2022 CVE Vulnerabilities
27,554 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-0474 | LOW | 3.5 | 0.6% | Feb 7, 2022 | Full list of recipients from customer users in a contact field could be disclosed in notification emails event when the ... |
| CVE-2022-0473 | MEDIUM | 4.8 | 0.5% | Feb 7, 2022 | OTRS administrators can configure dynamic field and inject malicious JavaScript code in the error message of the regular... |
| CVE-2022-23184 | MEDIUM | 6.1 | 0.6% | Feb 7, 2022 | In affected Octopus Server versions when the server HTTP and HTTPS bindings are configured to localhost, Octopus Server ... |
| CVE-2022-22679 | MEDIUM | 4.9 | 1.1% | Feb 7, 2022 | Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in support service manageme... |
| CVE-2022-22680 | HIGH | 7.5 | 1.1% | Feb 7, 2022 | Exposure of sensitive information to an unauthorized actor vulnerability in Web Server in Synology DiskStation Manager (... |
| CVE-2022-22833 | HIGH | 7.5 | 11.5% | Feb 6, 2022 | An issue was discovered in Servisnet Tessa 0.0.2. An attacker can obtain sensitive information via a /js/app.js request. |
| CVE-2022-24552 | CRITICAL | 9.8 | 1.3% | Feb 6, 2022 | A flaw was found in the REST API in StarWind Stack. REST command, which manipulates a virtual disk, doesn’t check input ... |
| CVE-2022-24551 | HIGH | 8.8 | 0.9% | Feb 6, 2022 | A flaw was found in StarWind Stack. The endpoint for setting a new password doesn’t check the current username and old p... |
| CVE-2022-22832 | CRITICAL | 9.8 | 14.1% | Feb 6, 2022 | An issue was discovered in Servisnet Tessa 0.0.2. Authorization data is available via an unauthenticated /data-service/u... |
| CVE-2022-22831 | CRITICAL | 9.8 | 11.4% | Feb 6, 2022 | An issue was discovered in Servisnet Tessa 0.0.2. An attacker can add a new sysadmin user via a manipulation of the Auth... |
| CVE-2022-23206 | HIGH | 7.5 | 1.9% | Feb 6, 2022 | In Apache Traffic Control Traffic Ops prior to 6.1.0 or 5.1.6, an unprivileged user who can reach Traffic Ops over HTTPS... |
| CVE-2022-0502 | MEDIUM | 5.4 | 0.6% | Feb 6, 2022 | Cross-site Scripting (XSS) - Stored in Packagist remdex/livehelperchat prior to 3.93v. |
| CVE-2022-0501 | MEDIUM | 6.1 | 0.9% | Feb 5, 2022 | Cross-site Scripting (XSS) - Reflected in Packagist ptrofimov/beanstalk_console prior to 1.7.12. |
| CVE-2022-0437 | MEDIUM | 6.1 | 15.2% | Feb 5, 2022 | Cross-site Scripting (XSS) - DOM in NPM karma prior to 6.3.14. |
| CVE-2022-24115 | HIGH | 7.8 | 0.2% | Feb 4, 2022 | Local privilege escalation due to unrestricted loading of unsigned libraries. The following products are affected: Acron... |
| CVE-2022-24114 | HIGH | 7 | 0.2% | Feb 4, 2022 | Local privilege escalation due to race condition on application startup. The following products are affected: Acronis Cy... |
| CVE-2022-24113 | HIGH | 7.8 | 0.2% | Feb 4, 2022 | Local privilege escalation due to excessive permissions assigned to child processes. The following products are affected... |
| CVE-2022-23980 | MEDIUM | 6.1 | 0.8% | Feb 4, 2022 | Cross-Site Scripting (XSS) vulnerability discovered in Yasr – Yet Another Stars Rating WordPress plugin (versions <= 2.9... |
| CVE-2022-23947 | HIGH | 7.8 | 1.4% | Feb 4, 2022 | A stack-based buffer overflow vulnerability exists in the Gerber Viewer gerber and excellon DCodeNumber parsing function... |
| CVE-2022-23946 | HIGH | 7.8 | 1.6% | Feb 4, 2022 | A stack-based buffer overflow vulnerability exists in the Gerber Viewer gerber and excellon GCodeNumber parsing function... |
| CVE-2022-23913 | HIGH | 7.5 | 2.7% | Feb 4, 2022 | In Apache ActiveMQ Artemis prior to 2.20.0 or 2.19.1, an attacker could partially disrupt availability (DoS) through unc... |
| CVE-2022-23805 | HIGH | 7.1 | 0.7% | Feb 4, 2022 | A security out-of-bounds read information disclosure vulnerability in Trend Micro Worry-Free Business Security Server co... |
| CVE-2022-23614 | CRITICAL | 9.8 | 8.3% | Feb 4, 2022 | Twig is an open source template language for PHP. When in a sandbox mode, the `arrow` parameter of the `sort` filter mus... |
| CVE-2022-23611 | CRITICAL | 9.8 | 1.5% | Feb 4, 2022 | iTunesRPC-Remastered is a Discord Rich Presence for iTunes on Windows utility. In affected versions iTunesRPC-Remastered... |
| CVE-2022-23609 | CRITICAL | 9.1 | 1.0% | Feb 4, 2022 | iTunesRPC-Remastered is a Discord Rich Presence for iTunes on Windows utility. In affected versions iTunesRPC-Remastered... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now