2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-24952 | MEDIUM | 6.5 | 1.3% | Aug 16, 2022 | Several denial of service vulnerabilities exist in Eternal Terminal prior to version 6.2.0, including a DoS triggered re... |
| CVE-2022-38358 | MEDIUM | 6.1 | 0.5% | Aug 15, 2022 | Improper neutralization of input during web page generation leaves the Eyes of Network web application vulnerable to cro... |
| CVE-2022-38191 | MEDIUM | 5.4 | 0.5% | Aug 15, 2022 | There is an HTML injection issue in Esri Portal for ArcGIS versions 10.9.0 and below which may allow a remote, authentic... |
| CVE-2022-38190 | MEDIUM | 6.1 | 0.5% | Aug 15, 2022 | A stored Cross Site Scripting (XSS) vulnerability in Esri Portal for ArcGIS configurable apps may allow a remote, unauth... |
| CVE-2022-38188 | MEDIUM | 6.1 | 0.5% | Aug 15, 2022 | There is a reflected XSS vulnerability in Esri Portal for ArcGIS versions 10.9.1 which may allow a remote attacker able ... |
| CVE-2022-38186 | MEDIUM | 6.1 | 0.5% | Aug 15, 2022 | There is a reflected XSS vulnerability in Esri Portal for ArcGIS versions 10.8.1 and below which may allow a remote atta... |
| CVE-2022-24654 | MEDIUM | 5.4 | 1.1% | Aug 15, 2022 | Authenticated stored cross-site scripting (XSS) vulnerability in "Field Server Address" field in INTELBRAS ATA 200 Firmw... |
| CVE-2022-2824 | MEDIUM | 5.4 | 0.6% | Aug 15, 2022 | Authorization Bypass Through User-Controlled Key in GitHub repository openemr/openemr prior to 7.0.0.1. |
| CVE-2022-33991 | MEDIUM | 5.3 | 0.8% | Aug 15, 2022 | dproxy-nexgen (aka dproxy nexgen) forwards and caches DNS queries with the CD (aka checking disabled) bit set to 1. This... |
| CVE-2022-33989 | MEDIUM | 5.3 | 0.8% | Aug 15, 2022 | dproxy-nexgen (aka dproxy nexgen) uses a static UDP source port (selected randomly only at boot time) in upstream querie... |
| CVE-2022-33993 | MEDIUM | 5.3 | 0.7% | Aug 15, 2022 | Misinterpretation of special domain name characters in DNRD (aka Domain Name Relay Daemon) 2.20.3 leads to cache poisoni... |
| CVE-2022-35961 | MEDIUM | 6.5 | 0.3% | Aug 15, 2022 | OpenZeppelin Contracts is a library for secure smart contract development. The functions `ECDSA.recover` and `ECDSA.tryR... |
| CVE-2022-35954 | MEDIUM | 5 | 0.6% | Aug 15, 2022 | The GitHub Actions ToolKit provides a set of packages to make creating actions easier. The `core.exportVariable` functio... |
| CVE-2022-35948 | MEDIUM | 5.3 | 1.2% | Aug 15, 2022 | undici is an HTTP/1.1 client, written from scratch for Node.js.`=< undici@5.8.0` users are vulnerable to _CRLF Injection... |
| CVE-2022-2814 | MEDIUM | 6.1 | 0.5% | Aug 15, 2022 | A vulnerability has been found in SourceCodester Simple and Nice Shopping Cart Script and classified as problematic. Aff... |
| CVE-2022-2811 | MEDIUM | 6.1 | 0.5% | Aug 15, 2022 | A vulnerability classified as problematic has been found in SourceCodester Guest Management System. This affects an unkn... |
| CVE-2022-2535 | MEDIUM | 5.3 | 1.5% | Aug 15, 2022 | The SearchWP Live Ajax Search WordPress plugin before 1.6.2 does not ensure that users making a live search are limited ... |
| CVE-2022-2384 | MEDIUM | 4.8 | 0.5% | Aug 15, 2022 | The Digital Publications by Supsystic WordPress plugin before 1.7.4 does not sanitise and escape its settings, allowing ... |
| CVE-2022-2378 | MEDIUM | 6.1 | 0.5% | Aug 15, 2022 | The Easy Student Results WordPress plugin through 2.2.8 does not sanitise and escape a parameter before outputting it ba... |
| CVE-2022-2152 | MEDIUM | 4.8 | 0.5% | Aug 15, 2022 | The Duplicate Page and Post WordPress plugin before 2.8 does not sanitise and escape its settings, allowing high privile... |
| CVE-2022-2116 | MEDIUM | 6.1 | 0.5% | Aug 15, 2022 | The Contact Form DB WordPress plugin before 1.8.0 does not sanitise and escape some parameters before outputting them ba... |
| CVE-2022-35953 | MEDIUM | 6.1 | 0.5% | Aug 12, 2022 | BookWyrm is a social network for tracking your reading, talking about books, writing reviews, and discovering what to re... |
| CVE-2022-38183 | MEDIUM | 6.5 | 0.7% | Aug 12, 2022 | In Gitea before 1.16.9, it was possible for users to add existing issues to projects. Due to improper access controls, a... |
| CVE-2022-2800 | MEDIUM | 6.1 | 0.5% | Aug 12, 2022 | A vulnerability, which was classified as problematic, has been found in SourceCodester Gym Management System. Affected b... |
| CVE-2022-2622 | MEDIUM | 6.5 | 0.6% | Aug 12, 2022 | Insufficient validation of untrusted input in Safe Browsing in Google Chrome on Windows prior to 104.0.5112.79 allowed a... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now