2022 CVE Vulnerabilities

27,553 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-24722MEDIUM6.1VIewComponent is a framework for building view components in Ruby on Rails. Versions prior to 2.31.2 and 2.49.1 contain ...
CVE-2022-23958MEDIUM5.5Potential vulnerabilities have been identified in the BIOS for some HP PC products which may allow denial of service.
CVE-2022-23957MEDIUM5.5Potential vulnerabilities have been identified in the BIOS for some HP PC products which may allow denial of service.
CVE-2022-23955MEDIUM5.5Potential vulnerabilities have been identified in the BIOS for some HP PC products which may allow denial of service.
CVE-2022-23954MEDIUM5.5Potential vulnerabilities have been identified in the BIOS for some HP PC products which may allow denial of service.
CVE-2022-0711HIGH7.5A flaw was found in the way HAProxy processed HTTP responses containing the "Set-Cookie2" header. This flaw could allow ...
CVE-2022-25045CRITICAL9.8Home Owners Collection Management System v1.0 was discovered to contain hardcoded credentials which allows attackers to ...
CVE-2022-23956MEDIUM5.5Potential vulnerabilities have been identified in the BIOS for some HP PC products which may allow denial of service.
CVE-2022-23953MEDIUM5.5Potential vulnerabilities have been identified in the BIOS for some HP PC products which may allow denial of service.
CVE-2022-23656MEDIUM5.4Zulip is an open source team chat app. The `main` development branch of Zulip Server from June 2021 and later is vulnera...
CVE-2022-22944MEDIUM5.4VMware Workspace ONE Boxer contains a stored cross-site scripting (XSS) vulnerability. Due to insufficient sanitization ...
CVE-2022-0675CRITICAL9.8In certain situations it is possible for an unmanaged rule to exist on the target system that has the same comment as th...
CVE-2022-23640CRITICAL9.8Excel-Streaming-Reader is an easy-to-use implementation of a streaming Excel reader using Apache POI. Prior to xlsx-stre...
CVE-2022-23878CRITICAL9.8seacms V11.5 is affected by an arbitrary code execution vulnerability in admin_config.php.
CVE-2022-25016CRITICAL9.8Home Owners Collection Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via the c...
CVE-2022-22350MEDIUM5.5IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in CAA to cause a...
CVE-2022-0819HIGH8.8Code Injection in GitHub repository dolibarr/dolibarr prior to 15.0.1.
CVE-2022-25634HIGH7.5Qt through 5.15.8 and 6.x through 6.2.3 can load system library files from an unintended working directory.
CVE-2022-24447MEDIUM6.5An issue was discovered in Zoho ManageEngine Key Manager Plus before 6200. A service exposed by the application allows a...
CVE-2022-24306CRITICAL9.8Zoho ManageEngine SharePoint Manager Plus before 4329 allows account takeover because authorization is mishandled.
CVE-2022-24305CRITICAL9.8Zoho ManageEngine SharePoint Manager Plus before 4329 is vulnerable to a sensitive data leak that leads to privilege esc...
CVE-2022-23779MEDIUM5.3Zoho ManageEngine Desktop Central before 10.1.2137.8 exposes the installed server name to anyone. The internal hostname ...
CVE-2022-23395MEDIUM6.1jQuery Cookie 1.4.1 is affected by prototype pollution, which can lead to DOM cross-site scripting (XSS).
CVE-2022-0829HIGH8.1Improper Authorization in GitHub repository webmin/webmin prior to 1.990.
CVE-2022-0824HIGH8.8Improper Access Control to Remote Code Execution in GitHub repository webmin/webmin prior to 1.990.

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now