2022 CVE Vulnerabilities
27,525 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-45139 | MEDIUM | 5.3 | 0.3% | Feb 27, 2023 | A CORS Misconfiguration in the web-based management allows a malicious third party webserver to misuse all basic informa... |
| CVE-2022-45137 | MEDIUM | 6.1 | 0.4% | Feb 27, 2023 | The configuration backend of the web-based management is vulnerable to reflected XSS (Cross-Site Scripting) attacks that... |
| CVE-2022-34910 | MEDIUM | 5.5 | 0.1% | Feb 27, 2023 | An issue was discovered in the A4N (Aremis 4 Nomad) application 1.5.0 for Android. It uses a local database to store dat... |
| CVE-2022-31405 | MEDIUM | 6.5 | 0.6% | Feb 27, 2023 | MV iDigital Clinic Enterprise (iDCE) 1.0 stores passwords in cleartext. |
| CVE-2022-4203 | MEDIUM | 4.9 | 1.5% | Feb 24, 2023 | A read buffer overrun can be triggered in X.509 certificate verification, specifically in name constraint checking. Note... |
| CVE-2022-43923 | MEDIUM | 5.5 | 0.2% | Feb 24, 2023 | IBM Maximo Application Suite 8.8.0 and 8.9.0 stores potentially sensitive information that could be read by a local user... |
| CVE-2022-48345 | MEDIUM | 6.1 | 0.6% | Feb 24, 2023 | sanitize-url (aka @braintree/sanitize-url) before 6.0.2 allows XSS via HTML entities. |
| CVE-2022-46440 | MEDIUM | 5.5 | 0.3% | Feb 24, 2023 | ttftool v0.9.2 was discovered to contain a segmentation violation via the readU16 function at ttf.c. |
| CVE-2022-46785 | MEDIUM | 6.1 | 0.4% | Feb 23, 2023 | SquaredUp Dashboard Server SCOM edition before 5.7.1 GA allows XSS (issue 1 of 2). |
| CVE-2022-46784 | MEDIUM | 6.1 | 0.4% | Feb 23, 2023 | SquaredUp Dashboard Server SCOM edition before 5.7.1 GA allows open redirection. (The issue was originally found in 5.5.... |
| CVE-2022-46786 | MEDIUM | 5.4 | 0.4% | Feb 23, 2023 | SquaredUp Dashboard Server SCOM edition before 5.7.1 GA allows XSS (issue 2 of 2). |
| CVE-2022-48344 | MEDIUM | 6.1 | 0.4% | Feb 23, 2023 | In JetBrains TeamCity before 2022.10.2 there was an XSS vulnerability in the group creation process. |
| CVE-2022-48343 | MEDIUM | 6.1 | 59.5% | Feb 23, 2023 | In JetBrains TeamCity before 2022.10.2 there was an XSS vulnerability in the user creation process. |
| CVE-2022-29273 | MEDIUM | 6.1 | 59.6% | Feb 22, 2023 | pfSense CE through 2.6.0 and pfSense Plus before 22.05 allow XSS in the WebGUI via URL Table Alias URL parameters. |
| CVE-2022-43870 | MEDIUM | 6.5 | 0.6% | Feb 22, 2023 | IBM Spectrum Virtualize 8.3, 8.4, and 8.5 could disclose SNMPv3 server credentials to an authenticated user in log files... |
| CVE-2022-43578 | MEDIUM | 5.4 | 0.4% | Feb 22, 2023 | IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.7 and 6.1.0.0 through 6.1.2.0 is vulnerable to cross-... |
| CVE-2022-41567 | MEDIUM | 5.4 | 0.4% | Feb 22, 2023 | The BusinessConnect UI component of TIBCO Software Inc.'s TIBCO BusinessConnect contains an easily exploitable vulnerabi... |
| CVE-2022-41566 | MEDIUM | 5.4 | 0.4% | Feb 22, 2023 | The server component of TIBCO Software Inc.'s TIBCO EBX Add-ons contains an easily exploitable vulnerability that allows... |
| CVE-2022-41565 | MEDIUM | 5.4 | 0.4% | Feb 22, 2023 | The Web Application component of TIBCO Software Inc.'s TIBCO EBX and TIBCO Product and Service Catalog powered by TIBCO ... |
| CVE-2022-41216 | MEDIUM | 6.5 | 0.6% | Feb 22, 2023 | Local File Inclusion vulnerability within Cloudflow allows attackers to retrieve confidential information from the syste... |
| CVE-2022-38779 | MEDIUM | 6.1 | 0.5% | Feb 22, 2023 | An open redirect issue was discovered in Kibana that could lead to a user being redirected to an arbitrary website if th... |
| CVE-2022-4897 | MEDIUM | 6.1 | 0.9% | Feb 21, 2023 | The BackupBuddy WordPress plugin before 8.8.3 does not sanitise and escape some parameters before outputting them back i... |
| CVE-2022-4791 | MEDIUM | 5.4 | 0.5% | Feb 21, 2023 | The Product Slider and Carousel with Category for WooCommerce WordPress plugin before 2.8 does not validate and escape o... |
| CVE-2022-4786 | MEDIUM | 5.4 | 0.5% | Feb 21, 2023 | The Video.js WordPress plugin through 4.5.0 does not validate and escape some of its shortcode attributes before outputt... |
| CVE-2022-4785 | MEDIUM | 5.4 | 0.5% | Feb 21, 2023 | The Video Sidebar Widgets WordPress plugin through 6.1 does not validate and escape some of its shortcode attributes bef... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now