2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-38654 | MEDIUM | 5.5 | 0.2% | Nov 4, 2022 | HCL Domino is susceptible to an information disclosure vulnerability. In some scenarios, local calls made on the server... |
| CVE-2022-27894 | MEDIUM | 5.4 | 0.3% | Nov 4, 2022 | The Foundry Blobster service was found to have a cross-site scripting (XSS) vulnerability that could have allowed an att... |
| CVE-2022-20969 | MEDIUM | 5.4 | 0.4% | Nov 4, 2022 | A vulnerability in multiple management dashboard pages of Cisco Umbrella could allow an authenticated, remote attacker t... |
| CVE-2022-20963 | MEDIUM | 5.4 | 0.4% | Nov 4, 2022 | A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticat... |
| CVE-2022-20951 | MEDIUM | 6.5 | 1.9% | Nov 4, 2022 | A vulnerability in the web-based management interface of Cisco BroadWorks CommPilot application could allow an authentic... |
| CVE-2022-20942 | MEDIUM | 6.5 | 0.9% | Nov 4, 2022 | A vulnerability in the web-based management interface of Cisco Email Security Appliance (ESA), Cisco Secure Email and We... |
| CVE-2022-20937 | MEDIUM | 5.3 | 0.8% | Nov 4, 2022 | A vulnerability in a feature that monitors RADIUS requests on Cisco Identity Services Engine (ISE) Software could allow ... |
| CVE-2022-20867 | MEDIUM | 6.5 | 0.8% | Nov 4, 2022 | A vulnerability in web-based management interface of the of Cisco Email Security Appliance and Cisco Secure Email and We... |
| CVE-2022-20772 | MEDIUM | 5.3 | 0.5% | Nov 4, 2022 | A vulnerability in Cisco Email Security Appliance (ESA) and Cisco Secure Email and Web Manager could allow an unauthenti... |
| CVE-2022-27893 | MEDIUM | 4.2 | 0.2% | Nov 4, 2022 | The Foundry Magritte plugin osisoft-pi-web-connector versions 0.15.0 - 0.43.0 was found to be logging in a manner that c... |
| CVE-2022-3721 | MEDIUM | 4.6 | 0.8% | Nov 4, 2022 | Code Injection in GitHub repository froxlor/froxlor prior to 0.10.39. |
| CVE-2022-38582 | MEDIUM | 6.5 | 0.6% | Nov 4, 2022 | Incorrect access control in the anti-virus driver wsdkd.sys of Watchdog Antivirus v1.4.158 allows attackers to write arb... |
| CVE-2022-44724 | MEDIUM | 5.4 | 0.7% | Nov 4, 2022 | The Handy Tip macro in Stiltsoft Handy Macros for Confluence Server/Data Center 3.x before 3.5.5 allows remote attackers... |
| CVE-2022-43561 | MEDIUM | 4.8 | 0.6% | Nov 3, 2022 | In Splunk Enterprise versions below 8.1.12, 8.2.9, and 9.0.2, a remote user that holds the “power” Splunk role can store... |
| CVE-2022-44628 | MEDIUM | 4.8 | 0.4% | Nov 3, 2022 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in JumpDEMAND Inc. 4ECPS Web Forms plugin <= 0.2.17 on Wo... |
| CVE-2022-44627 | MEDIUM | 5.4 | 0.2% | Nov 3, 2022 | Cross-Site Request Forgery (CSRF) vulnerability in David Cole Simple SEO plugin <= 1.8.12 on WordPress allows attackers ... |
| CVE-2022-43451 | MEDIUM | 6.5 | 0.2% | Nov 3, 2022 | OpenHarmony-v3.1.2 and prior versions had an Multiple path traversal vulnerability in appspawn and nwebspawn services. L... |
| CVE-2022-43449 | MEDIUM | 5.5 | 0.2% | Nov 3, 2022 | OpenHarmony-v3.1.2 and prior versions had an Arbitrary file read vulnerability via download_server. Local attackers can ... |
| CVE-2022-42749 | MEDIUM | 6.1 | 1.1% | Nov 3, 2022 | CandidATS version 3.0.0 on 'page' of the 'ajax.php' resource, allows an external attacker to steal the cookie of arbitra... |
| CVE-2022-42748 | MEDIUM | 6.1 | 1.1% | Nov 3, 2022 | CandidATS version 3.0.0 on 'sortDirection' of the 'ajax.php' resource, allows an external attacker to steal the cookie o... |
| CVE-2022-42747 | MEDIUM | 6.1 | 1.1% | Nov 3, 2022 | CandidATS version 3.0.0 on 'sortBy' of the 'ajax.php' resource, allows an external attacker to steal the cookie of arbit... |
| CVE-2022-42746 | MEDIUM | 6.1 | 1.1% | Nov 3, 2022 | CandidATS version 3.0.0 on 'indexFile' of the 'ajax.php' resource, allows an external attacker to steal the cookie of ar... |
| CVE-2022-42743 | MEDIUM | 5.3 | 0.6% | Nov 3, 2022 | deep-parse-json version 1.0.2 allows an external attacker to edit or add new properties to an object. This is possible b... |
| CVE-2022-41714 | MEDIUM | 5.3 | 0.6% | Nov 3, 2022 | fastest-json-copy version 1.0.1 allows an external attacker to edit or add new properties to an object. This is possible... |
| CVE-2022-41713 | MEDIUM | 5.3 | 0.6% | Nov 3, 2022 | deep-object-diff version 1.1.0 allows an external attacker to edit or add new properties to an object. This is possible ... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now