2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-31472 | MEDIUM | 4.3 | 0.7% | Jul 11, 2022 | Browse restriction bypass vulnerability in Cabinet of Cybozu Garoon 4.0.0 to 5.5.1 allows a remote authenticated attacke... |
| CVE-2022-30943 | MEDIUM | 4.3 | 0.7% | Jul 11, 2022 | Browsing restriction bypass vulnerability in Bulletin of Cybozu Garoon 4.0.0 to 5.9.1 allows a remote authenticated atta... |
| CVE-2022-29512 | MEDIUM | 6.5 | 0.9% | Jul 11, 2022 | Exposure of sensitive information to an unauthorized actor issue in multiple applications of Cybozu Garoon 4.0.0 to 5.9.... |
| CVE-2022-27168 | MEDIUM | 6.1 | 0.9% | Jul 11, 2022 | Cross-site scripting vulnerability in LiteCart versions prior to 2.4.2 allows a remote attacker to inject an arbitrary s... |
| CVE-2022-2365 | MEDIUM | 5.4 | 0.4% | Jul 10, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository zadam/trilium prior to 0.53.3. |
| CVE-2022-27910 | MEDIUM | 6.1 | 0.5% | Jul 10, 2022 | In Joomla component 'Joomlatools - DOCman 3.5.13 (and likely most versions below)' are affected to an reflected Cross-Si... |
| CVE-2022-2353 | MEDIUM | 6.1 | 0.5% | Jul 9, 2022 | Prior to microweber/microweber v1.2.20, due to improper neutralization of input, an attacker can steal tokens to perform... |
| CVE-2022-35412 | MEDIUM | 5.1 | 0.2% | Jul 8, 2022 | Digital Guardian Agent 7.7.4.0042 allows an administrator (who ordinarily does not have a supported way to uninstall the... |
| CVE-2022-22463 | MEDIUM | 6.5 | 0.8% | Jul 8, 2022 | IBM Security Access Manager Appliance 10.0.0.0, 10.0.1.0, 10.0.2.0, and 10.0.3.0 is vulnerable to SQL injection. A remot... |
| CVE-2022-22370 | MEDIUM | 5.4 | 0.4% | Jul 8, 2022 | IBM Security Verify Access 10.0.0.0, 10.0.1.0, 10.0.2.0, and 10.0.3.0 is vulnerable to cross-site scripting. This vulner... |
| CVE-2022-34306 | MEDIUM | 5.4 | 0.6% | Jul 8, 2022 | IBM CICS TX Standard and Advanced 11.1 is vulnerable to HTTP header injection, caused by improper validation of input by... |
| CVE-2022-34167 | MEDIUM | 5.4 | 0.5% | Jul 8, 2022 | IBM CICS TX Standard and Advanced 11.1 is vulnerable to stored cross-site scripting. This vulnerability allows users to ... |
| CVE-2022-34166 | MEDIUM | 5.4 | 0.5% | Jul 8, 2022 | IBM CICS TX Standard and Advanced 11.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed a... |
| CVE-2022-34160 | MEDIUM | 5.4 | 0.9% | Jul 8, 2022 | IBM CICS TX Standard and Advanced 11.1 is vulnerable to HTML injection. A remote attacker could inject malicious HTML co... |
| CVE-2022-35406 | MEDIUM | 4.3 | 0.6% | Jul 8, 2022 | A URL disclosure issue was discovered in Burp Suite before 2022.6. If a user views a crafted response in the Repeater or... |
| CVE-2022-28624 | MEDIUM | 4.8 | 0.4% | Jul 8, 2022 | A potential security vulnerability has been identified in certain HPE FlexNetwork and FlexFabric switch products. The vu... |
| CVE-2022-32115 | MEDIUM | 6.1 | 1.0% | Jul 8, 2022 | An issue in the isSVG() function of Known v1.2.2+2020061101 allows attackers to execute arbitrary code via a crafted SVG... |
| CVE-2022-31290 | MEDIUM | 5.4 | 0.7% | Jul 8, 2022 | A cross-site scripting (XSS) vulnerability in Known v1.2.2+2020061101 allows authenticated attackers to execute arbitrar... |
| CVE-2022-30852 | MEDIUM | 4.3 | 0.7% | Jul 8, 2022 | Known v1.3.1 was discovered to contain an Insecure Direct Object Reference (IDOR). |
| CVE-2022-32061 | MEDIUM | 4.8 | 0.5% | Jul 7, 2022 | An arbitrary file upload vulnerability in the Select User function under the People Menu component of Snipe-IT v6.0.2 al... |
| CVE-2022-32060 | MEDIUM | 4.8 | 0.9% | Jul 7, 2022 | An arbitrary file upload vulnerability in the Update Branding Settings component of Snipe-IT v6.0.2 allows attackers to ... |
| CVE-2022-31029 | MEDIUM | 4.8 | 0.4% | Jul 7, 2022 | AdminLTE is a Pi-hole Dashboard for stats and configuration. In affected versions inserting code like `<script>alert("XS... |
| CVE-2022-33098 | MEDIUM | 6.1 | 52.2% | Jul 7, 2022 | Magnolia CMS v6.2.19 was discovered to contain a cross-site scripting (XSS) vulnerability via the Edit Contact function.... |
| CVE-2022-28889 | MEDIUM | 4.3 | 1.6% | Jul 7, 2022 | In Apache Druid 0.22.1 and earlier, the server did not set appropriate headers to prevent clickjacking. Druid 0.23.0 and... |
| CVE-2022-31136 | MEDIUM | 6.1 | 0.5% | Jul 7, 2022 | Bookwyrm is an open source social reading and reviewing program. Versions of Bookwyrm prior to 0.4.1 did not properly sa... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now