2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-2238 | MEDIUM | 6.5 | 0.8% | Sep 1, 2022 | A vulnerability was found in the search-api container in Red Hat Advanced Cluster Management for Kubernetes when a query... |
| CVE-2022-23452 | MEDIUM | 4.9 | 1.0% | Sep 1, 2022 | An authorization flaw was found in openstack-barbican, where anyone with an admin role could add secrets to a different ... |
| CVE-2022-1677 | MEDIUM | 6.3 | 0.5% | Sep 1, 2022 | In OpenShift Container Platform, a user with permissions to create or modify Routes can craft a payload that inserts a m... |
| CVE-2022-1632 | MEDIUM | 6.5 | 0.3% | Sep 1, 2022 | An Improper Certificate Validation attack was found in Openshift. A re-encrypt Route with destinationCACertificate expli... |
| CVE-2022-1615 | MEDIUM | 5.5 | 0.4% | Sep 1, 2022 | In Samba, GnuTLS gnutls_rnd() can fail and give predictable random values. |
| CVE-2022-3061 | MEDIUM | 5.5 | 0.3% | Sep 1, 2022 | Found Linux Kernel flaw in the i740 driver. The Userspace program could pass any values to the driver through ioctl() in... |
| CVE-2022-36583 | MEDIUM | 6.1 | 0.5% | Sep 1, 2022 | DedeCMS V5.7.97 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities at /dede/co_do.php via the... |
| CVE-2022-36796 | MEDIUM | 6.1 | 0.3% | Sep 1, 2022 | Cross-Site Request Forgery (CSRF) vulnerability leading to Stored Cross-Site Scripting (XSS) in CallRail, Inc. CallRail ... |
| CVE-2022-36355 | MEDIUM | 5.4 | 0.4% | Sep 1, 2022 | Authenticated (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in PluginlySpeaking Easy Org Chart plugin <... |
| CVE-2022-28199 | MEDIUM | 6.5 | 1.8% | Sep 1, 2022 | NVIDIA’s distribution of the Data Plane Development Kit (MLNX_DPDK) contains a vulnerability in the network stack, where... |
| CVE-2022-38790 | MEDIUM | 5.4 | 0.6% | Sep 1, 2022 | Weave GitOps Enterprise before 0.9.0-rc.5 has a cross-site scripting (XSS) bug allowing a malicious user to inject a jav... |
| CVE-2022-36055 | MEDIUM | 6.5 | 0.8% | Sep 1, 2022 | Helm is a tool for managing Charts. Charts are packages of pre-configured Kubernetes resources. Fuzz testing, provided b... |
| CVE-2022-3072 | MEDIUM | 5.4 | 0.7% | Sep 1, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository francoisjacquet/rosariosis prior to 8.9.3. |
| CVE-2022-36449 | MEDIUM | 6.5 | 0.9% | Sep 1, 2022 | An issue was discovered in the Arm Mali GPU Kernel Driver. A non-privileged user can make improper GPU processing operat... |
| CVE-2022-36203 | MEDIUM | 6.1 | 0.7% | Aug 31, 2022 | Doctor's Appointment System 1.0 is vulnerable to Cross Site Scripting (XSS) via the admin panel. In addition, it leads t... |
| CVE-2022-2898 | MEDIUM | 5.5 | 0.2% | Aug 31, 2022 | Measuresoft ScadaPro Server and Client (All Versions) do not properly resolve links before file access; this could allow... |
| CVE-2022-36048 | MEDIUM | 4.3 | 0.5% | Aug 31, 2022 | Zulip is an open-source team collaboration tool with topic-based threading that combines email and chat. When displaying... |
| CVE-2022-1841 | MEDIUM | 5.3 | 0.5% | Aug 31, 2022 | In subsys/net/ip/tcp.c , function tcp_flags , when the incoming parameter flags is ECN or CWR , the buf will out-of-boun... |
| CVE-2022-36046 | MEDIUM | 5.3 | 1.0% | Aug 31, 2022 | Next.js is a React framework that can provide building blocks to create web applications. All of the following must be t... |
| CVE-2022-38812 | MEDIUM | 6.5 | 2.1% | Aug 31, 2022 | AeroCMS 0.1.1 is vulnerable to SQL Injection via the author parameter. |
| CVE-2022-38153 | MEDIUM | 5.9 | 1.7% | Aug 31, 2022 | An issue was discovered in wolfSSL before 5.5.0 (when --enable-session-ticket is used); however, only version 5.3.0 is e... |
| CVE-2022-37183 | MEDIUM | 6.1 | 0.6% | Aug 31, 2022 | Piwigo 12.3.0 is vulnerable to Cross Site Scripting (XSS) via /search/1940/created-monthly-list. |
| CVE-2022-2758 | MEDIUM | 5.9 | 0.3% | Aug 31, 2022 | Passwords are not adequately encrypted during the communication process between all versions of LS Industrial Systems (L... |
| CVE-2022-2521 | MEDIUM | 6.5 | 0.9% | Aug 31, 2022 | It was found in libtiff 4.4.0rc1 that there is an invalid pointer free operation in TIFFClose() at tif_close.c:131 calle... |
| CVE-2022-2520 | MEDIUM | 6.5 | 0.9% | Aug 31, 2022 | A flaw was found in libtiff 4.4.0rc1. There is a sysmalloc assertion fail in rotateImage() at tiffcrop.c:8621 that can c... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now