2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-39236 | MEDIUM | 5.3 | 1.0% | Sep 28, 2022 | Matrix Javascript SDK is the Matrix Client-Server SDK for JavaScript. Starting with version 17.1.0-rc.1, improperly form... |
| CVE-2022-36771 | MEDIUM | 6.5 | 0.5% | Sep 28, 2022 | IBM QRadar User Behavior Analytics could allow an authenticated user to obtain sensitive information from that they shou... |
| CVE-2022-35722 | MEDIUM | 5.4 | 0.4% | Sep 28, 2022 | IBM Jazz for Service Management is vulnerable to stored cross-site scripting. This vulnerability allows users to embed a... |
| CVE-2022-35282 | MEDIUM | 6.5 | 0.3% | Sep 28, 2022 | IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to server-side request forgery (SSRF). By sending ... |
| CVE-2022-22387 | MEDIUM | 5.4 | 0.4% | Sep 28, 2022 | IBM Application Gateway is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaSc... |
| CVE-2022-40912 | MEDIUM | 6.1 | 0.5% | Sep 28, 2022 | ETAP Lighting International NV ETAP Safety Manager 1.0.0.32 is vulnerable to Cross Site Scripting (XSS). Input passed to... |
| CVE-2022-28816 | MEDIUM | 6.1 | 0.4% | Sep 28, 2022 | In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 the Sentilo Proxy is prone to refl... |
| CVE-2022-3349 | MEDIUM | 6.8 | 0.5% | Sep 28, 2022 | A vulnerability was found in Sony PS4 and PS5. It has been classified as critical. This affects the function UVFAT_readu... |
| CVE-2022-2760 | MEDIUM | 4.3 | 0.4% | Sep 28, 2022 | In affected versions of Octopus Deploy it is possible to reveal the Space ID of spaces that the user does not have acces... |
| CVE-2022-32170 | MEDIUM | 4.3 | 0.5% | Sep 28, 2022 | The “Bytebase” application does not restrict low privilege user to access admin “projects“ for which an unauthorized use... |
| CVE-2022-32169 | MEDIUM | 4.3 | 0.5% | Sep 28, 2022 | The “Bytebase” application does not restrict low privilege user to access “admin issues“ for which an unauthorized user ... |
| CVE-2022-32166 | MEDIUM | 6.1 | 0.5% | Sep 28, 2022 | In ovs versions v0.90.0 through v2.5.0 are vulnerable to heap buffer over-read in flow.c. An unsafe comparison of “minim... |
| CVE-2022-3348 | MEDIUM | 4.9 | 0.8% | Sep 28, 2022 | Just like in the previous report, an attacker could steal the account of different users. But in this case, it's a littl... |
| CVE-2022-3333 | MEDIUM | 5.4 | 0.4% | Sep 28, 2022 | A vulnerability, which was classified as problematic, was found in Zephyr Project Manager up to 3.2.4. Affected is an un... |
| CVE-2022-39054 | MEDIUM | 6.1 | 0.5% | Sep 28, 2022 | Cowell enterprise travel management system has insufficient filtering for special characters within web URL. An unauthen... |
| CVE-2022-39053 | MEDIUM | 6.1 | 0.5% | Sep 28, 2022 | Heimavista Rpage has insufficient filtering for platform web URL. An unauthenticated remote attacker can inject JavaScri... |
| CVE-2022-39035 | MEDIUM | 6.1 | 0.5% | Sep 28, 2022 | Smart eVision has insufficient filtering for special characters in the POST Data parameter in the specific function. An ... |
| CVE-2022-39034 | MEDIUM | 6.5 | 1.2% | Sep 28, 2022 | Smart eVision has a path traversal vulnerability in the Report API function due to insufficient filtering for special ch... |
| CVE-2022-39031 | MEDIUM | 5.3 | 0.6% | Sep 28, 2022 | Smart eVision has insufficient authorization for task acquisition function. An unauthorized remote attacker can exploit ... |
| CVE-2022-39029 | MEDIUM | 6.5 | 0.6% | Sep 28, 2022 | Smart eVision has inadequate authorization for the database query function. A remote attacker with general user privileg... |
| CVE-2022-38699 | MEDIUM | 5.9 | 0.3% | Sep 28, 2022 | Armoury Crate Service’s logging function has insufficient validation to check if the log file is a symbolic link. A phys... |
| CVE-2022-40817 | MEDIUM | 4.3 | 0.4% | Sep 27, 2022 | Zammad 5.2.1 has a fine-grained permission model that allows to configure read-only access to tickets. However, agents w... |
| CVE-2022-40816 | MEDIUM | 6.5 | 0.7% | Sep 27, 2022 | Zammad 5.2.1 is vulnerable to Incorrect Access Control. Zammad's asset handling mechanism has logic to ensure that custo... |
| CVE-2022-3303 | MEDIUM | 4.7 | 0.3% | Sep 27, 2022 | A race condition flaw was found in the Linux kernel sound subsystem due to improper locking. It could lead to a NULL poi... |
| CVE-2022-39835 | MEDIUM | 5.3 | 0.5% | Sep 27, 2022 | An issue was discovered in Gajim through 1.4.7. The vulnerability allows attackers, via crafted XML stanzas, to correct ... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now