2022 CVE Vulnerabilities

27,553 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-26295MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in /ptms/?page=user of Online Project Time Management System v1.0 allo...
CVE-2022-26293CRITICAL9.8Online Project Time Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter ...
CVE-2022-23610HIGH8.1wire-server provides back end services for Wire, an open source messenger. In versions of wire-server prior to the 2022-...
CVE-2022-24729HIGH7.5CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. CKEditor4 prior to version 4.18.0 contains a vulne...
CVE-2022-24728MEDIUM5.4CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A vulnerability has been discovered in the core HT...
CVE-2022-23812CRITICAL9.8This affects the package node-ipc from 10.1.1 and before 10.1.3. This package contains malicious code, that targets user...
CVE-2022-21164HIGH7.5The package node-lmdb before 0.9.7 are vulnerable to Denial of Service (DoS) when defining a non-invokable ToString valu...
CVE-2022-26660HIGH7.5RunAsSpc 4.0 uses a universal and recoverable encryption key. In possession of a file encrypted by RunAsSpc, an attacker...
CVE-2022-26354LOW3.2A flaw was found in the vhost-vsock device of QEMU. In case of error, an invalid element was not detached from the virtq...
CVE-2022-26353HIGH7.5A flaw was found in the virtio-net device of QEMU. This flaw was inadvertently introduced with the fix for CVE-2021-3748...
CVE-2022-25252HIGH7.5When connecting to a certain port Axeda agent (All versions) and Axeda Desktop Server for Windows (All versions) when re...
CVE-2022-25251CRITICAL9.8When connecting to a certain port Axeda agent (All versions) and Axeda Desktop Server for Windows (All versions) may all...
CVE-2022-25250HIGH7.5When connecting to a certain port Axeda agent (All versions) and Axeda Desktop Server for Windows (All versions) may all...
CVE-2022-25249HIGH7.5When connecting to a certain port Axeda agent (All versions) and Axeda Desktop Server for Windows (All versions) (disreg...
CVE-2022-25248MEDIUM5.3When connecting to a certain port Axeda agent (All versions) and Axeda Desktop Server for Windows (All versions) supplie...
CVE-2022-25247CRITICAL9.8Axeda agent (All versions) and Axeda Desktop Server for Windows (All versions) may allow an attacker to send certain com...
CVE-2022-25246HIGH8.8Axeda agent (All versions) and Axeda Desktop Server for Windows (All versions) uses hard-coded credentials for its Ultra...
CVE-2022-23234MEDIUM5.5SnapCenter versions prior to 4.5 are susceptible to a vulnerability which could allow a local authenticated attacker to ...
CVE-2022-0982CRITICAL9.8The telnet_input_char function in opt/src/accel-pppd/cli/telnet.c suffers from a memory corruption vulnerability, whereb...
CVE-2022-0959MEDIUM6.5A malicious, but authorised and authenticated user can construct an HTTP request using their existing CSRF token and ses...
CVE-2022-0918HIGH7.5A vulnerability was discovered in the 389 Directory Server that allows an unauthenticated attacker with network access t...
CVE-2022-0811HIGH8.8A flaw was found in CRI-O in the way it set kernel options for a pod. This issue allows anyone with rights to deploy a p...
CVE-2022-24751HIGH7.4Zulip is an open source group chat application. Starting with version 4.0 and prior to version 4.11, Zulip is vulnerable...
CVE-2022-0986MEDIUM6.1Reflected Cross-site Scripting (XSS) Vulnerability in GitHub repository hestiacp/hestiacp prior to 1.5.11.
CVE-2022-0705MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.4.0.

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now