2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-36116 | MEDIUM | 5.3 | 0.7% | Aug 25, 2022 | An issue was discovered in Blue Prism Enterprise 6.0 through 7.01. In a misconfigured environment that exposes the Blue ... |
| CVE-2022-31798 | MEDIUM | 6.1 | 6.7% | Aug 25, 2022 | Nortek Linear eMerge E3-Series 0.32-07p devices are vulnerable to /card_scan.php?CardFormatNo= XSS with session fixation... |
| CVE-2022-2980 | MEDIUM | 5.5 | 0.7% | Aug 25, 2022 | NULL Pointer Dereference in GitHub repository vim/vim prior to 9.0.0259. |
| CVE-2022-36527 | MEDIUM | 5.4 | 0.4% | Aug 25, 2022 | Jfinal CMS v5.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the post... |
| CVE-2022-20865 | MEDIUM | 6.7 | 0.3% | Aug 25, 2022 | A vulnerability in the CLI of Cisco FXOS Software could allow an authenticated, local attacker to inject arbitrary comma... |
| CVE-2022-37953 | MEDIUM | 6.1 | 0.3% | Aug 25, 2022 | An HTTP response splitting vulnerability exists in the AM Gateway Challenge-Response dialog of WorkstationST (<v07.09.15... |
| CVE-2022-37952 | MEDIUM | 6.1 | 0.3% | Aug 25, 2022 | A reflected cross-site scripting (XSS) vulnerability exists in the iHistorian Data Display of WorkstationST (<v07.09.15)... |
| CVE-2022-36358 | MEDIUM | 4.3 | 0.2% | Aug 25, 2022 | Cross-Site Request Forgery (CSRF) vulnerability in SEO Scout plugin <= 0.9.83 at WordPress allows attackers to trick use... |
| CVE-2022-32746 | MEDIUM | 5.4 | 1.1% | Aug 25, 2022 | A flaw was found in the Samba AD LDAP server. The AD DC database audit logging module can access LDAP message values fre... |
| CVE-2022-32742 | MEDIUM | 4.3 | 1.0% | Aug 25, 2022 | A flaw was found in Samba. Some SMB1 write requests were not correctly range-checked to ensure the client had sent enoug... |
| CVE-2022-2991 | MEDIUM | 6.7 | 0.4% | Aug 25, 2022 | A heap-based buffer overflow was found in the Linux kernel's LightNVM subsystem. The issue results from the lack of prop... |
| CVE-2022-23715 | MEDIUM | 6.5 | 0.7% | Aug 25, 2022 | A flaw was discovered in ECE before 3.4.0 that might lead to the disclosure of sensitive information such as user passwo... |
| CVE-2022-23235 | MEDIUM | 5.3 | 0.5% | Aug 25, 2022 | Active IQ Unified Manager for VMware vSphere, Linux, and Microsoft Windows versions prior to 9.10P1 are susceptible to a... |
| CVE-2022-37162 | MEDIUM | 5.4 | 0.6% | Aug 25, 2022 | Claroline 13.5.7 and prior is vulnerable to Cross Site Scripting (XSS). An attacker can obtain javascript code execution... |
| CVE-2022-37161 | MEDIUM | 6.1 | 0.5% | Aug 25, 2022 | Claroline 13.5.7 and prior is vulnerable to Cross Site Scripting (XSS) via SVG file upload. |
| CVE-2022-37160 | MEDIUM | 5.4 | 0.5% | Aug 25, 2022 | Claroline 13.5.7 and prior allows an authenticated attacker to elevate privileges via the arbitrary creation of a privil... |
| CVE-2022-37292 | MEDIUM | 5.5 | 0.3% | Aug 25, 2022 | Tenda AX12 V22.03.01.21_CN is vulnerable to Buffer Overflow. This overflow is triggered in the sub_42FDE4 function, whic... |
| CVE-2022-37238 | MEDIUM | 5.4 | 0.5% | Aug 25, 2022 | MDaemon Technologies SecurityGateway for Email Servers 8.5.2 is vulnerable to Cross Site Scripting (XSS) via the current... |
| CVE-2022-37245 | MEDIUM | 5.4 | 0.5% | Aug 25, 2022 | MDaemon Technologies SecurityGateway for Email Servers 8.5.2 is vulnerable to Cross Site Scripting (XSS) via the Blackli... |
| CVE-2022-37244 | MEDIUM | 5.4 | 0.5% | Aug 25, 2022 | MDaemon Technologies SecurityGateway for Email Servers 8.5.2 is vulnerable to IFRAME Injectionvia the currentRequest par... |
| CVE-2022-37243 | MEDIUM | 5.4 | 0.5% | Aug 25, 2022 | MDaemon Technologies SecurityGateway for Email Servers 8.5.2 is vulnerable to Cross Site Scripting (XSS) via the whiteli... |
| CVE-2022-37241 | MEDIUM | 5.4 | 0.5% | Aug 25, 2022 | MDaemon Technologies SecurityGateway for Email Servers 8.5.2 is vulnerable to Cross Site Scripting (XSS) via the data_le... |
| CVE-2022-37239 | MEDIUM | 5.4 | 0.5% | Aug 25, 2022 | MDaemon Technologies SecurityGateway for Email Servers 8.5.2 is vulnerable to Cross Site Scripting (XSS) via the rulles_... |
| CVE-2022-32857 | MEDIUM | 4.3 | 0.2% | Aug 24, 2022 | This issue was addressed by using HTTPS when sending information over the network. This issue is fixed in macOS Monterey... |
| CVE-2022-32838 | MEDIUM | 5.5 | 0.5% | Aug 24, 2022 | A logic issue was addressed with improved state management. This issue is fixed in macOS Monterey 12.5, macOS Big Sur 11... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now