2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-21523 | MEDIUM | 4.3 | 0.5% | Jul 19, 2022 | Vulnerability in the Oracle BI Publisher product of Oracle Fusion Middleware (component: BI Publisher Security). Support... |
| CVE-2022-21522 | MEDIUM | 4.4 | 1.3% | Jul 19, 2022 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Stored Procedure). Supported versions that... |
| CVE-2022-21521 | MEDIUM | 4.9 | 0.7% | Jul 19, 2022 | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: XML Publisher). Supporte... |
| CVE-2022-21520 | MEDIUM | 6.1 | 0.6% | Jul 19, 2022 | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Fluid Core). Supported v... |
| CVE-2022-21519 | MEDIUM | 5.9 | 1.2% | Jul 19, 2022 | Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported versions that are af... |
| CVE-2022-21518 | MEDIUM | 6.5 | 0.7% | Jul 19, 2022 | Vulnerability in the Oracle Health Sciences Data Management Workbench product of Oracle Health Sciences Applications (co... |
| CVE-2022-21517 | MEDIUM | 4.9 | 1.4% | Jul 19, 2022 | Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are ... |
| CVE-2022-21515 | MEDIUM | 4.9 | 1.4% | Jul 19, 2022 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Options). Supported versions that are affe... |
| CVE-2022-21512 | MEDIUM | 4.4 | 0.2% | Jul 19, 2022 | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Integration Broker). Sup... |
| CVE-2022-21509 | MEDIUM | 5.5 | 1.3% | Jul 19, 2022 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are af... |
| CVE-2022-21508 | MEDIUM | 5.8 | 0.2% | Jul 19, 2022 | Vulnerability in Oracle Essbase (component: Security and Provisioning). The supported version that is affected is 21.3. ... |
| CVE-2022-21455 | MEDIUM | 4.9 | 0.9% | Jul 19, 2022 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: PAM Auth Plugin). Supported versions that ... |
| CVE-2022-21439 | MEDIUM | 4.2 | 0.2% | Jul 19, 2022 | Vulnerability in the Oracle Solaris product of Oracle Systems (component: Kernel). Supported versions that are affected ... |
| CVE-2022-21428 | MEDIUM | 6.7 | 0.6% | Jul 19, 2022 | Vulnerability in the Oracle FLEXCUBE Universal Banking product of Oracle Financial Services Applications (component: Inf... |
| CVE-2022-31150 | MEDIUM | 6.5 | 1.2% | Jul 19, 2022 | undici is an HTTP/1.1 client, written from scratch for Node.js. It is possible to inject CRLF sequences into request hea... |
| CVE-2022-34537 | MEDIUM | 5.4 | 0.4% | Jul 19, 2022 | Digital Watchdog DW MEGApix IP cameras A7.2.2_20211029 was discovered to contain a cross-site scripting (XSS) vulnerabil... |
| CVE-2022-34266 | MEDIUM | 5.5 | 0.3% | Jul 19, 2022 | The libtiff-4.0.3-35.amzn2.0.1 package for LibTIFF on Amazon Linux 2 allows attackers to cause a denial of service (appl... |
| CVE-2022-2476 | MEDIUM | 5.5 | 0.4% | Jul 19, 2022 | A null pointer dereference bug was found in wavpack-5.4.0 The results from the ASAN log: AddressSanitizer:DEADLYSIGNAL =... |
| CVE-2022-36305 | MEDIUM | 6.1 | 0.4% | Jul 19, 2022 | Vesta v1.0.0-5 was discovered to contain a cross-site scripting (XSS) vulnerability via the body function at /web/api/v1... |
| CVE-2022-36304 | MEDIUM | 6.1 | 0.4% | Jul 19, 2022 | Vesta v1.0.0-5 was discovered to contain a cross-site scripting (XSS) vulnerability via the generate_response function a... |
| CVE-2022-36303 | MEDIUM | 6.1 | 0.4% | Jul 19, 2022 | Vesta v1.0.0-5 was discovered to contain a cross-site scripting (XSS) vulnerability via the handle_file_upload function ... |
| CVE-2022-34025 | MEDIUM | 6.1 | 0.4% | Jul 19, 2022 | Vesta v1.0.0-5 was discovered to contain a cross-site scripting (XSS) vulnerability via the post function at /web/api/v1... |
| CVE-2022-30570 | MEDIUM | 6.5 | 0.6% | Jul 19, 2022 | The Column Based Security component of TIBCO Software Inc.'s TIBCO Data Virtualization and TIBCO Data Virtualization for... |
| CVE-2022-34001 | MEDIUM | 6.5 | 0.7% | Jul 19, 2022 | Unit4 ERP through 7.9 allows XXE via ExecuteServerProcessAsynchronously. |
| CVE-2022-22417 | MEDIUM | 5.4 | 0.4% | Jul 19, 2022 | IBM Sterling Partner Engagement Manager 6.1.2, 6.2, and Cloud/SasS 22.2 is vulnerable to cross-site scripting. This vuln... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now