2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-35945 | MEDIUM | 6.1 | 0.5% | Sep 14, 2022 | GLPI stands for Gestionnaire Libre de Parc Informatique and is a Free Asset and IT Management Software package, that pro... |
| CVE-2022-31187 | MEDIUM | 5.4 | 0.6% | Sep 14, 2022 | GLPI stands for Gestionnaire Libre de Parc Informatique and is a Free Asset and IT Management Software package, that pro... |
| CVE-2022-31143 | MEDIUM | 5.3 | 0.7% | Sep 14, 2022 | GLPI stands for Gestionnaire Libre de Parc Informatique and is a Free Asset and IT Management Software package, that pro... |
| CVE-2022-1778 | MEDIUM | 4.4 | 0.4% | Sep 14, 2022 | Improper Input Validation vulnerability in Hitachi Energy MicroSCADA X SYS600 while reading a specific configuration fil... |
| CVE-2022-0029 | MEDIUM | 5.5 | 0.2% | Sep 14, 2022 | An improper link resolution vulnerability in the Palo Alto Networks Cortex XDR agent on Windows devices allows a local a... |
| CVE-2022-20231 | MEDIUM | 6.7 | 0.1% | Sep 14, 2022 | In smc_intc_request_fiq of arm_gic.c, there is a possible out of bounds write due to improper input validation. This cou... |
| CVE-2022-38796 | MEDIUM | 6.1 | 0.5% | Sep 14, 2022 | A Host Header Injection vulnerability in Feehi CMS 2.1.1 may allow an attacker to spoof a particular header. This can be... |
| CVE-2022-22520 | MEDIUM | 5.3 | 0.8% | Sep 14, 2022 | A remote, unauthenticated attacker can enumerate valid users by sending specific requests to the webservice of MB connec... |
| CVE-2022-40626 | MEDIUM | 6.1 | 0.7% | Sep 14, 2022 | An unauthenticated user can create a link with reflected Javascript code inside the backurl parameter and send it to oth... |
| CVE-2022-37139 | MEDIUM | 5.4 | 0.5% | Sep 14, 2022 | Loan Management System version 1.0 suffers from a persistent cross site scripting vulnerability. |
| CVE-2022-37137 | MEDIUM | 5.4 | 0.5% | Sep 14, 2022 | PayMoney 3.3 is vulnerable to Stored Cross-Site Scripting (XSS) during replying the ticket. The XSS can be obtain from i... |
| CVE-2022-36668 | MEDIUM | 5.4 | 0.5% | Sep 14, 2022 | Garage Management System 1.0 is vulnerable to Stored Cross Site Scripting (XSS) on several parameters. The vulnerabiliti... |
| CVE-2022-38770 | MEDIUM | 5.3 | 0.6% | Sep 13, 2022 | The mobile application in Transtek Mojodat FAM (Fixed Asset Management) 2.4.6 allows remote attackers to fetch other use... |
| CVE-2022-37191 | MEDIUM | 6.5 | 2.5% | Sep 13, 2022 | The component "cuppa/api/index.php" of CuppaCMS v1.0 is Vulnerable to LFI. An authenticated user can read system files v... |
| CVE-2022-31861 | MEDIUM | 5.4 | 0.5% | Sep 13, 2022 | Cross site Scripting (XSS) in ThingsBoard IoT Platform through 3.3.4.1 via a crafted value being sent to the audit logs. |
| CVE-2022-31324 | MEDIUM | 6.5 | 0.4% | Sep 13, 2022 | An arbitrary file download vulnerability in the downloadAction() function of Penta Security Systems Inc WAPPLES v6.0 r3 ... |
| CVE-2022-39816 | MEDIUM | 6.5 | 0.5% | Sep 13, 2022 | In NOKIA 1350 OMS R14.2, Insufficiently Protected Credentials (cleartext administrator password) occur in the edit confi... |
| CVE-2022-39814 | MEDIUM | 6.1 | 0.4% | Sep 13, 2022 | In NOKIA 1350 OMS R14.2, an Open Redirect vulnerability occurs is the login page via next HTTP GET parameter. |
| CVE-2022-38497 | MEDIUM | 5.5 | 0.3% | Sep 13, 2022 | LIEF commit 365a16a was discovered to contain a segmentation violation via the component CoreFile.tcc:69. |
| CVE-2022-38496 | MEDIUM | 5.5 | 0.3% | Sep 13, 2022 | LIEF commit 365a16a was discovered to contain a reachable assertion abort via the component BinaryStream.hpp. |
| CVE-2022-38329 | MEDIUM | 4.3 | 0.4% | Sep 13, 2022 | A CSRF vulnerability in Shopxian CMS 3.0.0 could allow an unauthenticated, remote attacker to craft a malicious link, po... |
| CVE-2022-38307 | MEDIUM | 5.5 | 0.3% | Sep 13, 2022 | LIEF commit 5d1d643 was discovered to contain a segmentation violation via the function LIEF::MachO::SegmentCommand::fil... |
| CVE-2022-35637 | MEDIUM | 6.5 | 1.0% | Sep 13, 2022 | IBM Db2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, 11.1, and 11.5 is vulnerable to a denial of service after entering ... |
| CVE-2022-34336 | MEDIUM | 5.4 | 0.4% | Sep 13, 2022 | IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows... |
| CVE-2022-22483 | MEDIUM | 6.5 | 0.8% | Sep 13, 2022 | IBM Db2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, 11.1, and 11.5 is vulnerable to an information disclosure in some s... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now