2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-4647 | MEDIUM | 6.1 | 0.5% | Dec 22, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 1.3.2. |
| CVE-2022-4646 | MEDIUM | 6.5 | 0.3% | Dec 22, 2022 | Cross-Site Request Forgery (CSRF) in GitHub repository ikus060/rdiffweb prior to 2.5.4. |
| CVE-2022-43271 | MEDIUM | 5.4 | 0.5% | Dec 22, 2022 | Inhabit Systems Pty Ltd Move CRM version 4, build 260 was discovered to contain a cross-site scripting (XSS) vulnerabili... |
| CVE-2022-4644 | MEDIUM | 6.1 | 0.6% | Dec 22, 2022 | Open Redirect in GitHub repository ikus060/rdiffweb prior to 2.5.4. |
| CVE-2022-3189 | MEDIUM | 5.3 | 0.5% | Dec 21, 2022 | Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where a specially crafted PHP script coul... |
| CVE-2022-3188 | MEDIUM | 5.3 | 0.5% | Dec 21, 2022 | Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where unauthenticated users could open PH... |
| CVE-2022-3187 | MEDIUM | 5.3 | 0.5% | Dec 21, 2022 | Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where certain PHP pages only validate whe... |
| CVE-2022-3185 | MEDIUM | 5.3 | 0.5% | Dec 21, 2022 | Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where the affected product exposes sensit... |
| CVE-2022-4642 | MEDIUM | 5.4 | 0.5% | Dec 21, 2022 | A vulnerability was found in tatoeba2. It has been classified as problematic. This affects an unknown part of the compon... |
| CVE-2022-4641 | MEDIUM | 5.5 | 0.2% | Dec 21, 2022 | A vulnerability was found in pig-vector and classified as problematic. Affected by this issue is the function LogisticRe... |
| CVE-2022-4640 | MEDIUM | 5.4 | 0.4% | Dec 21, 2022 | A vulnerability has been found in Mingsoft MCMS 5.2.9 and classified as problematic. Affected by this vulnerability is t... |
| CVE-2022-4638 | MEDIUM | 6.1 | 0.4% | Dec 21, 2022 | A vulnerability classified as problematic was found in collective.contact.widget up to 1.12. This vulnerability affects ... |
| CVE-2022-4637 | MEDIUM | 6.1 | 0.5% | Dec 21, 2022 | A vulnerability classified as problematic has been found in ep3-bs up to 1.7.x. This affects an unknown part. The manipu... |
| CVE-2022-23551 | MEDIUM | 5.3 | 0.7% | Dec 21, 2022 | aad-pod-identity assigns Azure Active Directory identities to Kubernetes applications and has now been deprecated as of ... |
| CVE-2022-4632 | MEDIUM | 6.1 | 0.5% | Dec 21, 2022 | A vulnerability has been found in Auto Upload Images up to 3.3.0 and classified as problematic. Affected by this vulnera... |
| CVE-2022-4631 | MEDIUM | 6.1 | 0.4% | Dec 21, 2022 | A vulnerability, which was classified as problematic, was found in WP-Ban. Affected is an unknown function of the file b... |
| CVE-2022-46096 | MEDIUM | 6.1 | 0.5% | Dec 21, 2022 | A Cross site scripting (XSS) vulnerability in Sourcecodester Online Covid-19 Directory on Vaccination System v1.0 allows... |
| CVE-2022-46095 | MEDIUM | 6.1 | 0.5% | Dec 21, 2022 | Sourcecodester Covid-19 Directory on Vaccination System 1.0 was discovered to contain a Cross-Site Scripting (XSS) vulne... |
| CVE-2022-36221 | MEDIUM | 6.5 | 0.8% | Dec 21, 2022 | Nokia Fastmile 3tg00118abad52 is affected by an authenticated path traversal vulnerability which allows attackers to rea... |
| CVE-2022-4630 | MEDIUM | 5.3 | 0.6% | Dec 21, 2022 | Sensitive Cookie Without 'HttpOnly' Flag in GitHub repository lirantal/daloradius prior to master. |
| CVE-2022-40841 | MEDIUM | 6.1 | 0.5% | Dec 21, 2022 | A cross-site scripting (XSS) vulnerability in NdkAdvancedCustomizationFields v3.5.0 allows attackers to execute arbitrar... |
| CVE-2022-44756 | MEDIUM | 6.5 | 0.4% | Dec 21, 2022 | Insights for Vulnerability Remediation (IVR) is vulnerable to improper input validation. This may lead to information d... |
| CVE-2022-42454 | MEDIUM | 5.3 | 0.2% | Dec 21, 2022 | Insights for Vulnerability Remediation (IVR) is vulnerable to man-in-the-middle attacks that may lead to information dis... |
| CVE-2022-38655 | MEDIUM | 5.8 | 0.4% | Dec 21, 2022 | BigFix WebUI non-master operators are missing controls that prevent them from being able to modify the relevance of fixl... |
| CVE-2022-46662 | MEDIUM | 6.7 | 0.4% | Dec 21, 2022 | Roxio Creator LJB starts another program with an unquoted file path. Since a registered Windows service path contains sp... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now