2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-23549 | MEDIUM | 6.5 | 0.6% | Jan 5, 2023 | Discourse is an option source discussion platform. Prior to version 2.8.14 on the `stable` branch and version 2.9.0.beta... |
| CVE-2022-23548 | MEDIUM | 6.5 | 0.7% | Jan 5, 2023 | Discourse is an option source discussion platform. Prior to version 2.8.14 on the `stable` branch and version 2.9.0.beta... |
| CVE-2022-23546 | MEDIUM | 5.5 | 0.3% | Jan 5, 2023 | In version 2.9.0.beta14 of Discourse, an open-source discussion platform, maliciously embedded urls can leak an admin's ... |
| CVE-2022-4435 | MEDIUM | 4.4 | 0.2% | Jan 5, 2023 | A buffer over-read vulnerability was reported in the ThinkPadX13s BIOS LenovoRemoteConfigUpdateDxe driver that could all... |
| CVE-2022-4434 | MEDIUM | 4.4 | 0.2% | Jan 5, 2023 | A buffer over-read vulnerability was reported in the ThinkPadX13s BIOS driver that could allow a local attacker with ele... |
| CVE-2022-4433 | MEDIUM | 4.4 | 0.2% | Jan 5, 2023 | A buffer over-read vulnerability was reported in the ThinkPadX13s BIOS LenovoSetupConfigDxe driver that could allow a lo... |
| CVE-2022-4432 | MEDIUM | 4.4 | 0.2% | Jan 5, 2023 | A buffer over-read vulnerability was reported in the ThinkPadX13s BIOS PersistenceConfigDxe driver that could allow a lo... |
| CVE-2022-43573 | MEDIUM | 5.3 | 0.5% | Jan 5, 2023 | IBM Robotic Process Automation 20.12 through 21.0.6 is vulnerable to exposure of the name and email for the creator/modi... |
| CVE-2022-41740 | MEDIUM | 4.6 | 0.2% | Jan 5, 2023 | IBM Robotic Process Automation 20.12 through 21.0.6 could allow an attacker with physical access to the system to obtai... |
| CVE-2022-47662 | MEDIUM | 5.5 | 0.3% | Jan 5, 2023 | GPAC MP4Box 2.1-DEV-rev649-ga8f438d20 has a segment fault (/stack overflow) due to infinite recursion in Media_GetSample... |
| CVE-2022-47086 | MEDIUM | 5.5 | 0.3% | Jan 5, 2023 | GPAC MP4Box v2.1-DEV-rev574-g9d5bb184b contains a segmentation violation via the function gf_sm_load_init_swf at scene_m... |
| CVE-2022-46490 | MEDIUM | 5.5 | 0.3% | Jan 5, 2023 | GPAC version 2.1-DEV-rev505-gb9577e6ad-master was discovered to contain a memory leak via the afrt_box_read function at ... |
| CVE-2022-46489 | MEDIUM | 5.5 | 0.3% | Jan 5, 2023 | GPAC version 2.1-DEV-rev505-gb9577e6ad-master was discovered to contain a memory leak via the gf_isom_box_parse_ex funct... |
| CVE-2022-4877 | MEDIUM | 6.1 | 0.5% | Jan 5, 2023 | A vulnerability has been found in snoyberg keter up to 1.8.1 and classified as problematic. This vulnerability affects u... |
| CVE-2022-43540 | MEDIUM | 5.5 | 0.2% | Jan 5, 2023 | A vulnerability exists in the ClearPass OnGuard macOS agent that allows for an attacker with local macOS instance access... |
| CVE-2022-43539 | MEDIUM | 4.5 | 0.3% | Jan 5, 2023 | A vulnerability exists in the ClearPass Policy Manager cluster communications that allow for an attacker in a privilege... |
| CVE-2022-43532 | MEDIUM | 4.8 | 0.4% | Jan 5, 2023 | A vulnerability in the web-based management interface of ClearPass Policy Manager could allow an authenticated remote a... |
| CVE-2022-43529 | MEDIUM | 5.4 | 0.4% | Jan 5, 2023 | A vulnerability in the web-based management interface of Aruba EdgeConnect Enterprise Orchestrator could allow an remote... |
| CVE-2022-43528 | MEDIUM | 6.5 | 0.4% | Jan 5, 2023 | Under certain configurations, an attacker can login to Aruba EdgeConnect Enterprise Orchestrator without supplying a mul... |
| CVE-2022-43527 | MEDIUM | 6.1 | 0.5% | Jan 5, 2023 | Multiple vulnerabilities within the web-based management interface of Aruba EdgeConnect Enterprise Orchestrator could al... |
| CVE-2022-43526 | MEDIUM | 6.1 | 0.5% | Jan 5, 2023 | Multiple vulnerabilities within the web-based management interface of Aruba EdgeConnect Enterprise Orchestrator could al... |
| CVE-2022-43525 | MEDIUM | 6.1 | 0.5% | Jan 5, 2023 | Multiple vulnerabilities within the web-based management interface of Aruba EdgeConnect Enterprise Orchestrator could al... |
| CVE-2022-43524 | MEDIUM | 5.4 | 0.5% | Jan 5, 2023 | A vulnerability in the web-based management interface of Aruba EdgeConnect Enterprise Orchestrator could allow an authen... |
| CVE-2022-34330 | MEDIUM | 6.1 | 0.4% | Jan 5, 2023 | IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.1 is vulnerable to cross-site scripting. This vulnera... |
| CVE-2022-22371 | MEDIUM | 6.5 | 0.3% | Jan 5, 2023 | IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.1 does not invalidate session after a password change... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now