2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-2882 | MEDIUM | 4.3 | 0.7% | Oct 28, 2022 | An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.6 before 15.2.5, all versions start... |
| CVE-2022-26884 | MEDIUM | 6.5 | 1.5% | Oct 28, 2022 | Users can read any files by log server, Apache DolphinScheduler users should upgrade to version 2.0.6 or higher. |
| CVE-2022-41702 | MEDIUM | 5.4 | 11.1% | Oct 27, 2022 | The affected product DIAEnergie (versions prior to v1.9.01.002) is vulnerable to a stored cross-site scripting vulnerabi... |
| CVE-2022-41701 | MEDIUM | 5.4 | 11.1% | Oct 27, 2022 | The affected product DIAEnergie (versions prior to v1.9.01.002) is vulnerable to a stored cross-site scripting vulnerabi... |
| CVE-2022-41651 | MEDIUM | 5.4 | 11.1% | Oct 27, 2022 | The affected product DIAEnergie (versions prior to v1.9.01.002) is vulnerable to a stored cross-site scripting vulnerabi... |
| CVE-2022-41555 | MEDIUM | 5.4 | 11.1% | Oct 27, 2022 | The affected product DIAEnergie (versions prior to v1.9.01.002) is vulnerable to a stored cross-site scripting vulnerabi... |
| CVE-2022-40965 | MEDIUM | 5.4 | 11.1% | Oct 27, 2022 | The affected product DIAEnergie (versions prior to v1.9.01.002) is vulnerable to a stored cross-site scripting vulnerabi... |
| CVE-2022-3387 | MEDIUM | 5.3 | 14.0% | Oct 27, 2022 | Advantech R-SeeNet Versions 2.4.19 and prior are vulnerable to path traversal attacks. An unauthorized attacker could r... |
| CVE-2022-0072 | MEDIUM | 5.8 | 1.0% | Oct 27, 2022 | Directory Traversal vulnerability in LiteSpeed Technologies OpenLiteSpeed Web Server and LiteSpeed Web Server dashboards... |
| CVE-2022-32407 | MEDIUM | 6.1 | 0.5% | Oct 27, 2022 | Softr v2.0 was discovered to contain a Cross-Site Scripting (XSS) vulnerability via the First Name parameter under the C... |
| CVE-2022-42055 | MEDIUM | 6.5 | 1.7% | Oct 27, 2022 | Multiple command injection vulnerabilities in GL.iNet GoodCloud IoT Device Management System Version 1.00.220412.00 via ... |
| CVE-2022-42054 | MEDIUM | 5.4 | 0.5% | Oct 27, 2022 | Multiple stored cross-site scripting (XSS) vulnerabilities in GL.iNet GoodCloud IoT Device Management System Version 1.0... |
| CVE-2022-31898 | MEDIUM | 6.8 | 15.9% | Oct 27, 2022 | gl-inet GL-MT300N-V2 Mango v3.212 and GL-AX1800 Flint v3.214 were discovered to contain multiple command injection vulne... |
| CVE-2022-40184 | MEDIUM | 4.8 | 0.3% | Oct 27, 2022 | Incomplete filtering of JavaScript code in different configuration fields of the web based interface of the VIDEOJET mul... |
| CVE-2022-40183 | MEDIUM | 4.7 | 0.3% | Oct 27, 2022 | An error in the URL handler of the VIDEOJET multi 4000 may lead to a reflected cross site scripting (XSS) in the web-bas... |
| CVE-2022-24670 | MEDIUM | 6.5 | 0.5% | Oct 27, 2022 | An attacker can use the unrestricted LDAP queries to determine configuration entries |
| CVE-2022-24669 | MEDIUM | 6.5 | 0.4% | Oct 27, 2022 | It may be possible to gain some details of the deployment through a well-crafted attack. This may allow that data to be ... |
| CVE-2022-39364 | MEDIUM | 6.5 | 0.5% | Oct 27, 2022 | Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform. In Nextcloud Server pri... |
| CVE-2022-42993 | MEDIUM | 5.4 | 0.6% | Oct 27, 2022 | Password Storage Application v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Setup pag... |
| CVE-2022-42991 | MEDIUM | 5.4 | 0.6% | Oct 27, 2022 | A stored cross-site scripting (XSS) vulnerability in Simple Online Public Access Catalog v1.0 allows attackers to execut... |
| CVE-2022-39330 | MEDIUM | 4.3 | 0.8% | Oct 27, 2022 | Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform. Nextcloud Server prior ... |
| CVE-2022-39329 | MEDIUM | 5.3 | 0.6% | Oct 27, 2022 | Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform. Nextcloud Server and Ne... |
| CVE-2022-36182 | MEDIUM | 6.1 | 0.5% | Oct 27, 2022 | Hashicorp Boundary v0.8.0 is vulnerable to Clickjacking which allow for the interception of login credentials, re-direct... |
| CVE-2022-42992 | MEDIUM | 5.4 | 0.6% | Oct 27, 2022 | Multiple stored cross-site scripting (XSS) vulnerabilities in Train Scheduler App v1.0 allow attackers to execute arbitr... |
| CVE-2022-3716 | MEDIUM | 5.4 | 0.3% | Oct 27, 2022 | A vulnerability classified as problematic was found in SourceCodester Online Medicine Ordering System 1.0. Affected by t... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now