2022 CVE Vulnerabilities

27,554 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-0178MEDIUM5.4Missing Authorization vulnerability in snipe snipe/snipe-it.This issue affects snipe/snipe-i before 5.3.8.
CVE-2022-22991HIGH8.8A malicious user on the same LAN could use DNS spoofing followed by a command injection attack to trick a NAS device int...
CVE-2022-22990HIGH8.8A limited authentication bypass vulnerability was discovered that could allow an attacker to achieve remote code executi...
CVE-2022-22989CRITICAL9.8My Cloud OS 5 was vulnerable to a pre-authenticated stack overflow vulnerability on the FTP service that could be exploi...
CVE-2022-22988CRITICAL9.1File and directory permissions have been corrected to prevent unintended users from modifying or accessing resources. It...
CVE-2022-21684HIGH8.8Discourse is an open source discussion platform. Versions prior to 2.7.13 in `stable`, 2.8.0.beta11 in `beta`, and 2.8.0...
CVE-2022-21682MEDIUM6.5Flatpak is a Linux application sandboxing and distribution framework. A path traversal vulnerability affects versions of...
CVE-2022-21678MEDIUM4.3Discourse is an open source discussion platform. Prior to version 2.8.0.beta11 in the `tests-passed` branch, version 2.8...
CVE-2022-22125MEDIUM4.8In Halo, versions v1.0.0 to v1.4.17 (latest) are vulnerable to Stored Cross-Site Scripting (XSS) in the article tag. An ...
CVE-2022-22124MEDIUM5.4In Halo, versions v1.0.0 to v1.4.17 (latest) are vulnerable to Stored Cross-Site Scripting (XSS) in the profile image. A...
CVE-2022-22123MEDIUM5.4In Halo, versions v1.0.0 to v1.4.17 (latest) are vulnerable to Stored Cross-Site Scripting (XSS) in the article title. A...
CVE-2022-22122Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: None. Reason: This candidate is a reservation duplicate o...
CVE-2022-23134MEDIUM5.3After the initial setup process, some steps of setup.php file are reachable not only by super-administrators, but by una...
CVE-2022-23133MEDIUM5.4An authenticated user can create a hosts group from the configuration with XSS payload, which will be available for othe...
CVE-2022-23132HIGH7.3During Zabbix installation from RPM, DAC_OVERRIDE SELinux capability is in use to access PID files in [/var/run/zabbix] ...
CVE-2022-23131CRITICAL9.8In the case of instances where the SAML SSO authentication is enabled (non-default), session data can be modified by a m...
CVE-2022-22113HIGH8.8In DayByDay CRM, versions 2.2.0 through 2.2.1 (latest) are vulnerable to Insufficient Session Expiration. When a passwor...
CVE-2022-22112MEDIUM5.4In DayByDay CRM, versions 1.1 through 2.2.1 (latest) suffer from an application-wide Client-Side Template Injection (CST...
CVE-2022-0198HIGH7.1corenlp is vulnerable to Improper Restriction of XML External Entity Reference
CVE-2022-0197HIGH8.8phoronix-test-suite is vulnerable to Cross-Site Request Forgery (CSRF)
CVE-2022-0196HIGH8.8phoronix-test-suite is vulnerable to Cross-Site Request Forgery (CSRF)
CVE-2022-23118HIGH8.8Jenkins Debian Package Builder Plugin 1.6.11 and earlier implements functionality that allows agents to invoke command-l...
CVE-2022-23117HIGH7.5Jenkins Conjur Secrets Plugin 1.0.9 and earlier implements functionality that allows attackers able to control agent pro...
CVE-2022-23116HIGH7.5Jenkins Conjur Secrets Plugin 1.0.9 and earlier implements functionality that allows attackers able to control agent pro...
CVE-2022-23115MEDIUM5.4Cross-site request forgery (CSRF) vulnerabilities in Jenkins batch task Plugin 1.19 and earlier allows attackers with Ov...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now