2022 CVE Vulnerabilities
27,553 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-0838 | MEDIUM | 6.1 | 1.1% | Mar 4, 2022 | Cross-site Scripting (XSS) - Reflected in GitHub repository hestiacp/hestiacp prior to 1.5.10. |
| CVE-2022-0730 | CRITICAL | 9.8 | 3.5% | Mar 3, 2022 | Under certain ldap conditions, Cacti authentication can be bypassed with certain credential types. |
| CVE-2022-25220 | MEDIUM | 4.8 | 0.5% | Mar 3, 2022 | PeteReport Version 0.5 allows an authenticated admin user to inject persistent JavaScript code inside the markdown descr... |
| CVE-2022-24725 | MEDIUM | 5.5 | 0.5% | Mar 3, 2022 | Shescape is a shell escape package for JavaScript. An issue in versions 1.4.0 to 1.5.1 allows for exposure of the home d... |
| CVE-2022-23710 | MEDIUM | 6.1 | 0.7% | Mar 3, 2022 | A cross-site-scripting (XSS) vulnerability was discovered in the Data Preview Pane (previously known as Index Pattern Pr... |
| CVE-2022-23709 | MEDIUM | 4.3 | 0.5% | Mar 3, 2022 | A flaw was discovered in Kibana in which users with Read access to the Uptime feature could modify alerting rules. A use... |
| CVE-2022-23708 | MEDIUM | 4.3 | 0.9% | Mar 3, 2022 | A flaw was discovered in Elasticsearch 7.17.0’s upgrade assistant, in which upgrading from version 6.x to 7.x would disa... |
| CVE-2022-23052 | MEDIUM | 6.5 | 0.4% | Mar 3, 2022 | PeteReport Version 0.5 contains a Cross Site Request Forgery (CSRF) vulnerability allowing an attacker to trick users in... |
| CVE-2022-23051 | MEDIUM | 5.4 | 0.5% | Mar 3, 2022 | PeteReport Version 0.5 allows an authenticated admin user to inject persistent JavaScript code while adding an 'Attack T... |
| CVE-2022-22947 | CRITICAL | 10 | 98.3% | Mar 3, 2022 | In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe... |
| CVE-2022-22943 | MEDIUM | 6.7 | 1.2% | Mar 3, 2022 | VMware Tools for Windows (11.x.y and 10.x.y prior to 12.0.0) contains an uncontrolled search path vulnerability. A malic... |
| CVE-2022-0265 | CRITICAL | 9.8 | 2.8% | Mar 3, 2022 | Improper Restriction of XML External Entity Reference in GitHub repository hazelcast/hazelcast in 5.1-BETA-1. |
| CVE-2022-24723 | MEDIUM | 5.3 | 2.0% | Mar 3, 2022 | URI.js is a Javascript URL mutation library. Before version 1.19.9, whitespace characters are not removed from the begin... |
| CVE-2022-21716 | HIGH | 7.5 | 3.6% | Mar 3, 2022 | Twisted is an event-based framework for internet applications, supporting Python 3.6+. Prior to 22.2.0, Twisted SSH clie... |
| CVE-2022-24724 | CRITICAL | 9.8 | 4.2% | Mar 3, 2022 | cmark-gfm is GitHub's extended version of the C reference implementation of CommonMark. Prior to versions 0.29.0.gfm.3 a... |
| CVE-2022-25125 | CRITICAL | 9.8 | 7.2% | Mar 3, 2022 | MCMS v5.2.4 was discovered to contain a SQL injection vulnerability via search.do in the file /mdiy/dict/listExcludeApp. |
| CVE-2022-23899 | CRITICAL | 9.8 | 1.1% | Mar 3, 2022 | MCMS v5.2.5 was discovered to contain a SQL injection vulnerability via search.do in the file /web/MCmsAction.java. |
| CVE-2022-23898 | CRITICAL | 9.8 | 7.7% | Mar 3, 2022 | MCMS v5.2.5 was discovered to contain a SQL injection vulnerability via the categoryId parameter in the file IContentDao... |
| CVE-2022-22700 | MEDIUM | 5.3 | 1.1% | Mar 3, 2022 | CyberArk Identity versions up to and including 22.1 in the 'StartAuthentication' resource, exposes the response header '... |
| CVE-2022-0492 | HIGH | 7.8 | 5.5% | Mar 3, 2022 | A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function. Th... |
| CVE-2022-26129 | HIGH | 7.8 | 1.0% | Mar 3, 2022 | Buffer overflow vulnerabilities exist in FRRouting through 8.1.0 due to wrong checks on the subtlv length in the functio... |
| CVE-2022-26128 | HIGH | 7.8 | 1.0% | Mar 3, 2022 | A buffer overflow vulnerability exists in FRRouting through 8.1.0 due to a wrong check on the input packet length in the... |
| CVE-2022-26127 | HIGH | 7.8 | 1.0% | Mar 3, 2022 | A buffer overflow vulnerability exists in FRRouting through 8.1.0 due to missing a check on the input packet length in t... |
| CVE-2022-26126 | HIGH | 7.8 | 1.1% | Mar 3, 2022 | Buffer overflow vulnerabilities exist in FRRouting through 8.1.0 due to the use of strdup with a non-zero-terminated bin... |
| CVE-2022-26125 | HIGH | 7.8 | 1.0% | Mar 3, 2022 | Buffer overflow vulnerabilities exist in FRRouting through 8.1.0 due to wrong checks on the input packet length in isisd... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now