2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-45150 | MEDIUM | 6.1 | 0.7% | Nov 23, 2022 | A reflected cross-site scripting vulnerability was discovered in Moodle. This flaw exists due to insufficient sanitizati... |
| CVE-2022-45149 | MEDIUM | 5.4 | 0.4% | Nov 23, 2022 | A vulnerability was found in Moodle which exists due to insufficient validation of the HTTP request origin in course red... |
| CVE-2022-42895 | MEDIUM | 6.5 | 0.4% | Nov 23, 2022 | There is an infoleak vulnerability in the Linux kernel's net/bluetooth/l2cap_core.c's l2cap_parse_conf_req function whic... |
| CVE-2022-4045 | MEDIUM | 6.5 | 0.6% | Nov 23, 2022 | A denial-of-service vulnerability in the Mattermost allows an authenticated user to crash the server via multiple reques... |
| CVE-2022-4044 | MEDIUM | 6.5 | 1.1% | Nov 23, 2022 | A denial-of-service vulnerability in Mattermost allows an authenticated user to crash the server via multiple large auto... |
| CVE-2022-4019 | MEDIUM | 6.5 | 0.7% | Nov 23, 2022 | A denial-of-service vulnerability in the Mattermost Playbooks plugin allows an authenticated user to crash the server vi... |
| CVE-2022-45472 | MEDIUM | 5.4 | 0.5% | Nov 23, 2022 | CAE LearningSpace Enterprise (with Intuity License) image 267r patch 639 allows DOM XSS, related to ontouchmove and onpo... |
| CVE-2022-41446 | MEDIUM | 5.4 | 1.1% | Nov 23, 2022 | An access control issue in /Admin/dashboard.php of Record Management System using CodeIgniter v1.0 allows attackers to a... |
| CVE-2022-38147 | MEDIUM | 5.4 | 0.5% | Nov 23, 2022 | Silverstripe silverstripe/framework through 4.11 allows XSS (issue 3 of 3). |
| CVE-2022-37421 | MEDIUM | 5.4 | 0.5% | Nov 23, 2022 | Silverstripe silverstripe/cms through 4.11.0 allows XSS. |
| CVE-2022-42095 | MEDIUM | 4.8 | 1.9% | Nov 23, 2022 | Backdrop CMS version 1.23.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Page con... |
| CVE-2022-38145 | MEDIUM | 5.4 | 0.6% | Nov 23, 2022 | Silverstripe silverstripe/framework through 4.11 allows XSS (issue 1 of 3) via remote attackers adding a Javascript payl... |
| CVE-2022-37430 | MEDIUM | 5.4 | 0.5% | Nov 23, 2022 | Silverstripe silverstripe/framework through 4.11 allows XSS vulnerability via href attribute of a link (issue 2 of 2). |
| CVE-2022-37429 | MEDIUM | 5.4 | 0.5% | Nov 23, 2022 | Silverstripe silverstripe/framework through 4.11 allows XSS (issue 1 of 2) via JavaScript payload to the href attribute ... |
| CVE-2022-35500 | MEDIUM | 5.4 | 0.5% | Nov 23, 2022 | Amasty Blog 2.10.3 is vulnerable to Cross Site Scripting (XSS) via leave comment functionality. |
| CVE-2022-38724 | MEDIUM | 5.4 | 0.7% | Nov 23, 2022 | Silverstripe silverstripe/framework through 4.11.0, silverstripe/assets through 1.11.0, and silverstripe/asset-admin thr... |
| CVE-2022-37774 | MEDIUM | 5.3 | 0.5% | Nov 23, 2022 | There is a broken access control vulnerability in the Maarch RM 2.8.3 solution. When accessing some specific document (p... |
| CVE-2022-37773 | MEDIUM | 6.5 | 0.8% | Nov 23, 2022 | An authenticated SQL Injection vulnerability in the statistics page (/statistics/retrieve) of Maarch RM 2.8, via the fil... |
| CVE-2022-45536 | MEDIUM | 4.9 | 0.8% | Nov 22, 2022 | AeroCMS v0.0.1 was discovered to contain a SQL Injection vulnerability via the id parameter at \admin\post_comments.php.... |
| CVE-2022-45535 | MEDIUM | 4.9 | 0.8% | Nov 22, 2022 | AeroCMS v0.0.1 was discovered to contain a SQL Injection vulnerability via the edit parameter at \admin\categories.php. ... |
| CVE-2022-45529 | MEDIUM | 4.9 | 0.7% | Nov 22, 2022 | AeroCMS v0.0.1 was discovered to contain a SQL Injection vulnerability via the post_category_id parameter at \admin\incl... |
| CVE-2022-39397 | MEDIUM | 4.3 | 0.4% | Nov 22, 2022 | aliyun-oss-client is a rust client for Alibaba Cloud OSS. Users of this library will be affected, the incoming secret wi... |
| CVE-2022-39199 | MEDIUM | 5.9 | 0.3% | Nov 22, 2022 | immudb is a database with built-in cryptographic proof and verification. immudb client SDKs use server's UUID to disting... |
| CVE-2022-40228 | MEDIUM | 5.4 | 0.3% | Nov 22, 2022 | IBM DataPower Gateway 10.0.3.0 through 10.0.4.0, 10.0.1.0 through 10.0.1.9, 2018.4.1.0 through 2018.4.1.22, and 10.5.... |
| CVE-2022-3500 | MEDIUM | 5.1 | 0.2% | Nov 22, 2022 | A vulnerability was found in keylime. This security issue happens in some circumstances, due to some improperly handled ... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now