2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-42722 | MEDIUM | 5.5 | 0.6% | Oct 14, 2022 | In the Linux kernel 5.8 through 5.19.x before 5.19.16, local attackers able to inject WLAN frames into the mac80211 stac... |
| CVE-2022-42721 | MEDIUM | 5.5 | 0.6% | Oct 14, 2022 | A list management bug in BSS handling in the mac80211 stack in the Linux kernel 5.1 through 5.19.x before 5.19.16 could ... |
| CVE-2022-39302 | MEDIUM | 5.4 | 0.4% | Oct 14, 2022 | Ree6 is a moderation bot. This vulnerability would allow other server owners to create configurations such as "Better-Au... |
| CVE-2022-39295 | MEDIUM | 6.1 | 0.5% | Oct 13, 2022 | Knowage is an open source suite for modern business analytics alternative over big data systems. KnowageLabs / Knowage-S... |
| CVE-2022-39229 | MEDIUM | 4.3 | 0.8% | Oct 13, 2022 | Grafana is an open source data visualization platform for metrics, logs, and traces. Versions prior to 9.1.8 and 8.5.14 ... |
| CVE-2022-35612 | MEDIUM | 5.4 | 0.4% | Oct 13, 2022 | A cross-site scripting (XSS) vulnerability in MQTTRoute v3.3 and below allows attackers to execute arbitrary web scripts... |
| CVE-2022-35611 | MEDIUM | 4.3 | 0.3% | Oct 13, 2022 | A Cross-Site Request Forgery (CSRF) in MQTTRoute v3.3 and below allows attackers to create and remove dashboards. |
| CVE-2022-35136 | MEDIUM | 6.5 | 0.5% | Oct 13, 2022 | Boodskap IoT Platform v4.4.9-02 allows attackers to make unauthenticated API requests. |
| CVE-2022-35134 | MEDIUM | 5.4 | 0.4% | Oct 13, 2022 | Boodskap IoT Platform v4.4.9-02 contains a cross-site scripting (XSS) vulnerability. |
| CVE-2022-34021 | MEDIUM | 5.4 | 0.4% | Oct 13, 2022 | Multiple Cross Site Scripting (XSS) vulnerabilities in ResIOT IOT Platform + LoRaWAN Network Server through 4.1.1000114 ... |
| CVE-2022-42159 | MEDIUM | 4.3 | 0.6% | Oct 13, 2022 | D-Link COVR 1200,1202,1203 v1.08 was discovered to have a predictable seed in a Pseudo-Random Number Generator. |
| CVE-2022-3493 | MEDIUM | 5.4 | 0.3% | Oct 13, 2022 | A vulnerability, which was classified as problematic, has been found in SourceCodester Human Resource Management System ... |
| CVE-2022-41474 | MEDIUM | 6.5 | 0.3% | Oct 13, 2022 | RPCMS v3.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) which allows attackers to arbitrarily change ... |
| CVE-2022-41473 | MEDIUM | 6.1 | 1.0% | Oct 13, 2022 | RPCMS v3.0.2 was discovered to contain a reflected cross-site scripting (XSS) vulnerability in the Search function. |
| CVE-2022-38902 | MEDIUM | 5.4 | 0.7% | Oct 13, 2022 | A Cross-site scripting (XSS) vulnerability in the Blog module - add new topic functionality in Liferay Digital Experienc... |
| CVE-2022-35081 | MEDIUM | 5.5 | 0.3% | Oct 13, 2022 | SWFTools commit 772e55a2 was discovered to contain a heap-buffer overflow via png_read_header at /src/png2swf.c. |
| CVE-2022-35080 | MEDIUM | 5.5 | 0.3% | Oct 13, 2022 | SWFTools commit 772e55a2 was discovered to contain a heap-buffer overflow via png_load at /lib/png.c. |
| CVE-2022-2828 | MEDIUM | 6.5 | 0.5% | Oct 13, 2022 | In affected versions of Octopus Server it is possible to reveal information about teams via the API due to an Insecure D... |
| CVE-2022-3473 | MEDIUM | 6.5 | 0.5% | Oct 13, 2022 | A vulnerability classified as critical has been found in SourceCodester Human Resource Management System. This affects a... |
| CVE-2022-3472 | MEDIUM | 4.9 | 0.5% | Oct 13, 2022 | A vulnerability was found in SourceCodester Human Resource Management System. It has been rated as critical. Affected by... |
| CVE-2022-3471 | MEDIUM | 4.9 | 0.5% | Oct 13, 2022 | A vulnerability was found in SourceCodester Human Resource Management System. It has been declared as critical. Affected... |
| CVE-2022-3470 | MEDIUM | 6.5 | 0.5% | Oct 13, 2022 | A vulnerability was found in SourceCodester Human Resource Management System. It has been classified as critical. Affect... |
| CVE-2022-41316 | MEDIUM | 5.3 | 0.4% | Oct 12, 2022 | HashiCorp Vault and Vault Enterprise’s TLS certificate auth method did not initially load the optionally configured CRL ... |
| CVE-2022-41351 | MEDIUM | 6.1 | 0.4% | Oct 12, 2022 | In Zimbra Collaboration Suite (ZCS) 8.8.15, at the URL /h/calendar, one can trigger XSS by adding JavaScript code to the... |
| CVE-2022-41350 | MEDIUM | 6.1 | 0.4% | Oct 12, 2022 | In Zimbra Collaboration Suite (ZCS) 8.8.15, /h/search?action=voicemail&action=listen accepts a phone parameter that is v... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now