2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-39847MEDIUM5.3Use after free vulnerability in set_nft_pid and signal_handler function of NFC driver prior to SMR Oct-2022 Release 1 al...
CVE-2022-3423MEDIUM6.5Allocation of Resources Without Limits or Throttling in GitHub repository nocodb/nocodb prior to 0.92.0.
CVE-2022-2929MEDIUM6.5In ISC DHCP 1.0 -> 4.4.3, ISC DHCP 4.1-ESV-R1 -> 4.1-ESV-R16-P1 a system with access to a DHCP server, sending DHCP pack...
CVE-2022-2928MEDIUM6.5In ISC DHCP 4.4.0 -> 4.4.3, ISC DHCP 4.1-ESV-R1 -> 4.1-ESV-R16-P1, when the function option_code_hash_lookup() is called...
CVE-2022-26238MEDIUM5.5The default privileges for the running service Normand Service Manager in Beckman Coulter Remisol Advance v2.0.12.1 and ...
CVE-2022-26236MEDIUM5.5The default privileges for the running service Normand Remisol Advance Launcher in Beckman Coulter Remisol Advance v2.0....
CVE-2022-39284MEDIUM4.3CodeIgniter is a PHP full-stack web framework. In versions prior to 4.2.7 setting `$secure` or `$httponly` value to `tru...
CVE-2022-39279MEDIUM5.4discourse-chat is a plugin for the Discourse message board which adds chat functionality. In versions prior to 0.9 some ...
CVE-2022-41294MEDIUM6.5IBM Robotic Process Automation 21.0.0, 21.0.1, 21.0.2, 21.0.3, and 21.0.4 is vulnerable to cross origin resource sharing...
CVE-2022-40160MEDIUM6.5** DISPUTED ** This record was originally reported by the oss-fuzz project who failed to consider the security context i...
CVE-2022-40159MEDIUM6.5** DISPUTED ** This record was originally reported by the oss-fuzz project who failed to consider the security context i...
CVE-2022-3376MEDIUM5.3Weak Password Requirements in GitHub repository ikus060/rdiffweb prior to 2.5.0a4.
CVE-2022-3002MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0.
CVE-2022-39988MEDIUM5.4A cross-site scripting (XSS) vulnerability in Centreon 22.04.0 allows attackers to execute arbitrary web script or HTML ...
CVE-2022-39275MEDIUM4.3Saleor is a headless, GraphQL commerce platform. In affected versions some GraphQL mutations were not properly checking ...
CVE-2022-39270MEDIUM5.4DiscoTOC is a Discourse theme component that generates a table of contents for topics. Users that can create topics in T...
CVE-2022-39222MEDIUM6.5Dex is an identity service that uses OpenID Connect to drive authentication for other apps. Dex instances with public cl...
CVE-2022-38709MEDIUM6.1IBM Robotic Process Automation 21.0.1, 21.0.2, and 21.0.3 for Cloud Pak is vulnerable to cross-site scripting. This vuln...
CVE-2022-36774MEDIUM5.3IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 is vulnerable to man in the middle attacks through manipulatio...
CVE-2022-31252MEDIUM4.4A Incorrect Authorization vulnerability in chkstat of SUSE Linux Enterprise Server 12-SP5; openSUSE Leap 15.3, openSUSE ...
CVE-2022-2975MEDIUM6.7A vulnerability related to weak permissions was detected in Avaya Aura Application Enablement Services web application, ...
CVE-2022-2783MEDIUM5.3In affected versions of Octopus Server it was identified that a session cookie could be used as the CSRF token
CVE-2022-2781MEDIUM5.3In affected versions of Octopus Server it was identified that the same encryption process was used for both encrypting s...
CVE-2022-26240MEDIUM6.5The default privileges for the running service Normand Message Buffer in Beckman Coulter Remisol Advance v2.0.12.1 and p...
CVE-2022-26239MEDIUM5.5The default privileges for the running service Normand License Manager in Beckman Coulter Remisol Advance v2.0.12.1 and ...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now