2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-34338MEDIUM6.5IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 could disclose sensitive information due to improper privilege...
CVE-2022-33169MEDIUM6.5IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 is vulnerable to insufficiently protected credentials for user...
CVE-2022-32750MEDIUM5.4IBM DataPower Gateway 10.0.2.0 through 10.0.4.0, 10.0.1.0 through 10.0.1.8, 10.5.0.0, and 2018.4.1.0 through 2018.4.1.21...
CVE-2022-31774MEDIUM5.4IBM DataPower Gateway 10.0.2.0 through 10.0.4.0, 10.0.1.0 through 10.0.1.8, 10.5.0.0, and 2018.4.1.0 through 2018.4.1.21...
CVE-2022-22334MEDIUM4.3IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 could allow a user to access information from a tenant of whic...
CVE-2022-34526MEDIUM6.5A stack overflow was discovered in the _TIFFVGetField function of Tiffsplit v4.4.0. This vulnerability allows attackers ...
CVE-2022-36378MEDIUM4.8Authenticated (author or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in PluginlySpeaking Floating ...
CVE-2022-23004MEDIUM5.3When computing a shared secret or point multiplication on the NIST P-256 curve using a public key with an X coordinate o...
CVE-2022-23003MEDIUM5.3When computing a shared secret or point multiplication on the NIST P-256 curve that results in an X coordinate of zero, ...
CVE-2022-23002MEDIUM5.3When compressing or decompressing a point on the NIST P-256 elliptic curve with an X coordinate of zero, the resulting o...
CVE-2022-23001MEDIUM5.3When compressing or decompressing elliptic curve points using the Sweet B library, an incorrect choice of sign bit is us...
CVE-2022-35632MEDIUM4.8The Velociraptor GUI contains an editor suggestion feature that can display the description field of a VQL function, plu...
CVE-2022-35631MEDIUM5.5On MacOS and Linux, it may be possible to perform a symlink attack by replacing this predictable file name with a symlin...
CVE-2022-35630MEDIUM6.1A cross-site scripting (XSS) issue in generating a collection report made it possible for malicious clients to inject Ja...
CVE-2022-35629MEDIUM5.4Due to a bug in the handling of the communication between the client and server, it was possible for one client, already...
CVE-2022-2579MEDIUM5.4A vulnerability, which was classified as problematic, was found in SourceCodester Garage Management System 1.0. Affected...
CVE-2022-36752MEDIUM5.5png2webp v1.0.4 was discovered to contain an out-of-bounds write via the function w2p. This vulnerability is exploitable...
CVE-2022-34556MEDIUM5.5PicoC v3.2.2 was discovered to contain a NULL pointer dereference at variable.c.
CVE-2022-34580MEDIUM4.8Advanced School Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the addr...
CVE-2022-29360MEDIUM5.4The Email Viewer in RainLoop through 1.6.0 allows XSS via a crafted email message.
CVE-2022-30320MEDIUM4.3Saia Burgess Controls (SBC) PCD through 2022-05-06 uses a Broken or Risky Cryptographic Algorithm. According to FSCT-202...
CVE-2022-30316MEDIUM6.8Honeywell Experion PKS Safety Manager 5.02 has Insufficient Verification of Data Authenticity. According to FSCT-2022-00...
CVE-2022-30314MEDIUM4.6Honeywell Experion PKS Safety Manager 5.02 uses Hard-coded Credentials. According to FSCT-2022-0052, there is a Honeywel...
CVE-2022-35882MEDIUM4.8Authenticated (author or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in GS Plugins GS Testimonial ...
CVE-2022-2553MEDIUM6.5The authfile directive in the booth config file is ignored, preventing use of authentication in communications from node...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now