSS) vulnerability via the component /u8sl/W... |
| CVE-2022-25582 | MEDIUM | 5.4 | 0.6% | Mar 25, 2022 | A stored cross-site scripting (XSS) vulnerability in the Column module of ClassCMS v2.5 and below allows attackers to ex... |
| CVE-2022-25577 | CRITICAL | 9.1 | 1.2% | Mar 25, 2022 | ALF-BanCO v8.2.5 and below was discovered to use a hardcoded password to encrypt the SQLite database containing the user... |
| CVE-2022-24777 | HIGH | 7.5 | 1.1% | Mar 25, 2022 | grpc-swift is the Swift language implementation of gRPC, a remote procedure call (RPC) framework. Prior to version 1.7.2... |
| CVE-2022-25574 | MEDIUM | 4.8 | 0.4% | Mar 25, 2022 | A stored cross-site scripting (XSS) vulnerability in the upload function of /admin/show.php allows attackers to execute ... |
| CVE-2022-27227 | HIGH | 7.5 | 4.9% | Mar 25, 2022 | In PowerDNS Authoritative Server before 4.4.3, 4.5.x before 4.5.4, and 4.6.x before 4.6.1 and PowerDNS Recursor before 4... |
| CVE-2022-1064 | HIGH | 8.8 | 1.1% | Mar 25, 2022 | SQL injection through marking blog comments on bulk as spam in GitHub repository forkcms/forkcms prior to 5.11.1. |
| CVE-2022-1040 | CRITICAL | 9.8 | 99.8% | Mar 25, 2022 | An authentication bypass vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sopho... |
| CVE-2022-22688 | HIGH | 8.8 | 1.6% | Mar 25, 2022 | Improper neutralization of special elements used in a command ('Command Injection') vulnerability in File service functi... |
| CVE-2022-22687 | CRITICAL | 9.8 | 2.3% | Mar 25, 2022 | Buffer copy without checking size of input ('Classic Buffer Overflow') vulnerability in Authentication functionality in ... |
| CVE-2022-25576 | MEDIUM | 4.5 | 0.4% | Mar 24, 2022 | Anchor CMS v0.12.7 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component anchor/routes/posts.p... |
| CVE-2022-26301 | CRITICAL | 9.8 | 1.1% | Mar 24, 2022 | TuziCMS v2.0.6 was discovered to contain a SQL injection vulnerability via the component App\Manage\Controller\ZhuantiCo... |
| CVE-2022-26279 | CRITICAL | 9.8 | 1.8% | Mar 24, 2022 | EyouCMS v1.5.5 was discovered to have no access control in the component /data/sqldata. |
| CVE-2022-26272 | CRITICAL | 9.8 | 22.5% | Mar 24, 2022 | A remote code execution (RCE) vulnerability in Ionize v1.0.8.1 allows attackers to execute arbitrary code via a crafted ... |
| CVE-2022-26249 | CRITICAL | 9.8 | 1.8% | Mar 24, 2022 | Survey King v0.3.0 does not filter data properly when exporting excel files, allowing attackers to execute arbitrary cod... |
| CVE-2022-25575 | MEDIUM | 6.1 | 0.6% | Mar 24, 2022 | Multiple cross-site scripting (XSS) vulnerabilities in Parking Management System v1.0 allows attackers to execute arbitr... |
| CVE-2022-25571 | HIGH | 7.5 | 0.9% | Mar 24, 2022 | Bluedon Information Security Technologies Co.,Ltd Internet Access Detector v1.0 was discovered to contain an information... |
| CVE-2022-24782 | MEDIUM | 4.3 | 0.9% | Mar 24, 2022 | Discourse is an open source discussion platform. Versions 2.8.2 and prior in the `stable` branch, 2.9.0.beta3 and prior ... |
| CVE-2022-24781 | HIGH | 7.1 | 0.9% | Mar 24, 2022 | Geon is a board game based on solving questions about the Pythagorean Theorem. Malicious users can obtain the uuid from ... |
| CVE-2022-24776 | MEDIUM | 6.1 | 0.9% | Mar 24, 2022 | Flask-AppBuilder is an application development framework, built on top of the Flask web framework. Flask-AppBuilder cont... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now