2022 CVE Vulnerabilities

27,554 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-0474LOW3.5Full list of recipients from customer users in a contact field could be disclosed in notification emails event when the ...
CVE-2022-0473MEDIUM4.8OTRS administrators can configure dynamic field and inject malicious JavaScript code in the error message of the regular...
CVE-2022-23184MEDIUM6.1In affected Octopus Server versions when the server HTTP and HTTPS bindings are configured to localhost, Octopus Server ...
CVE-2022-22679MEDIUM4.9Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in support service manageme...
CVE-2022-22680HIGH7.5Exposure of sensitive information to an unauthorized actor vulnerability in Web Server in Synology DiskStation Manager (...
CVE-2022-22833HIGH7.5An issue was discovered in Servisnet Tessa 0.0.2. An attacker can obtain sensitive information via a /js/app.js request.
CVE-2022-24552CRITICAL9.8A flaw was found in the REST API in StarWind Stack. REST command, which manipulates a virtual disk, doesn’t check input ...
CVE-2022-24551HIGH8.8A flaw was found in StarWind Stack. The endpoint for setting a new password doesn’t check the current username and old p...
CVE-2022-22832CRITICAL9.8An issue was discovered in Servisnet Tessa 0.0.2. Authorization data is available via an unauthenticated /data-service/u...
CVE-2022-22831CRITICAL9.8An issue was discovered in Servisnet Tessa 0.0.2. An attacker can add a new sysadmin user via a manipulation of the Auth...
CVE-2022-23206HIGH7.5In Apache Traffic Control Traffic Ops prior to 6.1.0 or 5.1.6, an unprivileged user who can reach Traffic Ops over HTTPS...
CVE-2022-0502MEDIUM5.4Cross-site Scripting (XSS) - Stored in Packagist remdex/livehelperchat prior to 3.93v.
CVE-2022-0501MEDIUM6.1Cross-site Scripting (XSS) - Reflected in Packagist ptrofimov/beanstalk_console prior to 1.7.12.
CVE-2022-0437MEDIUM6.1Cross-site Scripting (XSS) - DOM in NPM karma prior to 6.3.14.
CVE-2022-24115HIGH7.8Local privilege escalation due to unrestricted loading of unsigned libraries. The following products are affected: Acron...
CVE-2022-24114HIGH7Local privilege escalation due to race condition on application startup. The following products are affected: Acronis Cy...
CVE-2022-24113HIGH7.8Local privilege escalation due to excessive permissions assigned to child processes. The following products are affected...
CVE-2022-23980MEDIUM6.1Cross-Site Scripting (XSS) vulnerability discovered in Yasr – Yet Another Stars Rating WordPress plugin (versions <= 2.9...
CVE-2022-23947HIGH7.8A stack-based buffer overflow vulnerability exists in the Gerber Viewer gerber and excellon DCodeNumber parsing function...
CVE-2022-23946HIGH7.8A stack-based buffer overflow vulnerability exists in the Gerber Viewer gerber and excellon GCodeNumber parsing function...
CVE-2022-23913HIGH7.5In Apache ActiveMQ Artemis prior to 2.20.0 or 2.19.1, an attacker could partially disrupt availability (DoS) through unc...
CVE-2022-23805HIGH7.1A security out-of-bounds read information disclosure vulnerability in Trend Micro Worry-Free Business Security Server co...
CVE-2022-23614CRITICAL9.8Twig is an open source template language for PHP. When in a sandbox mode, the `arrow` parameter of the `sort` filter mus...
CVE-2022-23611CRITICAL9.8iTunesRPC-Remastered is a Discord Rich Presence for iTunes on Windows utility. In affected versions iTunesRPC-Remastered...
CVE-2022-23609CRITICAL9.1iTunesRPC-Remastered is a Discord Rich Presence for iTunes on Windows utility. In affected versions iTunesRPC-Remastered...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now