2022 CVE Vulnerabilities
27,554 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-22938 | MEDIUM | 6.5 | 0.4% | Jan 28, 2022 | VMware Workstation (16.x prior to 16.2.2) and Horizon Client for Windows (5.x prior to 5.5.3) contains a denial-of-servi... |
| CVE-2022-22791 | MEDIUM | 5.4 | 0.4% | Jan 28, 2022 | SYNEL - eharmony Authenticated Blind & Stored XSS. Inject JS code into the "comments" field could lead to potential stea... |
| CVE-2022-22790 | HIGH | 7.5 | 1.0% | Jan 28, 2022 | SYNEL - eharmony Directory Traversal. Directory Traversal - is an attack against a server or a Web application aimed at ... |
| CVE-2022-21801 | HIGH | 7.5 | 1.1% | Jan 28, 2022 | A denial of service vulnerability exists in the netserver recv_command functionality of reolink RLC-410W v3.0.0.136_2012... |
| CVE-2022-21796 | HIGH | 8.2 | 1.3% | Jan 28, 2022 | A memory corruption vulnerability exists in the netserver parse_command_list functionality of reolink RLC-410W v3.0.0.13... |
| CVE-2022-21236 | HIGH | 7.5 | 1.8% | Jan 28, 2022 | An information disclosure vulnerability exists due to a web server misconfiguration in the Reolink RLC-410W v3.0.0.136_2... |
| CVE-2022-21217 | CRITICAL | 9.8 | 1.4% | Jan 28, 2022 | An out-of-bounds write vulnerability exists in the device TestEmail functionality of reolink RLC-410W v3.0.0.136_2012110... |
| CVE-2022-21199 | MEDIUM | 5.9 | 0.9% | Jan 28, 2022 | An information disclosure vulnerability exists due to the hardcoded TLS key of reolink RLC-410W v3.0.0.136_20121102. A s... |
| CVE-2022-21134 | HIGH | 7.5 | 0.9% | Jan 28, 2022 | A firmware update vulnerability exists in the "update" firmware checks functionality of reolink RLC-410W v3.0.... |
| CVE-2022-22868 | MEDIUM | 4.8 | 0.9% | Jan 28, 2022 | Gibbon CMS v22.0.01 was discovered to contain a cross-site scripting (XSS) vulnerability, that allows attackers to injec... |
| CVE-2022-22294 | CRITICAL | 9.8 | 1.1% | Jan 28, 2022 | A SQL injection vulnerability exists in ZFAKA<=1.43 which an attacker can use to complete SQL injection in the foregroun... |
| CVE-2022-23863 | MEDIUM | 6.5 | 1.9% | Jan 28, 2022 | Zoho ManageEngine Desktop Central before 10.1.2137.10 allows an authenticated user to change any user's login password. |
| CVE-2022-23098 | HIGH | 7.5 | 2.5% | Jan 28, 2022 | An issue was discovered in the DNS proxy in Connman through 1.40. The TCP server reply implementation has an infinite lo... |
| CVE-2022-23097 | CRITICAL | 9.1 | 2.4% | Jan 28, 2022 | An issue was discovered in the DNS proxy in Connman through 1.40. forward_dns_reply mishandles a strnlen call, leading t... |
| CVE-2022-23096 | CRITICAL | 9.1 | 2.6% | Jan 28, 2022 | An issue was discovered in the DNS proxy in Connman through 1.40. The TCP server reply implementation lacks a check for ... |
| CVE-2022-24071 | MEDIUM | 4.3 | 0.7% | Jan 28, 2022 | A Built-in extension in Whale browser before 3.12.129.46 allows attackers to compromise the rendering process which coul... |
| CVE-2022-21720 | MEDIUM | 4.9 | 1.1% | Jan 28, 2022 | GLPI is a free asset and IT management software package. Prior to version 9.5.7, an entity administrator is capable of r... |
| CVE-2022-0394 | MEDIUM | 5.4 | 0.5% | Jan 28, 2022 | Cross-site Scripting (XSS) - Stored in Packagist remdex/livehelperchat prior to 3.93v. |
| CVE-2022-21719 | MEDIUM | 6.1 | 1.0% | Jan 28, 2022 | GLPI is a free asset and IT management software package. All GLPI versions prior to 9.5.7 are vulnerable to reflected cr... |
| CVE-2022-0348 | MEDIUM | 5.4 | 0.6% | Jan 27, 2022 | Cross-site Scripting (XSS) - Stored in Packagist pimcore/pimcore prior to 10.2. |
| CVE-2022-23181 | HIGH | 7 | 0.7% | Jan 27, 2022 | The fix for bug CVE-2020-9484 introduced a time of check, time of use vulnerability into Apache Tomcat 10.1.0-M1 to 10.1... |
| CVE-2022-0372 | MEDIUM | 5.4 | 0.6% | Jan 27, 2022 | Cross-site Scripting (XSS) - Stored in Packagist bytefury/crater prior to 6.0.2. |
| CVE-2022-22828 | HIGH | 7.5 | 2.1% | Jan 27, 2022 | An insecure direct object reference for the file-download URL in Synametrics SynaMan before 5.0 allows a remote attacker... |
| CVE-2022-0387 | MEDIUM | 5.4 | 0.6% | Jan 27, 2022 | Cross-site Scripting (XSS) - Stored in Packagist remdex/livehelperchat prior to 3.93v. |
| CVE-2022-0370 | MEDIUM | 5.4 | 0.8% | Jan 27, 2022 | Cross-site Scripting (XSS) - Stored in Packagist remdex/livehelperchat prior to 3.93v. |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now