2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-31175 | MEDIUM | 4.7 | 0.6% | Aug 3, 2022 | CKEditor 5 is a JavaScript rich text editor. A cross-site scripting vulnerability has been discovered affecting three op... |
| CVE-2022-35867 | MEDIUM | 6.7 | 0.3% | Aug 3, 2022 | This vulnerability allows local attackers to escalate privileges on affected installations of xhyve. An attacker must fi... |
| CVE-2022-35864 | MEDIUM | 6.5 | 1.3% | Aug 3, 2022 | This vulnerability allows remote attackers to disclose sensitive information on affected installations of BMC Track-It! ... |
| CVE-2022-34872 | MEDIUM | 6.5 | 1.8% | Aug 3, 2022 | This vulnerability allows remote attackers to disclose sensitive information on affected installations of Centreon. Auth... |
| CVE-2022-27484 | MEDIUM | 4.3 | 0.4% | Aug 3, 2022 | A unverified password change in Fortinet FortiADC version 6.2.0 through 6.2.3, 6.1.x, 6.0.x, 5.x.x allows an authenticat... |
| CVE-2022-23442 | MEDIUM | 4.3 | 0.5% | Aug 3, 2022 | An improper access control vulnerability [CWE-284] in FortiOS versions 6.2.0 through 6.2.11, 6.4.0 through 6.4.8 and 7.0... |
| CVE-2022-36800 | MEDIUM | 4.3 | 0.5% | Aug 3, 2022 | Affected versions of Atlassian Jira Service Management Server and Data Center allow remote attackers without the "Browse... |
| CVE-2022-27620 | MEDIUM | 4.9 | 1.2% | Aug 3, 2022 | Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in webapi component in Syno... |
| CVE-2022-27619 | MEDIUM | 5.9 | 0.3% | Aug 3, 2022 | Cleartext transmission of sensitive information vulnerability in authentication management in Synology Note Station Clie... |
| CVE-2022-27618 | MEDIUM | 6.5 | 1.2% | Aug 3, 2022 | Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in webapi component in Syno... |
| CVE-2022-27617 | MEDIUM | 4.3 | 0.8% | Aug 3, 2022 | Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in webapi component in Syno... |
| CVE-2022-36197 | MEDIUM | 5.4 | 0.5% | Aug 3, 2022 | BigTree CMS 4.4.16 was discovered to contain an arbitrary file upload vulnerability which allows attackers to execute ar... |
| CVE-2022-33917 | MEDIUM | 5.5 | 0.4% | Aug 2, 2022 | An issue was discovered in the Arm Mali GPU Kernel Driver (Valhall r29p0 through r38p0). A non-privileged user can make ... |
| CVE-2022-36968 | MEDIUM | 4.3 | 0.2% | Aug 2, 2022 | In Progress WS_FTP Server prior to version 8.7.3, forms within the administrative interface did not include a nonce to m... |
| CVE-2022-36967 | MEDIUM | 6.1 | 0.6% | Aug 2, 2022 | In Progress WS_FTP Server prior to version 8.7.3, multiple reflected cross-site scripting (XSS) vulnerabilities exist in... |
| CVE-2022-34619 | MEDIUM | 5.4 | 0.7% | Aug 2, 2022 | A stored cross-site scripting (XSS) vulnerability in Mealie v0.5.5 allows attackers to execute arbitrary web scripts or ... |
| CVE-2022-30572 | MEDIUM | 6.5 | 1.0% | Aug 2, 2022 | The iWay Service Manager Console component of TIBCO Software Inc.'s TIBCO iWay Service Manager contains an easily exploi... |
| CVE-2022-30571 | MEDIUM | 5.4 | 0.4% | Aug 2, 2022 | The iWay Service Manager Console component of TIBCO Software Inc.'s TIBCO iWay Service Manager contains easily exploitab... |
| CVE-2022-35222 | MEDIUM | 6.8 | 0.3% | Aug 2, 2022 | HiCOS Citizen verification component has a stack-based buffer overflow vulnerability due to insufficient parameter lengt... |
| CVE-2022-35221 | MEDIUM | 5.4 | 0.7% | Aug 2, 2022 | Teamplus Pro community discussion has an ‘allocation of resource without limits or throttling’ vulnerability on thread s... |
| CVE-2022-35220 | MEDIUM | 6.5 | 0.8% | Aug 2, 2022 | Teamplus Pro community discussion function has an ‘allocation of resource without limits or throttling’ vulnerability. A... |
| CVE-2022-35219 | MEDIUM | 5.5 | 0.2% | Aug 2, 2022 | The NHI card’s web service component has a stack-based buffer overflow vulnerability due to insufficient validation for ... |
| CVE-2022-35218 | MEDIUM | 5.5 | 0.2% | Aug 2, 2022 | The NHI card’s web service component has a heap-based buffer overflow vulnerability due to insufficient validation for p... |
| CVE-2022-23733 | MEDIUM | 5.4 | 0.5% | Aug 2, 2022 | A stored XSS vulnerability was identified in GitHub Enterprise Server that allowed the injection of arbitrary attributes... |
| CVE-2022-1293 | MEDIUM | 6.1 | 0.4% | Aug 2, 2022 | The embedded neutralization of Script-Related HTML Tag, was by-passed in the case of some extra conditions. |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now