2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-2303 | MEDIUM | 4.3 | 0.6% | Aug 5, 2022 | An issue has been discovered in GitLab CE/EE affecting all versions before 15.0.5, all versions starting from 15.1 befor... |
| CVE-2022-2095 | MEDIUM | 4.3 | 0.7% | Aug 5, 2022 | An improper access control check in GitLab CE/EE affecting all versions starting from 13.7 before 15.0.5, all versions s... |
| CVE-2022-35936 | MEDIUM | 5.3 | 1.1% | Aug 5, 2022 | Ethermint is an Ethereum library. In Ethermint running versions before `v0.17.2`, the contract `selfdestruct` invocation... |
| CVE-2022-37431 | MEDIUM | 6.1 | 0.6% | Aug 5, 2022 | A Reflected Cross-site scripting (XSS) issue was discovered in dotCMS Core through 22.06. This occurs in the admin porta... |
| CVE-2022-37416 | MEDIUM | 6.5 | 0.8% | Aug 5, 2022 | Ittiam libmpeg2 before 2022-07-27 uses memcpy with overlapping memory blocks in impeg2_mc_fullx_fully_8x8. |
| CVE-2022-35144 | MEDIUM | 4.8 | 0.7% | Aug 4, 2022 | Renato v0.17.0 was discovered to contain a cross-site scripting (XSS) vulnerability. |
| CVE-2022-35272 | MEDIUM | 5.5 | 0.4% | Aug 4, 2022 | In BIG-IP Versions 17.0.x before 17.0.0.1 and 16.1.x before 16.1.3.1, when source-port preserve-strict is configured on ... |
| CVE-2022-35241 | MEDIUM | 6.5 | 0.6% | Aug 4, 2022 | In versions 2.x before 2.3.1 and all versions of 1.x, when NGINX Instance Manager is in use, undisclosed requests can ca... |
| CVE-2022-34851 | MEDIUM | 6.5 | 0.6% | Aug 4, 2022 | In BIG-IP Versions 17.0.x before 17.0.0.1, 16.1.x before 16.1.3.1, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5.1, and a... |
| CVE-2022-33968 | MEDIUM | 4.9 | 0.4% | Aug 4, 2022 | In BIG-IP Versions 17.0.x before 17.0.0.1, 16.1.x before 16.1.3.1, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5.1, and a... |
| CVE-2022-33962 | MEDIUM | 6.7 | 0.2% | Aug 4, 2022 | In BIG-IP Versions 17.0.x before 17.0.0.1, 16.1.x before 16.1.3.1, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5.1, and a... |
| CVE-2022-33947 | MEDIUM | 6.5 | 0.6% | Aug 4, 2022 | In BIG-IP Versions 16.1.x before 16.1.3, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5, and all versions of 13.1.x, a vul... |
| CVE-2022-31119 | MEDIUM | 4.9 | 0.6% | Aug 4, 2022 | Nextcloud Mail is an email application for the nextcloud personal cloud product. Affected versions of Nextcloud mail wou... |
| CVE-2022-30535 | MEDIUM | 6.5 | 0.6% | Aug 4, 2022 | In versions 2.x before 2.3.0 and all versions of 1.x, An attacker authorized to create or update ingress objects can obt... |
| CVE-2022-31118 | MEDIUM | 5.3 | 0.6% | Aug 4, 2022 | Nextcloud server is an open source personal cloud solution. In affected versions an attacker could brute force to find i... |
| CVE-2022-2653 | MEDIUM | 6.5 | 0.8% | Aug 4, 2022 | With this vulnerability an attacker can read many sensitive files like configuration files, or the /proc/self/environ fi... |
| CVE-2022-2652 | MEDIUM | 6 | 0.3% | Aug 4, 2022 | Depending on the way the format strings in the card label are crafted it's possible to leak kernel stack memory. There i... |
| CVE-2022-2646 | MEDIUM | 6.1 | 0.5% | Aug 4, 2022 | A vulnerability, which was classified as problematic, was found in SourceCodester Online Admission System. Affected is a... |
| CVE-2022-2645 | MEDIUM | 6.1 | 0.4% | Aug 4, 2022 | A vulnerability has been found in SourceCodester Garage Management System and classified as problematic. Affected by thi... |
| CVE-2022-28732 | MEDIUM | 6.1 | 85.7% | Aug 4, 2022 | A carefully crafted request on WeblogPlugin could trigger an XSS vulnerability on Apache JSPWiki, which could allow the ... |
| CVE-2022-28731 | MEDIUM | 6.5 | 56.3% | Aug 4, 2022 | A carefully crafted request on UserPreferences.jsp could trigger an CSRF vulnerability on Apache JSPWiki before 2.11.3, ... |
| CVE-2022-28730 | MEDIUM | 6.1 | 85.3% | Aug 4, 2022 | A carefully crafted request on AJAXPreview.jsp could trigger an XSS vulnerability on Apache JSPWiki, which could allow t... |
| CVE-2022-27166 | MEDIUM | 6.1 | 85.3% | Aug 4, 2022 | A carefully crafted request on XHRHtml2Markup.jsp could trigger an XSS vulnerability on Apache JSPWiki up to and includi... |
| CVE-2022-35928 | MEDIUM | 5.5 | 0.2% | Aug 3, 2022 | AES Crypt is a file encryption software for multiple platforms. AES Crypt for Linux built using the source on GitHub and... |
| CVE-2022-27551 | MEDIUM | 6.5 | 0.4% | Aug 3, 2022 | HCL Launch could allow an authenticated user to obtain sensitive information in some instances due to improper security ... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now