2022 CVE Vulnerabilities
27,554 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-25174 | HIGH | 8.8 | 1.4% | Feb 15, 2022 | Jenkins Pipeline: Shared Groovy Libraries Plugin 552.vd9cc05b8a2e1 and earlier uses the same checkout directories for di... |
| CVE-2022-25173 | HIGH | 8.8 | 1.4% | Feb 15, 2022 | Jenkins Pipeline: Groovy Plugin 2648.va9433432b33c and earlier uses the same checkout directories for distinct SCMs when... |
| CVE-2022-24590 | MEDIUM | 5.4 | 0.6% | Feb 15, 2022 | A stored cross-site scripting (XSS) vulnerability in the Add Link function of BackdropCMS v1.21.1 allows attackers to ex... |
| CVE-2022-24588 | MEDIUM | 5.4 | 0.7% | Feb 15, 2022 | Flatpress v1.2.1 was discovered to contain a cross-site scripting (XSS) vulnerability in the Upload SVG File function. |
| CVE-2022-24587 | MEDIUM | 5.4 | 0.7% | Feb 15, 2022 | A stored cross-site scripting (XSS) vulnerability in the component core/admin/medias.php of PluXml v5.8.7 allows attacke... |
| CVE-2022-24585 | MEDIUM | 5.4 | 0.7% | Feb 15, 2022 | A stored cross-site scripting (XSS) vulnerability in the component /core/admin/comment.php of PluXml v5.8.7 allows attac... |
| CVE-2022-24226 | HIGH | 7.5 | 1.7% | Feb 15, 2022 | Hospital Management System v4.0 was discovered to contain a blind SQL injection vulnerability via the register function ... |
| CVE-2022-23604 | HIGH | 7.2 | 1.1% | Feb 15, 2022 | x26-Cogs is a repository of cogs made by Twentysix for the Red Discord bot. Among these cogs is the Defender cog, a tool... |
| CVE-2022-21698 | HIGH | 7.5 | 6.0% | Feb 15, 2022 | client_golang is the instrumentation library for Go applications in Prometheus, and the promhttp package in client_golan... |
| CVE-2022-24684 | MEDIUM | 6.5 | 1.4% | Feb 15, 2022 | HashiCorp Nomad and Nomad Enterprise 0.9.0 through 1.0.16, 1.1.11, and 1.2.5 allow operators with job-submit capabilitie... |
| CVE-2022-24227 | MEDIUM | 6.1 | 2.2% | Feb 15, 2022 | A cross-site scripting (XSS) vulnerability in BoltWire v7.10 and v 8.00 allows attackers to execute arbitrary web script... |
| CVE-2022-24586 | MEDIUM | 5.4 | 0.7% | Feb 15, 2022 | A stored cross-site scripting (XSS) vulnerability in the component /core/admin/categories.php of PluXml v5.8.7 allows at... |
| CVE-2022-0597 | MEDIUM | 6.1 | 3.0% | Feb 15, 2022 | Open Redirect in Packagist microweber/microweber prior to 1.2.11. |
| CVE-2022-0596 | MEDIUM | 4.3 | 0.6% | Feb 15, 2022 | Improper Validation of Specified Quantity in Input in Packagist microweber/microweber prior to 1.2.11. |
| CVE-2022-23384 | HIGH | 8.8 | 0.5% | Feb 15, 2022 | YzmCMS v6.3 is affected by Cross Site Request Forgery (CSRF) in /admin.add |
| CVE-2022-23317 | HIGH | 7.5 | 1.1% | Feb 15, 2022 | CobaltStrike <=4.5 HTTP(S) listener does not determine whether the request URL begins with "/", and attackers can obtain... |
| CVE-2022-0589 | MEDIUM | 5.4 | 0.8% | Feb 15, 2022 | Cross-site Scripting (XSS) - Stored in Packagist librenms/librenms prior to 22.1.0. |
| CVE-2022-0588 | MEDIUM | 6.5 | 1.1% | Feb 15, 2022 | Missing Authorization in Packagist librenms/librenms prior to 22.2.0. |
| CVE-2022-0587 | MEDIUM | 6.5 | 1.0% | Feb 15, 2022 | Improper Authorization in Packagist librenms/librenms prior to 22.2.0. |
| CVE-2022-21818 | MEDIUM | 5.4 | 0.3% | Feb 15, 2022 | NVIDIA License System contains a vulnerability in the installation scripts for the DLS virtual appliance, where a user o... |
| CVE-2022-0580 | HIGH | 8.8 | 1.1% | Feb 14, 2022 | Incorrect Authorization in Packagist librenms/librenms prior to 22.2.0. |
| CVE-2022-25139 | CRITICAL | 9.8 | 1.6% | Feb 14, 2022 | njs through 0.7.0, used in NGINX, was discovered to contain a heap use-after-free in njs_await_fulfilled. |
| CVE-2022-24705 | CRITICAL | 9.8 | 1.2% | Feb 14, 2022 | The rad_packet_recv function in radius/packet.c suffers from a memcpy buffer overflow, resulting in an overly-large recv... |
| CVE-2022-24704 | CRITICAL | 9.8 | 1.2% | Feb 14, 2022 | The rad_packet_recv function in opt/src/accel-pppd/radius/packet.c suffers from a buffer overflow vulnerability, whereby... |
| CVE-2022-23992 | CRITICAL | 9.8 | 2.3% | Feb 14, 2022 | XCOM Data Transport for Windows, Linux, and UNIX 11.6 releases contain a vulnerability due to insufficient input validat... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now