2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-39839 | MEDIUM | 4.8 | 0.4% | Sep 5, 2022 | Cotonti Siena 0.9.20 allows admins to conduct stored XSS attacks via a forum post. |
| CVE-2022-39196 | MEDIUM | 6.5 | 1.1% | Sep 5, 2022 | Blackboard Learn 1.10.1 allows remote authenticated users to read unintended files by entering student credentials and t... |
| CVE-2022-36647 | MEDIUM | 5.5 | 0.3% | Sep 2, 2022 | PKUVCL davs2 v1.6.205 was discovered to contain a global buffer overflow via the function parse_sequence_header() at sou... |
| CVE-2022-36639 | MEDIUM | 5.4 | 0.5% | Sep 2, 2022 | A stored cross-site scripting (XSS) vulnerability in /client.php of Garage Management System v1.0 allows attackers to ex... |
| CVE-2022-36638 | MEDIUM | 5.3 | 0.7% | Sep 2, 2022 | An access control issue in the component print.php of Garage Management System v1.0 allows unauthenticated attackers to ... |
| CVE-2022-35933 | MEDIUM | 6.1 | 0.4% | Sep 2, 2022 | This package is a PrestaShop module that allows users to post reviews and rate products. There is a vulnerability where ... |
| CVE-2022-34378 | MEDIUM | 5.5 | 0.2% | Sep 2, 2022 | Dell PowerScale OneFS, versions 9.0.0 up to and including 9.1.0.20, 9.2.1.13, 9.3.0.6, and 9.4.0.3, contain a relative p... |
| CVE-2022-22101 | MEDIUM | 5.5 | 0.1% | Sep 2, 2022 | Denial of service in multimedia due to uncontrolled resource consumption while parsing an incoming HAB message in Snapdr... |
| CVE-2022-38170 | MEDIUM | 4.7 | 0.6% | Sep 2, 2022 | In Apache Airflow prior to 2.3.4, an insecure umask was configured for numerous Airflow components when running with the... |
| CVE-2022-25370 | MEDIUM | 5.4 | 1.9% | Sep 2, 2022 | Apache OFBiz uses the Birt plugin (https://eclipse.github.io/birt-website/) to create data visualizations and reports. I... |
| CVE-2022-39194 | MEDIUM | 4.9 | 0.9% | Sep 2, 2022 | An issue was discovered in the MediaWiki through 1.38.2. The community configuration pages for the GrowthExperiments ext... |
| CVE-2022-39190 | MEDIUM | 5.5 | 0.3% | Sep 2, 2022 | An issue was discovered in net/netfilter/nf_tables_api.c in the Linux kernel before 5.19.6. A denial of service can occu... |
| CVE-2022-39188 | MEDIUM | 4.7 | 0.2% | Sep 2, 2022 | An issue was discovered in include/asm-generic/tlb.h in the Linux kernel before 5.19. Because of a race condition (unmap... |
| CVE-2022-37679 | MEDIUM | 4.8 | 0.4% | Sep 2, 2022 | Miniblog.Core v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /blog/edit. Thi... |
| CVE-2022-36637 | MEDIUM | 5.4 | 0.5% | Sep 2, 2022 | Garage Management System v1.0 was discovered to contain a persistent cross-site scripting (XSS) vulnerability via the br... |
| CVE-2022-36600 | MEDIUM | 4.8 | 0.4% | Sep 2, 2022 | BlogEngine v3.3.8.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /blogengine/ap... |
| CVE-2022-36593 | MEDIUM | 6.5 | 0.7% | Sep 2, 2022 | kkFileView v4.0.0 was discovered to contain an arbitrary file deletion vulnerability via the fileName parameter at /cont... |
| CVE-2022-3078 | MEDIUM | 5.5 | 0.2% | Sep 1, 2022 | An issue was discovered in the Linux kernel through 5.16-rc6. There is a lack of check after calling vzalloc() and lack ... |
| CVE-2022-2806 | MEDIUM | 5.5 | 0.2% | Sep 1, 2022 | It was found that the ovirt-log-collector/sosreport collects the RHV admin password unfiltered. Fixed in: sos-4.2-20.el8... |
| CVE-2022-2764 | MEDIUM | 4.9 | 0.8% | Sep 1, 2022 | A flaw was found in Undertow. Denial of service can be achieved as Undertow server waits for the LAST_CHUNK forever for ... |
| CVE-2022-2739 | MEDIUM | 5.3 | 0.4% | Sep 1, 2022 | The version of podman as released for Red Hat Enterprise Linux 7 Extras via RHSA-2022:2190 advisory included an incorrec... |
| CVE-2022-2663 | MEDIUM | 5.3 | 1.4% | Sep 1, 2022 | An issue was found in the Linux kernel in nf_conntrack_irc where the message handling can be confused and incorrectly ma... |
| CVE-2022-2447 | MEDIUM | 6.6 | 0.6% | Sep 1, 2022 | A flaw was found in Keystone. There is a time lag (up to one hour in a default configuration) between when security poli... |
| CVE-2022-2403 | MEDIUM | 6.5 | 0.5% | Sep 1, 2022 | A credentials leak was found in the OpenShift Container Platform. The private key for the external cluster certificate w... |
| CVE-2022-2308 | MEDIUM | 6.5 | 0.2% | Sep 1, 2022 | A flaw was found in vDPA with VDUSE backend. There are currently no checks in VDUSE kernel driver to ensure the size of ... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now