2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-29890 | MEDIUM | 6.1 | 0.4% | Jul 15, 2022 | In affected versions of Octopus Server the help sidebar can be customized to include a Cross-Site Scripting payload in t... |
| CVE-2022-1881 | MEDIUM | 5.3 | 0.5% | Jul 15, 2022 | In affected versions of Octopus Server an Insecure Direct Object Reference vulnerability exists where it is possible for... |
| CVE-2022-34094 | MEDIUM | 6.1 | 2.3% | Jul 14, 2022 | Portal do Software Publico Brasileiro i3geo v7.0.5 was discovered to contain a cross-site scripting (XSS) vulnerability ... |
| CVE-2022-34093 | MEDIUM | 6.1 | 2.3% | Jul 14, 2022 | Portal do Software Publico Brasileiro i3geo v7.0.5 was discovered to contain a cross-site scripting (XSS) vulnerability ... |
| CVE-2022-34092 | MEDIUM | 6.1 | 1.1% | Jul 14, 2022 | Portal do Software Publico Brasileiro i3geo v7.0.5 was discovered to contain a cross-site scripting (XSS) vulnerability ... |
| CVE-2022-32425 | MEDIUM | 5.3 | 0.5% | Jul 14, 2022 | The login function of Mealie v1.0.0beta-2 allows attackers to enumerate existing usernames by timing the server's respon... |
| CVE-2022-32406 | MEDIUM | 5.5 | 0.5% | Jul 14, 2022 | GtkRadiant v1.6.6 was discovered to contain a buffer overflow via the component q3map2. This vulnerability can cause a D... |
| CVE-2022-32318 | MEDIUM | 5.4 | 0.5% | Jul 14, 2022 | Fast Food Ordering System v1.0 was discovered to contain a persistent cross-site scripting (XSS) vulnerability via the c... |
| CVE-2022-32317 | MEDIUM | 5.5 | 0.8% | Jul 14, 2022 | The MPlayer Project v1.5 was discovered to contain a heap use-after-free resulting in a double free in the preinit funct... |
| CVE-2022-31156 | MEDIUM | 4.4 | 0.5% | Jul 14, 2022 | Gradle is a build tool. Dependency verification is a security feature in Gradle Build Tool that was introduced to allow ... |
| CVE-2022-23825 | MEDIUM | 6.5 | 0.8% | Jul 14, 2022 | Aliases in the branch predictor may cause some AMD processors to predict the wrong branch type potentially leading to in... |
| CVE-2022-2408 | MEDIUM | 4.3 | 0.5% | Jul 14, 2022 | The Guest account feature in Mattermost version 6.7.0 and earlier fails to properly restrict the permissions, which allo... |
| CVE-2022-2406 | MEDIUM | 6.5 | 0.8% | Jul 14, 2022 | The legacy Slack import feature in Mattermost version 6.7.0 and earlier fails to properly limit the sizes of imported fi... |
| CVE-2022-2401 | MEDIUM | 6.5 | 0.7% | Jul 14, 2022 | Unrestricted information disclosure of all users in Mattermost version 6.7.0 and earlier allows team members to access s... |
| CVE-2022-35283 | MEDIUM | 6.5 | 1.0% | Jul 14, 2022 | IBM Security Verify Information Queue 10.0.2 could allow an authenticated user to cause a denial of service with a speci... |
| CVE-2022-22477 | MEDIUM | 6.1 | 0.5% | Jul 14, 2022 | IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to e... |
| CVE-2022-22473 | MEDIUM | 5.3 | 0.8% | Jul 14, 2022 | IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to obtain sensitive information ca... |
| CVE-2022-32225 | MEDIUM | 6.1 | 0.5% | Jul 14, 2022 | A reflected DOM-Based XSS vulnerability has been discovered in the Help directory of Veeam Management Pack for Microsoft... |
| CVE-2022-32222 | MEDIUM | 5.3 | 1.7% | Jul 14, 2022 | A cryptographic vulnerability exists on Node.js on linux in versions of 18.x prior to 18.40.0 which allowed a default pa... |
| CVE-2022-32215 | MEDIUM | 6.5 | 68.8% | Jul 14, 2022 | The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not correctly handle multi-line T... |
| CVE-2022-32214 | MEDIUM | 6.5 | 77.3% | Jul 14, 2022 | The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not strictly use the CRLF sequenc... |
| CVE-2022-32213 | MEDIUM | 6.5 | 35.1% | Jul 14, 2022 | The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not correctly parse and validate ... |
| CVE-2022-32210 | MEDIUM | 6.5 | 0.4% | Jul 14, 2022 | `Undici.ProxyAgent` never verifies the remote server's certificate, and always exposes all request & response data to th... |
| CVE-2022-2393 | MEDIUM | 5.7 | 0.2% | Jul 14, 2022 | A flaw was found in pki-core, which could allow a user to get a certificate for another user identity when directory-bas... |
| CVE-2022-29593 | MEDIUM | 5.9 | 10.4% | Jul 14, 2022 | relay_cgi.cgi on Dingtian DT-R002 2CH relay devices with firmware 3.1.276A allows an attacker to replay HTTP post reques... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now