2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-38251 | MEDIUM | 4.8 | 1.7% | Sep 7, 2022 | Nagios XI v5.8.6 was discovered to contain a cross-site scripting (XSS) vulnerability via the System Performance Setting... |
| CVE-2022-38249 | MEDIUM | 6.1 | 1.7% | Sep 7, 2022 | Nagios XI v5.8.6 was discovered to contain a cross-site scripting (XSS) vulnerability via the MTR component in version 1... |
| CVE-2022-38248 | MEDIUM | 6.1 | 1.7% | Sep 7, 2022 | Nagios XI before v5.8.7 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities at auditlog.php. |
| CVE-2022-38247 | MEDIUM | 4.8 | 1.7% | Sep 7, 2022 | Nagios XI v5.8.6 was discovered to contain a cross-site scripting (XSS) vulnerability via the System Settings page under... |
| CVE-2022-36083 | MEDIUM | 5.3 | 1.1% | Sep 7, 2022 | JOSE is "JSON Web Almost Everything" - JWA, JWS, JWE, JWT, JWK, JWKS with no dependencies using runtime's native crypto ... |
| CVE-2022-36082 | MEDIUM | 5.3 | 0.6% | Sep 7, 2022 | mangadex-downloader is a command-line tool to download manga from MangaDex. When using `file:<location>` command and `<l... |
| CVE-2022-36080 | MEDIUM | 6.1 | 0.4% | Sep 7, 2022 | Wikmd is a file based wiki that uses markdown. Prior to version 1.7.1, an attacker could capture user's session cookies ... |
| CVE-2022-30312 | MEDIUM | 6.5 | 0.2% | Sep 7, 2022 | The Trend Controls IC protocol through 2022-05-06 allows Cleartext Transmission of Sensitive Information. According to F... |
| CVE-2022-36661 | MEDIUM | 6.5 | 0.7% | Sep 7, 2022 | xhyve commit dfbe09b was discovered to contain a NULL pointer dereference via the component vi_pci_read(). This vulnerab... |
| CVE-2022-36659 | MEDIUM | 6.5 | 0.7% | Sep 7, 2022 | xhyve commit dfbe09b was discovered to contain a NULL pointer dereference via the component vi_pci_write(). This vulnera... |
| CVE-2022-37731 | MEDIUM | 6.1 | 0.5% | Sep 7, 2022 | ftcms 2.1 poster.PHP has a XSS vulnerability. The attacker inserts malicious JavaScript code into the web page, causing ... |
| CVE-2022-31167 | MEDIUM | 6.5 | 0.6% | Sep 7, 2022 | XWiki Platform Security Parent POM contains the security APIs for XWiki Platform, a generic wiki platform. Starting with... |
| CVE-2022-31251 | MEDIUM | 6.3 | 0.2% | Sep 7, 2022 | A Incorrect Default Permissions vulnerability in the packaging of the slurm testsuite of openSUSE Factory allows local a... |
| CVE-2022-21950 | MEDIUM | 5.3 | 0.1% | Sep 7, 2022 | A Improper Access Control vulnerability in the systemd service of cana in openSUSE Backports SLE-15-SP3, openSUSE Backpo... |
| CVE-2022-38528 | MEDIUM | 6.5 | 0.6% | Sep 6, 2022 | Open Asset Import Library (assimp) commit 3c253ca was discovered to contain a segmentation violation via the component A... |
| CVE-2022-35913 | MEDIUM | 4.3 | 0.6% | Sep 6, 2022 | Samourai Wallet Stonewallx2 0.99.98e allows a denial of service via a P2P coinjoin. The attacker and victim must follow ... |
| CVE-2022-1522 | MEDIUM | 5.3 | 0.5% | Sep 6, 2022 | The Cognex 3D-A1000 Dimensioning System in firmware version 1.0.3 (3354) and prior is vulnerable to CWE-117: Improper Ou... |
| CVE-2022-36072 | MEDIUM | 5.9 | 0.5% | Sep 6, 2022 | SilverwareGames.io is a social network for users to play video games online. In version 1.1.8 and prior, due to an unobv... |
| CVE-2022-37253 | MEDIUM | 5.4 | 0.6% | Sep 6, 2022 | Persistent cross-site scripting (XSS) in Crime Reporting System 1.0 allows a remote attacker to introduce arbitary Javas... |
| CVE-2022-36057 | MEDIUM | 4.8 | 0.4% | Sep 6, 2022 | Discourse-Chat is an asynchronous messaging plugin for the Discourse open-source discussion platform. Users of Discourse... |
| CVE-2022-32277 | MEDIUM | 5.3 | 0.4% | Sep 6, 2022 | Squiz Matrix CMS 6.20 is vulnerable to an Insecure Direct Object Reference caused by failure to correctly validate autho... |
| CVE-2022-37771 | MEDIUM | 6.7 | 0.4% | Sep 6, 2022 | IObit Malware Fighter v9.2 for Microsoft Windows lacks tamper protection, allowing authenticated attackers with Administ... |
| CVE-2022-36670 | MEDIUM | 6.7 | 0.3% | Sep 6, 2022 | PCProtect Endpoint prior to v5.17.470 for Microsoft Windows lacks tamper protection, allowing authenticated attackers wi... |
| CVE-2022-36032 | MEDIUM | 5.3 | 0.8% | Sep 6, 2022 | ReactPHP HTTP is a streaming HTTP client and server implementation for ReactPHP. In ReactPHP's HTTP server component ver... |
| CVE-2022-31792 | MEDIUM | 5.4 | 0.5% | Sep 6, 2022 | A stored cross-site scripting (XSS) vulnerability exists in the management web interface of WatchGuard Firebox and XTM a... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now