2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-2042 | HIGH | 7.8 | 1.4% | Jun 10, 2022 | Use After Free in GitHub repository vim/vim prior to 8.2. |
| CVE-2022-22479 | HIGH | 8.8 | 0.3% | Jun 10, 2022 | IBM Spectrum Copy Data Management 2.2.0.0through 2.2.15.0 is vulnerable to cross-site request forgery which could allow ... |
| CVE-2022-27502 | HIGH | 7.8 | 0.7% | Jun 10, 2022 | RealVNC VNC Server 6.9.0 through 5.1.0 for Windows allows local privilege escalation because an installer repair operati... |
| CVE-2022-31043 | HIGH | 7.5 | 1.8% | Jun 10, 2022 | Guzzle is an open source PHP HTTP client. In affected versions `Authorization` headers on requests are sensitive informa... |
| CVE-2022-31042 | HIGH | 7.5 | 1.8% | Jun 10, 2022 | Guzzle is an open source PHP HTTP client. In affected versions the `Cookie` headers on requests are sensitive informatio... |
| CVE-2022-30703 | HIGH | 7.8 | 0.3% | Jun 9, 2022 | Trend Micro Security 2021 and 2022 (Consumer) is vulnerable to an exposed dangerous method vulnerability that could allo... |
| CVE-2022-31051 | HIGH | 7.5 | 1.6% | Jun 9, 2022 | semantic-release is an open source npm package for automated version management and package publishing. In affected vers... |
| CVE-2022-31033 | HIGH | 7.5 | 1.4% | Jun 9, 2022 | The Mechanize library is used for automating interaction with websites. Mechanize automatically stores and sends cookies... |
| CVE-2022-29228 | HIGH | 7.5 | 1.2% | Jun 9, 2022 | Envoy is a cloud-native high-performance proxy. In versions prior to 1.22.1 the OAuth filter would try to invoke the rem... |
| CVE-2022-29227 | HIGH | 7.5 | 1.1% | Jun 9, 2022 | Envoy is a cloud-native high-performance edge/middle/service proxy. In versions prior to 1.22.1 if Envoy attempts to sen... |
| CVE-2022-29225 | HIGH | 7.5 | 1.4% | Jun 9, 2022 | Envoy is a cloud-native high-performance proxy. In versions prior to 1.22.1 secompressors accumulate decompressed data i... |
| CVE-2022-30556 | HIGH | 7.5 | 4.7% | Jun 9, 2022 | Apache HTTP Server 2.4.53 and earlier may return lengths to applications calling r:wsread() that point past the end of t... |
| CVE-2022-30522 | HIGH | 7.5 | 90.4% | Jun 9, 2022 | If Apache HTTP Server 2.4.53 is configured to do transformations with mod_sed in contexts where the input to mod_sed may... |
| CVE-2022-2037 | HIGH | 8 | 1.1% | Jun 9, 2022 | Excessive Attack Surface in GitHub repository tooljet/tooljet prior to v1.16.0. |
| CVE-2022-2027 | HIGH | 8 | 1.1% | Jun 9, 2022 | Improper Neutralization of Formula Elements in a CSV File in GitHub repository kromitgmbh/titra prior to 0.77.0. |
| CVE-2022-29404 | HIGH | 7.5 | 5.7% | Jun 9, 2022 | In Apache HTTP Server 2.4.53 and earlier, a malicious request to a lua script that calls r:parsebody(0) may cause a deni... |
| CVE-2022-26377 | HIGH | 7.5 | 19.0% | Jun 9, 2022 | Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in mod_proxy_ajp of Apache HTTP Se... |
| CVE-2022-25153 | HIGH | 7.8 | 0.3% | Jun 9, 2022 | The ITarian Endpoint Manage Communication Client, prior to version 6.43.41148.21120, is compiled using insecure OpenSSL ... |
| CVE-2022-25152 | HIGH | 8.8 | 1.6% | Jun 9, 2022 | The ITarian platform (SAAS / on-premise) offers the possibility to run code on agents via a function called procedures. ... |
| CVE-2022-25151 | HIGH | 7.5 | 0.8% | Jun 9, 2022 | Within the Service Desk module of the ITarian platform (SAAS and on-premise), a remote attacker can obtain sensitive inf... |
| CVE-2022-1993 | HIGH | 8.1 | 51.1% | Jun 9, 2022 | Path Traversal in GitHub repository gogs/gogs prior to 0.12.9. |
| CVE-2022-31214 | HIGH | 7.8 | 0.4% | Jun 9, 2022 | A Privilege Context Switching issue was discovered in join.c in Firejail 0.9.68. By crafting a bogus Firejail container ... |
| CVE-2022-2019 | HIGH | 7.5 | 0.7% | Jun 9, 2022 | A vulnerability classified as critical was found in SourceCodester Prison Management System 1.0. Affected by this vulner... |
| CVE-2022-2018 | HIGH | 7.2 | 0.8% | Jun 9, 2022 | A vulnerability classified as critical has been found in SourceCodester Prison Management System 1.0. Affected is an unk... |
| CVE-2022-2017 | HIGH | 7.2 | 0.7% | Jun 9, 2022 | A vulnerability was found in SourceCodester Prison Management System 1.0. It has been rated as critical. This issue affe... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now