2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-2238MEDIUM6.5A vulnerability was found in the search-api container in Red Hat Advanced Cluster Management for Kubernetes when a query...
CVE-2022-23452MEDIUM4.9An authorization flaw was found in openstack-barbican, where anyone with an admin role could add secrets to a different ...
CVE-2022-1677MEDIUM6.3In OpenShift Container Platform, a user with permissions to create or modify Routes can craft a payload that inserts a m...
CVE-2022-1632MEDIUM6.5An Improper Certificate Validation attack was found in Openshift. A re-encrypt Route with destinationCACertificate expli...
CVE-2022-1615MEDIUM5.5In Samba, GnuTLS gnutls_rnd() can fail and give predictable random values.
CVE-2022-3061MEDIUM5.5Found Linux Kernel flaw in the i740 driver. The Userspace program could pass any values to the driver through ioctl() in...
CVE-2022-36583MEDIUM6.1DedeCMS V5.7.97 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities at /dede/co_do.php via the...
CVE-2022-36796MEDIUM6.1Cross-Site Request Forgery (CSRF) vulnerability leading to Stored Cross-Site Scripting (XSS) in CallRail, Inc. CallRail ...
CVE-2022-36355MEDIUM5.4Authenticated (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in PluginlySpeaking Easy Org Chart plugin <...
CVE-2022-28199MEDIUM6.5NVIDIA’s distribution of the Data Plane Development Kit (MLNX_DPDK) contains a vulnerability in the network stack, where...
CVE-2022-38790MEDIUM5.4Weave GitOps Enterprise before 0.9.0-rc.5 has a cross-site scripting (XSS) bug allowing a malicious user to inject a jav...
CVE-2022-36055MEDIUM6.5Helm is a tool for managing Charts. Charts are packages of pre-configured Kubernetes resources. Fuzz testing, provided b...
CVE-2022-3072MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository francoisjacquet/rosariosis prior to 8.9.3.
CVE-2022-36449MEDIUM6.5An issue was discovered in the Arm Mali GPU Kernel Driver. A non-privileged user can make improper GPU processing operat...
CVE-2022-36203MEDIUM6.1Doctor's Appointment System 1.0 is vulnerable to Cross Site Scripting (XSS) via the admin panel. In addition, it leads t...
CVE-2022-2898MEDIUM5.5Measuresoft ScadaPro Server and Client (All Versions) do not properly resolve links before file access; this could allow...
CVE-2022-36048MEDIUM4.3Zulip is an open-source team collaboration tool with topic-based threading that combines email and chat. When displaying...
CVE-2022-1841MEDIUM5.3In subsys/net/ip/tcp.c , function tcp_flags , when the incoming parameter flags is ECN or CWR , the buf will out-of-boun...
CVE-2022-36046MEDIUM5.3Next.js is a React framework that can provide building blocks to create web applications. All of the following must be t...
CVE-2022-38812MEDIUM6.5AeroCMS 0.1.1 is vulnerable to SQL Injection via the author parameter.
CVE-2022-38153MEDIUM5.9An issue was discovered in wolfSSL before 5.5.0 (when --enable-session-ticket is used); however, only version 5.3.0 is e...
CVE-2022-37183MEDIUM6.1Piwigo 12.3.0 is vulnerable to Cross Site Scripting (XSS) via /search/1940/created-monthly-list.
CVE-2022-2758MEDIUM5.9Passwords are not adequately encrypted during the communication process between all versions of LS Industrial Systems (L...
CVE-2022-2521MEDIUM6.5It was found in libtiff 4.4.0rc1 that there is an invalid pointer free operation in TIFFClose() at tif_close.c:131 calle...
CVE-2022-2520MEDIUM6.5A flaw was found in libtiff 4.4.0rc1. There is a sysmalloc assertion fail in rotateImage() at tiffcrop.c:8621 that can c...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now