2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-37313 | MEDIUM | 5.3 | 0.7% | Dec 26, 2022 | OX App Suite through 7.10.6 allows SSRF because the anti-SSRF protection mechanism only checks the first DNS AA or AAAA ... |
| CVE-2022-37312 | MEDIUM | 5.3 | 0.9% | Dec 26, 2022 | OX App Suite through 7.10.6 has Uncontrolled Resource Consumption via a large request body containing a redirect URL to ... |
| CVE-2022-37311 | MEDIUM | 5.3 | 0.9% | Dec 26, 2022 | OX App Suite through 7.10.6 has Uncontrolled Resource Consumption via a large location request parameter to the redirect... |
| CVE-2022-37307 | MEDIUM | 6.1 | 0.5% | Dec 26, 2022 | OX App Suite through 7.10.6 allows XSS via XHTML CDATA for a snippet, as demonstrated by the onerror attribute of an IMG... |
| CVE-2022-31469 | MEDIUM | 6.1 | 0.5% | Dec 26, 2022 | OX App Suite through 7.10.6 allows XSS via a deep link, as demonstrated by class="deep-link-app" for a /#!!&app=%2e./ UR... |
| CVE-2022-4741 | MEDIUM | 6.5 | 0.8% | Dec 25, 2022 | A vulnerability was found in docconv up to 1.2.0 and classified as problematic. This issue affects the function ConvertD... |
| CVE-2022-4740 | MEDIUM | 6.1 | 0.5% | Dec 25, 2022 | A vulnerability, which was classified as problematic, has been found in kkFileView. Affected by this issue is the functi... |
| CVE-2022-4738 | MEDIUM | 6.1 | 0.4% | Dec 25, 2022 | A vulnerability classified as problematic has been found in SourceCodester Blood Bank Management System 1.0. Affected is... |
| CVE-2022-4736 | MEDIUM | 6.1 | 0.5% | Dec 25, 2022 | A vulnerability was found in Venganzas del Pasado and classified as problematic. Affected by this issue is some unknown ... |
| CVE-2022-41317 | MEDIUM | 6.5 | 1.7% | Dec 25, 2022 | An issue was discovered in Squid 4.9 through 4.17 and 5.0.6 through 5.6. Due to inconsistent handling of internal URIs, ... |
| CVE-2022-4735 | MEDIUM | 6.1 | 0.5% | Dec 25, 2022 | A vulnerability classified as problematic was found in asrashley dash-live. This vulnerability affects the function read... |
| CVE-2022-4731 | MEDIUM | 5.4 | 0.5% | Dec 25, 2022 | A vulnerability, which was classified as problematic, was found in myapnea up to 29.0.x. Affected is an unknown function... |
| CVE-2022-45895 | MEDIUM | 6.5 | 0.7% | Dec 25, 2022 | Planet eStream before 6.72.10.07 discloses sensitive information, related to the ON cookie (findable in HTML source code... |
| CVE-2022-45894 | MEDIUM | 6.5 | 1.0% | Dec 25, 2022 | GetFile.aspx in Planet eStream before 6.72.10.07 allows ..\ directory traversal to read arbitrary local files. |
| CVE-2022-44381 | MEDIUM | 5.3 | 0.6% | Dec 25, 2022 | Snipe-IT through 6.0.14 allows attackers to check whether a user account exists because of response variations in a /pas... |
| CVE-2022-44380 | MEDIUM | 5.4 | 0.5% | Dec 25, 2022 | Snipe-IT before 6.0.14 is vulnerable to Cross Site Scripting (XSS) for View Assigned Assets. |
| CVE-2022-44014 | MEDIUM | 6.5 | 0.7% | Dec 25, 2022 | An issue was discovered in Simmeth Lieferantenmanager before 5.6. In the design of the API, a user is inherently able to... |
| CVE-2022-44012 | MEDIUM | 5.4 | 0.5% | Dec 25, 2022 | An issue was discovered in /DS/LM_API/api/SelectionService/InsertQueryWithActiveRelationsReturnId in Simmeth Lieferanten... |
| CVE-2022-45892 | MEDIUM | 5.4 | 0.4% | Dec 25, 2022 | In Planet eStream before 6.72.10.07, multiple Stored Cross-Site Scripting (XSS) vulnerabilities exist: Disclaimer, Searc... |
| CVE-2022-45890 | MEDIUM | 6.1 | 0.5% | Dec 25, 2022 | In Planet eStream before 6.72.10.07, a Reflected Cross-Site Scripting (XSS) vulnerability exists via any metadata filter... |
| CVE-2022-47934 | MEDIUM | 6.5 | 1.0% | Dec 24, 2022 | Brave Browser before 1.43.88 allowed a remote attacker to cause a denial of service in private and guest windows via a c... |
| CVE-2022-47933 | MEDIUM | 6.5 | 0.8% | Dec 24, 2022 | Brave Browser before 1.42.51 allowed a remote attacker to cause a denial of service via a crafted HTML file that referen... |
| CVE-2022-47932 | MEDIUM | 6.5 | 1.0% | Dec 24, 2022 | Brave Browser before 1.43.34 allowed a remote attacker to cause a denial of service via a crafted HTML file that mention... |
| CVE-2022-43860 | MEDIUM | 4.3 | 0.5% | Dec 24, 2022 | IBM Navigator for i 7.3, 7.4, and 7.5 could allow an authenticated user to obtain sensitive information they are authori... |
| CVE-2022-22449 | MEDIUM | 5.3 | 0.7% | Dec 24, 2022 | IBM Security Verify Governance, Identity Manager 10.01 could allow a remote attacker to obtain sensitive information whe... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now