2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-34618 | MEDIUM | 5.4 | 0.7% | Aug 2, 2022 | A stored cross-site scripting (XSS) vulnerability in Mealie 1.0.0beta3 allows attackers to execute arbitrary web scripts... |
| CVE-2022-35921 | MEDIUM | 4.3 | 0.4% | Aug 1, 2022 | fof/byobu is a private discussions extension for Flarum forum. Affected versions were found to not respect private discu... |
| CVE-2022-35918 | MEDIUM | 6.5 | 1.3% | Aug 1, 2022 | Streamlit is a data oriented application development framework for python. Users hosting Streamlit app(s) that use custo... |
| CVE-2022-35917 | MEDIUM | 5.3 | 0.6% | Aug 1, 2022 | Solana Pay is a protocol and set of reference implementations that enable developers to incorporate decentralized paymen... |
| CVE-2022-35916 | MEDIUM | 5.3 | 0.5% | Aug 1, 2022 | OpenZeppelin Contracts is a library for secure smart contract development. Contracts using the cross chain utilities for... |
| CVE-2022-35915 | MEDIUM | 5.3 | 0.6% | Aug 1, 2022 | OpenZeppelin Contracts is a library for secure smart contract development. The target contract of an EIP-165 `supportsIn... |
| CVE-2022-31193 | MEDIUM | 6.1 | 0.6% | Aug 1, 2022 | DSpace open source software is a repository application which provides durable access to digital resources. dspace-jspui... |
| CVE-2022-31192 | MEDIUM | 6.1 | 0.6% | Aug 1, 2022 | DSpace open source software is a repository application which provides durable access to digital resources. dspace-jspui... |
| CVE-2022-31191 | MEDIUM | 6.1 | 0.6% | Aug 1, 2022 | DSpace open source software is a repository application which provides durable access to digital resources. dspace-jspui... |
| CVE-2022-31189 | MEDIUM | 5.3 | 0.6% | Aug 1, 2022 | DSpace open source software is a repository application which provides durable access to digital resources. dspace-jspui... |
| CVE-2022-35118 | MEDIUM | 6.1 | 0.4% | Aug 1, 2022 | PyroCMS v3.9 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities. |
| CVE-2022-34530 | MEDIUM | 5.3 | 0.5% | Aug 1, 2022 | An issue in the login and reset password functionality of Backdrop CMS v1.22.0 allows attackers to enumerate usernames v... |
| CVE-2022-31190 | MEDIUM | 5.3 | 0.7% | Aug 1, 2022 | DSpace open source software is a repository application which provides durable access to digital resources. dspace-xmlui... |
| CVE-2022-31185 | MEDIUM | 5.3 | 0.5% | Aug 1, 2022 | mprweb is a hosting platform for the makedeb Package Repository. Email addresses were found to not have been hidden, eve... |
| CVE-2022-31182 | MEDIUM | 5.3 | 0.6% | Aug 1, 2022 | Discourse is the an open source discussion platform. In affected versions a maliciously crafted request for static asset... |
| CVE-2022-31178 | MEDIUM | 4.3 | 0.4% | Aug 1, 2022 | eLabFTW is an electronic lab notebook manager for research teams. A vulnerability was discovered which allows a logged i... |
| CVE-2022-31155 | MEDIUM | 4.3 | 0.4% | Aug 1, 2022 | Sourcegraph is an opensource code search and navigation engine. In Sourcegraph versions before 3.41.0, it is possible fo... |
| CVE-2022-31154 | MEDIUM | 4.3 | 0.4% | Aug 1, 2022 | Sourcegraph is an opensource code search and navigation engine. It is possible for an authenticated Sourcegraph user to ... |
| CVE-2022-31148 | MEDIUM | 5.4 | 0.5% | Aug 1, 2022 | Shopware is an open source e-commerce software. In versions from 5.7.0 a persistent cross site scripting (XSS) vulnerabi... |
| CVE-2022-31128 | MEDIUM | 5.4 | 0.5% | Aug 1, 2022 | Tuleap is a Free & Open Source Suite to improve management of software developments and collaboration. In affected versi... |
| CVE-2022-31109 | MEDIUM | 6.1 | 0.6% | Aug 1, 2022 | laminas-diactoros is a PHP package containing implementations of the PSR-7 HTTP message interfaces and PSR-17 HTTP messa... |
| CVE-2022-34307 | MEDIUM | 4.3 | 0.4% | Aug 1, 2022 | IBM CICS TX 11.1 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to ... |
| CVE-2022-34164 | MEDIUM | 5.5 | 0.2% | Aug 1, 2022 | IBM CICS TX 11.1 could allow a local user to impersonate another legitimate user due to improper input validation. IBM X... |
| CVE-2022-34163 | MEDIUM | 6.1 | 0.6% | Aug 1, 2022 | IBM CICS TX 11.1 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. Thi... |
| CVE-2022-34162 | MEDIUM | 6.1 | 0.7% | Aug 1, 2022 | IBM CICS TX 11.1 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to vi... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now