2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-44952 | MEDIUM | 5.4 | 0.9% | Dec 2, 2022 | Rukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in /index.php?module=conf... |
| CVE-2022-44951 | MEDIUM | 5.4 | 0.9% | Dec 2, 2022 | Rukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Add New Form tab f... |
| CVE-2022-44950 | MEDIUM | 5.4 | 0.9% | Dec 2, 2022 | Rukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Add New Field func... |
| CVE-2022-44949 | MEDIUM | 5.4 | 0.9% | Dec 2, 2022 | Rukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Add New Field func... |
| CVE-2022-44948 | MEDIUM | 5.4 | 0.9% | Dec 2, 2022 | Rukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Entities Group fea... |
| CVE-2022-44947 | MEDIUM | 5.4 | 1.0% | Dec 2, 2022 | Rukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Highlight Row feat... |
| CVE-2022-44946 | MEDIUM | 5.4 | 1.0% | Dec 2, 2022 | Rukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Add Page function ... |
| CVE-2022-44944 | MEDIUM | 5.4 | 1.0% | Dec 2, 2022 | Rukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Add Announcement f... |
| CVE-2022-45668 | MEDIUM | 6.5 | 0.3% | Dec 2, 2022 | Tenda i22 V1.0.0.3(4687) is vulnerable to Cross Site Request Forgery (CSRF) via function fromSysToolReboot. |
| CVE-2022-45667 | MEDIUM | 6.5 | 0.3% | Dec 2, 2022 | Tenda i22 V1.0.0.3(4687) is vulnerable to Cross Site Request Forgery (CSRF) via function fromSysToolRestoreSet. |
| CVE-2022-45674 | MEDIUM | 6.5 | 0.3% | Dec 2, 2022 | Tenda AC6V1.0 V15.03.05.19 is vulnerable to Cross Site Request Forgery (CSRF) via function fromSysToolReboot. |
| CVE-2022-45673 | MEDIUM | 6.5 | 0.3% | Dec 2, 2022 | Tenda AC6V1.0 V15.03.05.19 is vulnerable to Cross Site Request Forgery (CSRF) via function fromSysToolRestoreSet. |
| CVE-2022-4271 | MEDIUM | 5.4 | 0.7% | Dec 2, 2022 | Cross-site Scripting (XSS) - Reflected in GitHub repository osticket/osticket prior to 1.16.4. |
| CVE-2022-45483 | MEDIUM | 5.9 | 0.4% | Dec 2, 2022 | Lazy Mouse allows an attacker (in a man in the middle position between the server and a connected device) to see all dat... |
| CVE-2022-45480 | MEDIUM | 5.9 | 0.4% | Dec 2, 2022 | PC Keyboard WiFi & Bluetooth allows an attacker (in a man-in-the-middle position between the server and a connected devi... |
| CVE-2022-46159 | MEDIUM | 4.3 | 0.6% | Dec 2, 2022 | Discourse is an open-source discussion platform. In version 2.8.13 and prior on the `stable` branch and version 2.9.0.be... |
| CVE-2022-45215 | MEDIUM | 5.4 | 0.4% | Dec 2, 2022 | A cross-site scripting (XSS) vulnerability in Book Store Management System v1.0.0 allows attackers to execute arbitrary ... |
| CVE-2022-44212 | MEDIUM | 5.9 | 0.6% | Dec 1, 2022 | In GL.iNet Goodcloud 1.0, insecure design allows remote attacker to access devices' admin panel. |
| CVE-2022-41971 | MEDIUM | 6.5 | 0.8% | Dec 1, 2022 | Nextcould Talk android is a video and audio conferencing app for Nextcloud. Prior to versions 12.2.8, 13.0.10, 14.0.6, a... |
| CVE-2022-41970 | MEDIUM | 5.3 | 0.6% | Dec 1, 2022 | Nextcloud Server is an open source personal cloud server. Prior to versions 24.0.7 and 25.0.1, disabled download shares ... |
| CVE-2022-41968 | MEDIUM | 5.3 | 0.8% | Dec 1, 2022 | Nextcloud Server is an open source personal cloud server. Prior to versions 23.0.10 and 24.0.5, calendar name lengths ar... |
| CVE-2022-23737 | MEDIUM | 6.5 | 0.7% | Dec 1, 2022 | An improper privilege management vulnerability was identified in GitHub Enterprise Server that allowed users with improp... |
| CVE-2022-43901 | MEDIUM | 5.5 | 0.2% | Dec 1, 2022 | IBM WebSphere Automation for IBM Cloud Pak for Watson AIOps 1.4.3 could disclose sensitive information. An authenticate... |
| CVE-2022-43900 | MEDIUM | 6.5 | 0.2% | Dec 1, 2022 | IBM WebSphere Automation for IBM Cloud Pak for Watson AIOps 1.4.2 could provide a weaker than expected security. A loca... |
| CVE-2022-41297 | MEDIUM | 6.5 | 0.2% | Dec 1, 2022 | IBM Db2U 3.5, 4.0, and 4.5 is vulnerable to cross-site request forgery which could allow an attacker to execute maliciou... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now