2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-37796 | MEDIUM | 5.4 | 0.4% | Sep 12, 2022 | In Simple Online Book Store System 1.0 in /admin_book.php the Title, Author, and Description parameters are vulnerable t... |
| CVE-2022-40325 | MEDIUM | 6.1 | 0.4% | Sep 11, 2022 | SysAid Help Desk before 22.1.65 allows XSS via the Asset Dashboard, aka FR# 67262. |
| CVE-2022-40324 | MEDIUM | 6.1 | 0.4% | Sep 11, 2022 | SysAid Help Desk before 22.1.65 allows XSS via the Linked SRs field, aka FR# 67258. |
| CVE-2022-40323 | MEDIUM | 6.1 | 0.4% | Sep 11, 2022 | SysAid Help Desk before 22.1.65 allows XSS in the Password Services module, aka FR# 67241. |
| CVE-2022-40322 | MEDIUM | 6.1 | 0.4% | Sep 11, 2022 | SysAid Help Desk before 22.1.65 allows XSS, aka FR# 66542 and 65579. |
| CVE-2022-25295 | MEDIUM | 5.4 | 0.5% | Sep 11, 2022 | This affects the package github.com/gophish/gophish before 0.12.0. The Open Redirect vulnerability exists in the next qu... |
| CVE-2022-38266 | MEDIUM | 6.5 | 1.1% | Sep 9, 2022 | An issue in the Leptonica linked library (v1.79.0) allows attackers to cause an arithmetic exception leading to a Denial... |
| CVE-2022-36087 | MEDIUM | 6.5 | 1.3% | Sep 9, 2022 | OAuthLib is an implementation of the OAuth request-signing logic for Python 3.6+. In OAuthLib versions 3.1.1 until 3.2.1... |
| CVE-2022-38639 | MEDIUM | 5.4 | 0.4% | Sep 9, 2022 | A cross-site scripting (XSS) vulnerability in Markdown-Nice v1.8.22 allows attackers to execute arbitrary web scripts or... |
| CVE-2022-36109 | MEDIUM | 6.3 | 0.8% | Sep 9, 2022 | Moby is an open-source project created by Docker to enable software containerization. A bug was found in Moby (Docker En... |
| CVE-2022-40317 | MEDIUM | 5.4 | 0.9% | Sep 9, 2022 | OpenKM 6.3.11 allows stored XSS related to the javascript: substring in an A element. |
| CVE-2022-39810 | MEDIUM | 6.1 | 57.3% | Sep 9, 2022 | An issue was discovered in WSO2 Enterprise Integrator 6.4.0. A Reflected Cross-Site Scripting (XSS) vulnerability has be... |
| CVE-2022-39809 | MEDIUM | 6.1 | 0.5% | Sep 9, 2022 | An issue was discovered in WSO2 Enterprise Integrator 6.4.0. A Reflected Cross-Site Scripting (XSS) vulnerability has be... |
| CVE-2022-38613 | MEDIUM | 6.5 | 1.0% | Sep 9, 2022 | A Path Traversal vulnerability in SmartVista Cardgen v3.28.0 allows authenticated attackers to read arbitrary files in t... |
| CVE-2022-36617 | MEDIUM | 4.9 | 0.4% | Sep 9, 2022 | Arq Backup 7.19.5.0 and below stores backup encryption passwords using reversible encryption. This issue allows attacker... |
| CVE-2022-34165 | MEDIUM | 5.4 | 0.4% | Sep 9, 2022 | IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 and IBM WebSphere Application Server Liberty 17.0.0.3 through 22... |
| CVE-2022-40191 | MEDIUM | 5.4 | 0.4% | Sep 9, 2022 | Authenticated (subscriber+) Stored Cross-Site Scripting (XSS) vulnerability in Ali Khallad's Contact Form By Mega Forms ... |
| CVE-2022-40133 | MEDIUM | 5.5 | 0.5% | Sep 9, 2022 | A use-after-free(UAF) vulnerability was found in function 'vmw_execbuf_tie_context' in drivers/gpu/vmxgfx/vmxgfx_execbuf... |
| CVE-2022-3169 | MEDIUM | 5.5 | 0.2% | Sep 9, 2022 | A flaw was found in the Linux kernel. A denial of service flaw may occur if there is a consecutive request of the NVME_I... |
| CVE-2022-3147 | MEDIUM | 6.5 | 0.9% | Sep 9, 2022 | Mattermost version 7.0.x and earlier fails to sufficiently limit the in-memory sizes of concurrently uploaded JPEG image... |
| CVE-2022-3077 | MEDIUM | 5.5 | 0.2% | Sep 9, 2022 | A buffer overflow vulnerability was found in the Linux kernel Intel’s iSMT SMBus host controller driver in the way it ha... |
| CVE-2022-38457 | MEDIUM | 5.5 | 0.4% | Sep 9, 2022 | A use-after-free(UAF) vulnerability was found in function 'vmw_cmd_res_check' in drivers/gpu/vmxgfx/vmxgfx_execbuf.c in ... |
| CVE-2022-38096 | MEDIUM | 5.5 | 0.6% | Sep 9, 2022 | A NULL pointer dereference vulnerability was found in vmwgfx driver in drivers/gpu/vmxgfx/vmxgfx_execbuf.c in GPU compon... |
| CVE-2022-38081 | MEDIUM | 5.5 | 0.2% | Sep 9, 2022 | OpenHarmony-v3.1.2 and prior versions have a permission bypass vulnerability. LAN attackers can bypass the distributed p... |
| CVE-2022-38068 | MEDIUM | 4.8 | 0.4% | Sep 9, 2022 | Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Apasionados Export Post Info plugin <= 1.1.0 a... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now