2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-41349 | MEDIUM | 6.1 | 0.4% | Oct 12, 2022 | In Zimbra Collaboration Suite (ZCS) 8.8.15, the URL at /h/compose accepts an attachUrl parameter that is vulnerable to R... |
| CVE-2022-41348 | MEDIUM | 6.1 | 0.4% | Oct 12, 2022 | An issue was discovered in Zimbra Collaboration (ZCS) 9.0. XSS can occur via the onerror attribute of an IMG element, le... |
| CVE-2022-33918 | MEDIUM | 5.5 | 0.1% | Oct 12, 2022 | Dell GeoDrive, Versions 2.1 - 2.2, contains an information disclosure vulnerability. An authenticated non-admin user cou... |
| CVE-2022-32484 | MEDIUM | 4.4 | 0.2% | Oct 12, 2022 | Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with admin privilege... |
| CVE-2022-32483 | MEDIUM | 4.4 | 0.2% | Oct 12, 2022 | Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with admin privilege... |
| CVE-2022-42087 | MEDIUM | 6.5 | 0.3% | Oct 12, 2022 | Tenda AX1803 US_AX1803v2.0br_v1.0.0.1_2994_CN_ZGYD01_4 is vulnerable to Cross Site Request Forgery (CSRF) via function f... |
| CVE-2022-42086 | MEDIUM | 6.5 | 0.3% | Oct 12, 2022 | Tenda AX1803 US_AX1803v2.0br_v1.0.0.1_2994_CN_ZGYD01_4 is vulnerable to Cross Site Request Forgery (CSRF) via function T... |
| CVE-2022-42078 | MEDIUM | 6.5 | 0.3% | Oct 12, 2022 | Tenda AC1206 US_AC1206V1.0RTL_V15.03.06.23_multi_TD01 is vulnerable to Cross Site Request Forgery (CSRF) via function fr... |
| CVE-2022-42077 | MEDIUM | 6.5 | 0.3% | Oct 12, 2022 | Tenda AC1206 US_AC1206V1.0RTL_V15.03.06.23_multi_TD01 is vulnerable to Cross Site Request Forgery (CSRF) via function fr... |
| CVE-2022-2249 | MEDIUM | 6.7 | 0.2% | Oct 12, 2022 | Privilege escalation related vulnerabilities were discovered in Avaya Aura Communication Manager that may allow local ad... |
| CVE-2022-42715 | MEDIUM | 6.1 | 0.7% | Oct 12, 2022 | A reflected XSS vulnerability exists in REDCap before 12.04.18 in the Alerts & Notifications upload feature. A crafted C... |
| CVE-2022-3464 | MEDIUM | 6.1 | 0.5% | Oct 12, 2022 | A vulnerability classified as problematic has been found in puppyCMS up to 5.1. This affects an unknown part of the file... |
| CVE-2022-2720 | MEDIUM | 5.3 | 0.4% | Oct 12, 2022 | In affected versions of Octopus Server it was identified that when a sensitive value is a substring of another value, se... |
| CVE-2022-41606 | MEDIUM | 6.5 | 0.7% | Oct 12, 2022 | HashiCorp Nomad and Nomad Enterprise 1.0.2 up to 1.2.12, and 1.3.5 jobs submitted with an artifact stanza using invalid ... |
| CVE-2022-40440 | MEDIUM | 6.1 | 0.7% | Oct 12, 2022 | mxGraph v4.2.2 was discovered to contain a cross-site scripting (XSS) vulnerability via the setTooltips() function. |
| CVE-2022-41550 | MEDIUM | 6.5 | 0.5% | Oct 11, 2022 | GNU oSIP v5.3.0 was discovered to contain an integer overflow via the component osip_body_parse_header. |
| CVE-2022-41210 | MEDIUM | 5.2 | 0.4% | Oct 11, 2022 | SAP Customer Data Cloud (Gigya mobile app for Android) - version 7.4, uses insecure random number generator program whic... |
| CVE-2022-41209 | MEDIUM | 5.2 | 0.2% | Oct 11, 2022 | SAP Customer Data Cloud (Gigya mobile app for Android) - version 7.4, uses encryption method which lacks proper diffusio... |
| CVE-2022-41206 | MEDIUM | 5.4 | 0.5% | Oct 11, 2022 | SAP BusinessObjects Business Intelligence platform (Analysis for OLAP) - versions 420, 430, allows an authenticated atta... |
| CVE-2022-41183 | MEDIUM | 5.5 | 0.2% | Oct 11, 2022 | Due to lack of proper memory management, when a victim opens manipulated Windows Cursor File (.cur, ico.x3d) file receiv... |
| CVE-2022-41182 | MEDIUM | 5.5 | 0.2% | Oct 11, 2022 | Due to lack of proper memory management, when a victim opens manipulated Parasolid Part and Assembly (.x_b, CoreCadTrans... |
| CVE-2022-41181 | MEDIUM | 5.5 | 0.2% | Oct 11, 2022 | Due to lack of proper memory management, when a victim opens manipulated Portable Document Format (.pdf, PDFPublishing.d... |
| CVE-2022-41178 | MEDIUM | 5.5 | 0.2% | Oct 11, 2022 | Due to lack of proper memory management, when a victim opens manipulated Iges Part and Assembly (.igs, .iges, CoreCadTra... |
| CVE-2022-41176 | MEDIUM | 5.5 | 0.2% | Oct 11, 2022 | Due to lack of proper memory management, when a victim opens manipulated Enhanced Metafile (.emf, emf.x3d) file received... |
| CVE-2022-41174 | MEDIUM | 5.5 | 0.2% | Oct 11, 2022 | Due to lack of proper memory management, when a victim opens manipulated Right Hemisphere Material (.rhm, rh.x3d) file r... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now