2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-41841 | MEDIUM | 5.5 | 0.3% | Sep 30, 2022 | An issue was discovered in Bento4 through 1.6.0-639. A NULL pointer dereference occurs in AP4_File::ParseStream in Core/... |
| CVE-2022-39232 | MEDIUM | 4.3 | 1.0% | Sep 29, 2022 | Discourse is an open source discussion platform. Starting with version 2.9.0.beta5 and prior to version 2.9.0.beta10, an... |
| CVE-2022-39226 | MEDIUM | 4.3 | 0.8% | Sep 29, 2022 | Discourse is an open source discussion platform. In versions prior to 2.8.9 on the `stable` branch and prior to 2.9.0.be... |
| CVE-2022-36068 | MEDIUM | 4.3 | 0.7% | Sep 29, 2022 | Discourse is an open source discussion platform. In versions prior to 2.8.9 on the `stable` branch and prior to 2.9.0.be... |
| CVE-2022-35137 | MEDIUM | 5.4 | 0.5% | Sep 29, 2022 | DGIOT Lightweight industrial IoT v4.5.4 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities. |
| CVE-2022-40879 | MEDIUM | 6.1 | 1.1% | Sep 29, 2022 | kkFileView v4.1.0 is vulnerable to Cross Site Scripting (XSS) via the parameter 'errorMsg.' |
| CVE-2022-40931 | MEDIUM | 6.1 | 0.5% | Sep 29, 2022 | dutchcoders Transfer.sh 1.4.0 is vulnerable to Cross Site Scripting (XSS). |
| CVE-2022-39254 | MEDIUM | 6.5 | 0.6% | Sep 29, 2022 | matrix-nio is a Python Matrix client library, designed according to sans I/O principles. Prior to version 0.20, when a u... |
| CVE-2022-40408 | MEDIUM | 5.4 | 0.4% | Sep 29, 2022 | FeehiCMS v2.1.1 was discovered to contain a cross-site scripting (XSS) vulnerability via a crafted payload injected into... |
| CVE-2022-40363 | MEDIUM | 5.5 | 0.3% | Sep 29, 2022 | A buffer overflow in the component nfc_device_load_mifare_ul_data of Flipper Devices Inc., Flipper Zero before v0.65.2 a... |
| CVE-2022-3355 | MEDIUM | 5.4 | 0.6% | Sep 29, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository inventree/inventree prior to 0.8.3. |
| CVE-2022-1725 | MEDIUM | 5.5 | 0.5% | Sep 29, 2022 | NULL Pointer Dereference in GitHub repository vim/vim prior to 8.2.4959. |
| CVE-2022-1719 | MEDIUM | 5.4 | 0.7% | Sep 29, 2022 | Reflected XSS on ticket filter function in GitHub repository polonel/trudesk prior to 1.2.2. This vulnerability is capab... |
| CVE-2022-35888 | MEDIUM | 6.5 | 0.6% | Sep 29, 2022 | Ampere Altra and Ampere Altra Max devices through 2022-07-15 allow attacks via Hertzbleed, which is a power side-channel... |
| CVE-2022-3326 | MEDIUM | 4.3 | 0.5% | Sep 29, 2022 | Weak Password Requirements in GitHub repository ikus060/rdiffweb prior to 2.4.9. |
| CVE-2022-31629 | MEDIUM | 6.5 | 49.3% | Sep 28, 2022 | In PHP versions before 7.4.31, 8.0.24 and 8.1.11, the vulnerability enables network and same-site attackers to set a sta... |
| CVE-2022-31628 | MEDIUM | 5.5 | 0.6% | Sep 28, 2022 | In PHP versions before 7.4.31, 8.0.24 and 8.1.11, the phar uncompressor code would recursively uncompress "quines" gzip ... |
| CVE-2022-39264 | MEDIUM | 5.9 | 0.6% | Sep 28, 2022 | nheko is a desktop client for the Matrix communication application. All versions below 0.10.2 are vulnerable homeservers... |
| CVE-2022-3292 | MEDIUM | 4.6 | 0.5% | Sep 28, 2022 | Use of Cache Containing Sensitive Information in GitHub repository ikus060/rdiffweb prior to 2.4.8. |
| CVE-2022-29089 | MEDIUM | 4.9 | 0.5% | Sep 28, 2022 | Dell Networking OS10, versions prior to October 2021 with Smart Fabric Services enabled, contains an information disclos... |
| CVE-2022-3287 | MEDIUM | 6.5 | 0.6% | Sep 28, 2022 | When creating an OPERATOR user account on the BMC, the redfish plugin saved the auto-generated password to /etc/fwupd/re... |
| CVE-2022-39246 | MEDIUM | 5.3 | 0.6% | Sep 28, 2022 | matrix-android-sdk2 is the Matrix SDK for Android. Prior to version 1.5.1, an attacker cooperating with a malicious home... |
| CVE-2022-36781 | MEDIUM | 5.3 | 0.5% | Sep 28, 2022 | ConnectWise ScreenConnect versions 22.6 and below contained a flaw allowing potential brute force attacks on custom acce... |
| CVE-2022-23716 | MEDIUM | 5.3 | 0.5% | Sep 28, 2022 | A flaw was discovered in ECE before 3.1.1 that could lead to the disclosure of the SAML signing private key used for the... |
| CVE-2022-3193 | MEDIUM | 6.1 | 0.4% | Sep 28, 2022 | An HTML injection/reflected Cross-site scripting (XSS) vulnerability was found in the ovirt-engine. A parameter "error_d... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now