2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-39236MEDIUM5.3Matrix Javascript SDK is the Matrix Client-Server SDK for JavaScript. Starting with version 17.1.0-rc.1, improperly form...
CVE-2022-36771MEDIUM6.5IBM QRadar User Behavior Analytics could allow an authenticated user to obtain sensitive information from that they shou...
CVE-2022-35722MEDIUM5.4IBM Jazz for Service Management is vulnerable to stored cross-site scripting. This vulnerability allows users to embed a...
CVE-2022-35282MEDIUM6.5IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to server-side request forgery (SSRF). By sending ...
CVE-2022-22387MEDIUM5.4IBM Application Gateway is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaSc...
CVE-2022-40912MEDIUM6.1ETAP Lighting International NV ETAP Safety Manager 1.0.0.32 is vulnerable to Cross Site Scripting (XSS). Input passed to...
CVE-2022-28816MEDIUM6.1In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 the Sentilo Proxy is prone to refl...
CVE-2022-3349MEDIUM6.8A vulnerability was found in Sony PS4 and PS5. It has been classified as critical. This affects the function UVFAT_readu...
CVE-2022-2760MEDIUM4.3In affected versions of Octopus Deploy it is possible to reveal the Space ID of spaces that the user does not have acces...
CVE-2022-32170MEDIUM4.3The “Bytebase” application does not restrict low privilege user to access admin “projects“ for which an unauthorized use...
CVE-2022-32169MEDIUM4.3The “Bytebase” application does not restrict low privilege user to access “admin issues“ for which an unauthorized user ...
CVE-2022-32166MEDIUM6.1In ovs versions v0.90.0 through v2.5.0 are vulnerable to heap buffer over-read in flow.c. An unsafe comparison of “minim...
CVE-2022-3348MEDIUM4.9Just like in the previous report, an attacker could steal the account of different users. But in this case, it's a littl...
CVE-2022-3333MEDIUM5.4A vulnerability, which was classified as problematic, was found in Zephyr Project Manager up to 3.2.4. Affected is an un...
CVE-2022-39054MEDIUM6.1Cowell enterprise travel management system has insufficient filtering for special characters within web URL. An unauthen...
CVE-2022-39053MEDIUM6.1Heimavista Rpage has insufficient filtering for platform web URL. An unauthenticated remote attacker can inject JavaScri...
CVE-2022-39035MEDIUM6.1Smart eVision has insufficient filtering for special characters in the POST Data parameter in the specific function. An ...
CVE-2022-39034MEDIUM6.5Smart eVision has a path traversal vulnerability in the Report API function due to insufficient filtering for special ch...
CVE-2022-39031MEDIUM5.3Smart eVision has insufficient authorization for task acquisition function. An unauthorized remote attacker can exploit ...
CVE-2022-39029MEDIUM6.5Smart eVision has inadequate authorization for the database query function. A remote attacker with general user privileg...
CVE-2022-38699MEDIUM5.9Armoury Crate Service’s logging function has insufficient validation to check if the log file is a symbolic link. A phys...
CVE-2022-40817MEDIUM4.3Zammad 5.2.1 has a fine-grained permission model that allows to configure read-only access to tickets. However, agents w...
CVE-2022-40816MEDIUM6.5Zammad 5.2.1 is vulnerable to Incorrect Access Control. Zammad's asset handling mechanism has logic to ensure that custo...
CVE-2022-3303MEDIUM4.7A race condition flaw was found in the Linux kernel sound subsystem due to improper locking. It could lead to a NULL poi...
CVE-2022-39835MEDIUM5.3An issue was discovered in Gajim through 1.4.7. The vulnerability allows attackers, via crafted XML stanzas, to correct ...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now