2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-2930 | HIGH | 7.8 | 0.3% | Aug 22, 2022 | Unverified Password Change in GitHub repository octoprint/octoprint prior to 1.8.3. |
| CVE-2022-30036 | HIGH | 8.8 | 0.8% | Aug 21, 2022 | MA Lighting grandMA2 Light has a password of root for the root account. NOTE: The vendor's position is that the product ... |
| CVE-2022-2921 | HIGH | 8.8 | 1.1% | Aug 21, 2022 | Exposure of Private Personal Information to an Unauthorized Actor in GitHub repository notrinos/notrinoserp prior to v0.... |
| CVE-2022-38493 | HIGH | 7.5 | 0.3% | Aug 20, 2022 | Rhonabwy 0.9.99 through 1.1.x before 1.1.7 doesn't check the RSA private key length before RSA-OAEP decryption. This all... |
| CVE-2022-2909 | HIGH | 8.8 | 0.7% | Aug 20, 2022 | A vulnerability was found in SourceCodester Simple and Nice Shopping Cart Script. It has been declared as critical. Affe... |
| CVE-2022-2793 | HIGH | 7.8 | 0.1% | Aug 19, 2022 | Emerson Electric's Proficy Machine Edition Version 9.00 and prior is vulenrable to CWE-353 Missing Support for Integrity... |
| CVE-2022-2792 | HIGH | 7.5 | 0.4% | Aug 19, 2022 | Emerson Electric's Proficy Machine Edition Version 9.00 and prior is vulenrable to CWE-284 Improper Access Control, and ... |
| CVE-2022-36171 | HIGH | 8.1 | 0.6% | Aug 19, 2022 | MapGIS IGServer 10.5.6.11 is vulnerable to Arbitrary file deletion. |
| CVE-2022-36157 | HIGH | 8.8 | 1.2% | Aug 19, 2022 | XXL-JOB all versions as of 11 July 2022 are vulnerable to Insecure Permissions resulting in the ability to execute admin... |
| CVE-2022-36170 | HIGH | 8.8 | 0.8% | Aug 19, 2022 | MapGIS 10.5 Pro IGServer has hardcoded credentials in the front-end and can lead to escalation of privileges and arbitra... |
| CVE-2022-36009 | HIGH | 8.8 | 0.7% | Aug 19, 2022 | gomatrixserverlib is a Go library for matrix protocol federation. Dendrite is a Matrix homeserver written in Go, an alte... |
| CVE-2022-2788 | HIGH | 7.3 | 0.2% | Aug 19, 2022 | Emerson Electric's Proficy Machine Edition Version 9.80 and prior is vulnerable to CWE-29 Path Traversal: '\..\Filename'... |
| CVE-2022-23460 | HIGH | 7.5 | 0.6% | Aug 19, 2022 | Jsonxx or Json++ is a JSON parser, writer and reader written in C++. In affected versions of jsonxx json parsing may lea... |
| CVE-2022-36579 | HIGH | 8.8 | 0.4% | Aug 19, 2022 | Wellcms 2.2.0 is vulnerable to Cross Site Request Forgery (CSRF). |
| CVE-2022-36577 | HIGH | 8.8 | 0.4% | Aug 19, 2022 | An issue was discovered in jizhicms v2.3.1. There is a CSRF vulnerability that can add a admin. |
| CVE-2022-36225 | HIGH | 8.8 | 0.4% | Aug 19, 2022 | EyouCMS V1.5.8-UTF8-SP1 is vulnerable to Cross Site Request Forgery (CSRF) via the background, column management functio... |
| CVE-2022-36224 | HIGH | 8.8 | 0.4% | Aug 19, 2022 | XunRuiCMS V4.5.6 is vulnerable to Cross Site Request Forgery (CSRF). |
| CVE-2022-36263 | HIGH | 7.3 | 0.4% | Aug 19, 2022 | StreamLabs Desktop Application 1.9.0 is vulnerable to Incorrect Access Control via obs64.exe. An attacker can execute ar... |
| CVE-2022-35909 | HIGH | 8.8 | 1.3% | Aug 19, 2022 | In Jellyfin before 10.8, the /users endpoint has incorrect access control for admin functionality. |
| CVE-2022-2889 | HIGH | 7.8 | 0.5% | Aug 19, 2022 | Use After Free in GitHub repository vim/vim prior to 9.0.0225. |
| CVE-2022-2886 | HIGH | 8.8 | 0.6% | Aug 19, 2022 | A vulnerability, which was classified as critical, was found in Laravel 5.1. Affected is an unknown function. The manipu... |
| CVE-2022-2075 | HIGH | 7.5 | 0.7% | Aug 19, 2022 | In affected versions of Octopus Deploy it is possible to perform a Regex Denial of Service targeting the build informati... |
| CVE-2022-2074 | HIGH | 7.5 | 0.7% | Aug 19, 2022 | In affected versions of Octopus Deploy it is possible to perform a Regex Denial of Service using the Variable Project Te... |
| CVE-2022-2049 | HIGH | 7.5 | 0.7% | Aug 19, 2022 | In affected versions of Octopus Deploy it is possible to perform a Regex Denial of Service via the package upload functi... |
| CVE-2022-35167 | HIGH | 8.8 | 0.9% | Aug 19, 2022 | Printix Cloud Print Management v1.3.1149.0 for Windows was discovered to contain insecure permissions. |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now