2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-34338 | MEDIUM | 6.5 | 0.5% | Aug 1, 2022 | IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 could disclose sensitive information due to improper privilege... |
| CVE-2022-33169 | MEDIUM | 6.5 | 0.5% | Aug 1, 2022 | IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 is vulnerable to insufficiently protected credentials for user... |
| CVE-2022-32750 | MEDIUM | 5.4 | 0.4% | Aug 1, 2022 | IBM DataPower Gateway 10.0.2.0 through 10.0.4.0, 10.0.1.0 through 10.0.1.8, 10.5.0.0, and 2018.4.1.0 through 2018.4.1.21... |
| CVE-2022-31774 | MEDIUM | 5.4 | 0.4% | Aug 1, 2022 | IBM DataPower Gateway 10.0.2.0 through 10.0.4.0, 10.0.1.0 through 10.0.1.8, 10.5.0.0, and 2018.4.1.0 through 2018.4.1.21... |
| CVE-2022-22334 | MEDIUM | 4.3 | 0.4% | Aug 1, 2022 | IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 could allow a user to access information from a tenant of whic... |
| CVE-2022-34526 | MEDIUM | 6.5 | 1.4% | Jul 29, 2022 | A stack overflow was discovered in the _TIFFVGetField function of Tiffsplit v4.4.0. This vulnerability allows attackers ... |
| CVE-2022-36378 | MEDIUM | 4.8 | 0.4% | Jul 29, 2022 | Authenticated (author or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in PluginlySpeaking Floating ... |
| CVE-2022-23004 | MEDIUM | 5.3 | 0.6% | Jul 29, 2022 | When computing a shared secret or point multiplication on the NIST P-256 curve using a public key with an X coordinate o... |
| CVE-2022-23003 | MEDIUM | 5.3 | 0.6% | Jul 29, 2022 | When computing a shared secret or point multiplication on the NIST P-256 curve that results in an X coordinate of zero, ... |
| CVE-2022-23002 | MEDIUM | 5.3 | 0.6% | Jul 29, 2022 | When compressing or decompressing a point on the NIST P-256 elliptic curve with an X coordinate of zero, the resulting o... |
| CVE-2022-23001 | MEDIUM | 5.3 | 0.6% | Jul 29, 2022 | When compressing or decompressing elliptic curve points using the Sweet B library, an incorrect choice of sign bit is us... |
| CVE-2022-35632 | MEDIUM | 4.8 | 0.4% | Jul 29, 2022 | The Velociraptor GUI contains an editor suggestion feature that can display the description field of a VQL function, plu... |
| CVE-2022-35631 | MEDIUM | 5.5 | 0.2% | Jul 29, 2022 | On MacOS and Linux, it may be possible to perform a symlink attack by replacing this predictable file name with a symlin... |
| CVE-2022-35630 | MEDIUM | 6.1 | 0.4% | Jul 29, 2022 | A cross-site scripting (XSS) issue in generating a collection report made it possible for malicious clients to inject Ja... |
| CVE-2022-35629 | MEDIUM | 5.4 | 0.4% | Jul 29, 2022 | Due to a bug in the handling of the communication between the client and server, it was possible for one client, already... |
| CVE-2022-2579 | MEDIUM | 5.4 | 0.5% | Jul 29, 2022 | A vulnerability, which was classified as problematic, was found in SourceCodester Garage Management System 1.0. Affected... |
| CVE-2022-36752 | MEDIUM | 5.5 | 0.4% | Jul 28, 2022 | png2webp v1.0.4 was discovered to contain an out-of-bounds write via the function w2p. This vulnerability is exploitable... |
| CVE-2022-34556 | MEDIUM | 5.5 | 0.3% | Jul 28, 2022 | PicoC v3.2.2 was discovered to contain a NULL pointer dereference at variable.c. |
| CVE-2022-34580 | MEDIUM | 4.8 | 0.4% | Jul 28, 2022 | Advanced School Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the addr... |
| CVE-2022-29360 | MEDIUM | 5.4 | 1.0% | Jul 28, 2022 | The Email Viewer in RainLoop through 1.6.0 allows XSS via a crafted email message. |
| CVE-2022-30320 | MEDIUM | 4.3 | 0.2% | Jul 28, 2022 | Saia Burgess Controls (SBC) PCD through 2022-05-06 uses a Broken or Risky Cryptographic Algorithm. According to FSCT-202... |
| CVE-2022-30316 | MEDIUM | 6.8 | 0.3% | Jul 28, 2022 | Honeywell Experion PKS Safety Manager 5.02 has Insufficient Verification of Data Authenticity. According to FSCT-2022-00... |
| CVE-2022-30314 | MEDIUM | 4.6 | 0.3% | Jul 28, 2022 | Honeywell Experion PKS Safety Manager 5.02 uses Hard-coded Credentials. According to FSCT-2022-0052, there is a Honeywel... |
| CVE-2022-35882 | MEDIUM | 4.8 | 0.4% | Jul 28, 2022 | Authenticated (author or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in GS Plugins GS Testimonial ... |
| CVE-2022-2553 | MEDIUM | 6.5 | 0.9% | Jul 28, 2022 | The authfile directive in the booth config file is ignored, preventing use of authentication in communications from node... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now