2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-41949 | MEDIUM | 4.3 | 0.4% | Dec 8, 2022 | DHIS 2 is an open source information system for data capture, management, validation, analytics and visualization. In af... |
| CVE-2022-23494 | MEDIUM | 6.1 | 0.9% | Dec 8, 2022 | tinymce is an open source rich text editor. A cross-site scripting (XSS) vulnerability was discovered in the alert and c... |
| CVE-2022-23469 | MEDIUM | 6.5 | 1.0% | Dec 8, 2022 | Traefik is an open source HTTP reverse proxy and load balancer. Versions prior to 2.9.6 are subject to a potential vulne... |
| CVE-2022-41717 | MEDIUM | 5.3 | 5.6% | Dec 8, 2022 | An attacker can cause excessive memory growth in a Go server accepting HTTP/2 requests. HTTP/2 server connections contai... |
| CVE-2022-46831 | MEDIUM | 4.9 | 0.4% | Dec 8, 2022 | In JetBrains TeamCity between 2022.10 and 2022.10.1 connecting to AWS using the "Default Credential Provider Chain" allo... |
| CVE-2022-46830 | MEDIUM | 5.3 | 0.5% | Dec 8, 2022 | In JetBrains TeamCity between 2022.10 and 2022.10.1 a custom STS endpoint allowed internal port scanning. |
| CVE-2022-46827 | MEDIUM | 5.5 | 0.2% | Dec 8, 2022 | In JetBrains IntelliJ IDEA before 2022.3 an XXE attack leading to SSRF via requests to custom plugin repositories was po... |
| CVE-2022-46826 | MEDIUM | 5.5 | 0.2% | Dec 8, 2022 | In JetBrains IntelliJ IDEA before 2022.3 the built-in web server allowed an arbitrary file to be read by exploiting a pa... |
| CVE-2022-40939 | MEDIUM | 4.9 | 0.4% | Dec 8, 2022 | In certain Secustation products the administrator account password can be read. This affects V2.5.5.3116-S50-SMA-B201711... |
| CVE-2022-38599 | MEDIUM | 6.5 | 0.8% | Dec 8, 2022 | Teleport v3.2.2, Teleport v3.5.6-rc6, and Teleport v3.6.3-b2 was discovered to contain an information leak via the /user... |
| CVE-2022-4122 | MEDIUM | 5.3 | 0.8% | Dec 8, 2022 | A vulnerability was found in buildah. Incorrect following of symlinks while reading .containerignore and .dockerignore r... |
| CVE-2022-45877 | MEDIUM | 5.3 | 0.2% | Dec 8, 2022 | OpenHarmony-v3.1.4 and prior versions had an vulnerability. PIN code is transmitted to the peer device in plain text dur... |
| CVE-2022-45118 | MEDIUM | 5.5 | 0.2% | Dec 8, 2022 | OpenHarmony-v3.1.2 and prior versions had a vulnerability that telephony in communication subsystem sends public events ... |
| CVE-2022-3260 | MEDIUM | 4.8 | 0.4% | Dec 8, 2022 | The response header has not enabled X-FRAME-OPTIONS, Which helps prevents against Clickjacking attack.. Some browsers wo... |
| CVE-2022-39915 | MEDIUM | 5.5 | 0.3% | Dec 8, 2022 | Improper access control vulnerability in Calendar prior to versions 11.6.08.0 in Android Q(10), 12.2.11.3000 in Android ... |
| CVE-2022-39911 | MEDIUM | 6.8 | 0.2% | Dec 8, 2022 | Improper check or handling of exceptional conditions vulnerability in Samsung Pass prior to version 4.0.06.1 allows atta... |
| CVE-2022-39910 | MEDIUM | 4.2 | 0.3% | Dec 8, 2022 | Improper access control vulnerability in Samsung Pass prior to version 4.0.06.7 allow physical attackers to access data ... |
| CVE-2022-39909 | MEDIUM | 5.5 | 0.1% | Dec 8, 2022 | Insufficient verification of data authenticity vulnerability in Samsung Gear IconX PC Manager prior to version 2.1.22101... |
| CVE-2022-39905 | MEDIUM | 5.5 | 0.1% | Dec 8, 2022 | Implicit intent hijacking vulnerability in Telecom application prior to SMR Dec-2022 Release 1 allows attacker to access... |
| CVE-2022-39901 | MEDIUM | 6.5 | 0.2% | Dec 8, 2022 | Improper authentication in Exynos baseband prior to SMR DEC-2022 Release 1 allows remote attacker to disable the network... |
| CVE-2022-39900 | MEDIUM | 4.6 | 0.1% | Dec 8, 2022 | Improper access control vulnerability in Nice Catch prior to SMR Dec-2022 Release 1 allows physical attackers to access ... |
| CVE-2022-39899 | MEDIUM | 4.3 | 0.1% | Dec 8, 2022 | Improper authentication vulnerability in Samsung WindowManagerService prior to SMR Dec-2022 Release 1 allows attacker to... |
| CVE-2022-39897 | MEDIUM | 5.5 | 0.1% | Dec 8, 2022 | Exposure of Sensitive Information vulnerability in kernel prior to SMR Dec-2022 Release 1 allows attackers to access the... |
| CVE-2022-38754 | MEDIUM | 5.4 | 0.6% | Dec 8, 2022 | A potential vulnerability has been identified in Micro Focus Operations Bridge - Containerized. The vulnerability could ... |
| CVE-2022-4353 | MEDIUM | 5.4 | 0.4% | Dec 8, 2022 | A vulnerability has been found in LinZhaoguan pb-cms 2.0 and classified as problematic. Affected by this vulnerability i... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now