2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-39847 | MEDIUM | 5.3 | 0.1% | Oct 7, 2022 | Use after free vulnerability in set_nft_pid and signal_handler function of NFC driver prior to SMR Oct-2022 Release 1 al... |
| CVE-2022-3423 | MEDIUM | 6.5 | 1.8% | Oct 7, 2022 | Allocation of Resources Without Limits or Throttling in GitHub repository nocodb/nocodb prior to 0.92.0. |
| CVE-2022-2929 | MEDIUM | 6.5 | 0.6% | Oct 7, 2022 | In ISC DHCP 1.0 -> 4.4.3, ISC DHCP 4.1-ESV-R1 -> 4.1-ESV-R16-P1 a system with access to a DHCP server, sending DHCP pack... |
| CVE-2022-2928 | MEDIUM | 6.5 | 0.7% | Oct 7, 2022 | In ISC DHCP 4.4.0 -> 4.4.3, ISC DHCP 4.1-ESV-R1 -> 4.1-ESV-R16-P1, when the function option_code_hash_lookup() is called... |
| CVE-2022-26238 | MEDIUM | 5.5 | 0.2% | Oct 6, 2022 | The default privileges for the running service Normand Service Manager in Beckman Coulter Remisol Advance v2.0.12.1 and ... |
| CVE-2022-26236 | MEDIUM | 5.5 | 0.2% | Oct 6, 2022 | The default privileges for the running service Normand Remisol Advance Launcher in Beckman Coulter Remisol Advance v2.0.... |
| CVE-2022-39284 | MEDIUM | 4.3 | 0.8% | Oct 6, 2022 | CodeIgniter is a PHP full-stack web framework. In versions prior to 4.2.7 setting `$secure` or `$httponly` value to `tru... |
| CVE-2022-39279 | MEDIUM | 5.4 | 0.4% | Oct 6, 2022 | discourse-chat is a plugin for the Discourse message board which adds chat functionality. In versions prior to 0.9 some ... |
| CVE-2022-41294 | MEDIUM | 6.5 | 0.2% | Oct 6, 2022 | IBM Robotic Process Automation 21.0.0, 21.0.1, 21.0.2, 21.0.3, and 21.0.4 is vulnerable to cross origin resource sharing... |
| CVE-2022-40160 | MEDIUM | 6.5 | 1.2% | Oct 6, 2022 | ** DISPUTED ** This record was originally reported by the oss-fuzz project who failed to consider the security context i... |
| CVE-2022-40159 | MEDIUM | 6.5 | 1.2% | Oct 6, 2022 | ** DISPUTED ** This record was originally reported by the oss-fuzz project who failed to consider the security context i... |
| CVE-2022-3376 | MEDIUM | 5.3 | 0.7% | Oct 6, 2022 | Weak Password Requirements in GitHub repository ikus060/rdiffweb prior to 2.5.0a4. |
| CVE-2022-3002 | MEDIUM | 5.4 | 0.5% | Oct 6, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0. |
| CVE-2022-39988 | MEDIUM | 5.4 | 0.6% | Oct 6, 2022 | A cross-site scripting (XSS) vulnerability in Centreon 22.04.0 allows attackers to execute arbitrary web script or HTML ... |
| CVE-2022-39275 | MEDIUM | 4.3 | 0.5% | Oct 6, 2022 | Saleor is a headless, GraphQL commerce platform. In affected versions some GraphQL mutations were not properly checking ... |
| CVE-2022-39270 | MEDIUM | 5.4 | 0.4% | Oct 6, 2022 | DiscoTOC is a Discourse theme component that generates a table of contents for topics. Users that can create topics in T... |
| CVE-2022-39222 | MEDIUM | 6.5 | 1.1% | Oct 6, 2022 | Dex is an identity service that uses OpenID Connect to drive authentication for other apps. Dex instances with public cl... |
| CVE-2022-38709 | MEDIUM | 6.1 | 0.4% | Oct 6, 2022 | IBM Robotic Process Automation 21.0.1, 21.0.2, and 21.0.3 for Cloud Pak is vulnerable to cross-site scripting. This vuln... |
| CVE-2022-36774 | MEDIUM | 5.3 | 0.3% | Oct 6, 2022 | IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 is vulnerable to man in the middle attacks through manipulatio... |
| CVE-2022-31252 | MEDIUM | 4.4 | 0.1% | Oct 6, 2022 | A Incorrect Authorization vulnerability in chkstat of SUSE Linux Enterprise Server 12-SP5; openSUSE Leap 15.3, openSUSE ... |
| CVE-2022-2975 | MEDIUM | 6.7 | 0.2% | Oct 6, 2022 | A vulnerability related to weak permissions was detected in Avaya Aura Application Enablement Services web application, ... |
| CVE-2022-2783 | MEDIUM | 5.3 | 0.2% | Oct 6, 2022 | In affected versions of Octopus Server it was identified that a session cookie could be used as the CSRF token |
| CVE-2022-2781 | MEDIUM | 5.3 | 0.2% | Oct 6, 2022 | In affected versions of Octopus Server it was identified that the same encryption process was used for both encrypting s... |
| CVE-2022-26240 | MEDIUM | 6.5 | 0.6% | Oct 6, 2022 | The default privileges for the running service Normand Message Buffer in Beckman Coulter Remisol Advance v2.0.12.1 and p... |
| CVE-2022-26239 | MEDIUM | 5.5 | 0.2% | Oct 6, 2022 | The default privileges for the running service Normand License Manager in Beckman Coulter Remisol Advance v2.0.12.1 and ... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now