2022 CVE Vulnerabilities
27,554 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-0178 | MEDIUM | 5.4 | 0.7% | Jan 13, 2022 | Missing Authorization vulnerability in snipe snipe/snipe-it.This issue affects snipe/snipe-i before 5.3.8. |
| CVE-2022-22991 | HIGH | 8.8 | 1.3% | Jan 13, 2022 | A malicious user on the same LAN could use DNS spoofing followed by a command injection attack to trick a NAS device int... |
| CVE-2022-22990 | HIGH | 8.8 | 2.1% | Jan 13, 2022 | A limited authentication bypass vulnerability was discovered that could allow an attacker to achieve remote code executi... |
| CVE-2022-22989 | CRITICAL | 9.8 | 1.3% | Jan 13, 2022 | My Cloud OS 5 was vulnerable to a pre-authenticated stack overflow vulnerability on the FTP service that could be exploi... |
| CVE-2022-22988 | CRITICAL | 9.1 | 0.7% | Jan 13, 2022 | File and directory permissions have been corrected to prevent unintended users from modifying or accessing resources. It... |
| CVE-2022-21684 | HIGH | 8.8 | 1.0% | Jan 13, 2022 | Discourse is an open source discussion platform. Versions prior to 2.7.13 in `stable`, 2.8.0.beta11 in `beta`, and 2.8.0... |
| CVE-2022-21682 | MEDIUM | 6.5 | 1.7% | Jan 13, 2022 | Flatpak is a Linux application sandboxing and distribution framework. A path traversal vulnerability affects versions of... |
| CVE-2022-21678 | MEDIUM | 4.3 | 0.9% | Jan 13, 2022 | Discourse is an open source discussion platform. Prior to version 2.8.0.beta11 in the `tests-passed` branch, version 2.8... |
| CVE-2022-22125 | MEDIUM | 4.8 | 0.8% | Jan 13, 2022 | In Halo, versions v1.0.0 to v1.4.17 (latest) are vulnerable to Stored Cross-Site Scripting (XSS) in the article tag. An ... |
| CVE-2022-22124 | MEDIUM | 5.4 | 0.7% | Jan 13, 2022 | In Halo, versions v1.0.0 to v1.4.17 (latest) are vulnerable to Stored Cross-Site Scripting (XSS) in the profile image. A... |
| CVE-2022-22123 | MEDIUM | 5.4 | 0.7% | Jan 13, 2022 | In Halo, versions v1.0.0 to v1.4.17 (latest) are vulnerable to Stored Cross-Site Scripting (XSS) in the article title. A... |
| CVE-2022-22122 | — | — | — | Jan 13, 2022 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: None. Reason: This candidate is a reservation duplicate o... |
| CVE-2022-23134 | MEDIUM | 5.3 | 84.7% | Jan 13, 2022 | After the initial setup process, some steps of setup.php file are reachable not only by super-administrators, but by una... |
| CVE-2022-23133 | MEDIUM | 5.4 | 1.0% | Jan 13, 2022 | An authenticated user can create a hosts group from the configuration with XSS payload, which will be available for othe... |
| CVE-2022-23132 | HIGH | 7.3 | 0.8% | Jan 13, 2022 | During Zabbix installation from RPM, DAC_OVERRIDE SELinux capability is in use to access PID files in [/var/run/zabbix] ... |
| CVE-2022-23131 | CRITICAL | 9.8 | 95.7% | Jan 13, 2022 | In the case of instances where the SAML SSO authentication is enabled (non-default), session data can be modified by a m... |
| CVE-2022-22113 | HIGH | 8.8 | 1.0% | Jan 13, 2022 | In DayByDay CRM, versions 2.2.0 through 2.2.1 (latest) are vulnerable to Insufficient Session Expiration. When a passwor... |
| CVE-2022-22112 | MEDIUM | 5.4 | 0.6% | Jan 13, 2022 | In DayByDay CRM, versions 1.1 through 2.2.1 (latest) suffer from an application-wide Client-Side Template Injection (CST... |
| CVE-2022-0198 | HIGH | 7.1 | 0.7% | Jan 13, 2022 | corenlp is vulnerable to Improper Restriction of XML External Entity Reference |
| CVE-2022-0197 | HIGH | 8.8 | 0.8% | Jan 13, 2022 | phoronix-test-suite is vulnerable to Cross-Site Request Forgery (CSRF) |
| CVE-2022-0196 | HIGH | 8.8 | 0.7% | Jan 13, 2022 | phoronix-test-suite is vulnerable to Cross-Site Request Forgery (CSRF) |
| CVE-2022-23118 | HIGH | 8.8 | 1.6% | Jan 12, 2022 | Jenkins Debian Package Builder Plugin 1.6.11 and earlier implements functionality that allows agents to invoke command-l... |
| CVE-2022-23117 | HIGH | 7.5 | 1.3% | Jan 12, 2022 | Jenkins Conjur Secrets Plugin 1.0.9 and earlier implements functionality that allows attackers able to control agent pro... |
| CVE-2022-23116 | HIGH | 7.5 | 0.8% | Jan 12, 2022 | Jenkins Conjur Secrets Plugin 1.0.9 and earlier implements functionality that allows attackers able to control agent pro... |
| CVE-2022-23115 | MEDIUM | 5.4 | 0.6% | Jan 12, 2022 | Cross-site request forgery (CSRF) vulnerabilities in Jenkins batch task Plugin 1.19 and earlier allows attackers with Ov... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now