2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-31133MEDIUM4.8HumHub is an Open Source Enterprise Social Network. Affected versions of HumHub are vulnerable to a stored Cross-Site Sc...
CVE-2022-32441MEDIUM5.5A memory corruption in Hex Rays Ida Pro v6.6 allows attackers to cause a Denial of Service (DoS) via a crafted file. Rel...
CVE-2022-32208MEDIUM5.9When curl < 7.84.0 does FTP transfers secured by krb5, it handles message verification failures wrongly. This flaw makes...
CVE-2022-32206MEDIUM6.5curl < 7.84.0 supports "chained" HTTP compression algorithms, meaning that a serverresponse can be compressed multiple t...
CVE-2022-32205MEDIUM4.3A malicious server can serve excessive amounts of `Set-Cookie:` headers in a HTTP response to curl and curl < 7.84.0 sto...
CVE-2022-34007MEDIUM6.1EQS Integrity Line Professional through 2022-07-01 allows a stored XSS via a crafted whistleblower entry.
CVE-2022-25047MEDIUM5.9The password reset token in CWP v0.9.8.1126 is generated using known or predictable values.
CVE-2022-32567MEDIUM5.4The Appfire Jira Misc Custom Fields (JMCF) app 2.4.6 for Atlassian Jira allows XSS via a crafted project name to the Add...
CVE-2022-2342MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository outline/outline prior to v0.64.4.
CVE-2022-27549MEDIUM5.5HCL Launch may store certain data for recurring activities in a plain text format.
CVE-2022-27548MEDIUM5.5HCL Launch stores user credentials in plain clear text which can be read by a local user.
CVE-2022-20862MEDIUM4.3A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) and Cisco Uni...
CVE-2022-20815MEDIUM6.1A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM), Cisco Unifie...
CVE-2022-20813MEDIUM5.9Multiple vulnerabilities in the API and in the web-based management interface of Cisco Expressway Series and Cisco TeleP...
CVE-2022-20812MEDIUM6.5Multiple vulnerabilities in the API and in the web-based management interface of Cisco Expressway Series and Cisco TeleP...
CVE-2022-20808MEDIUM6.5A vulnerability in Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an authenticated, remote attacker to c...
CVE-2022-20800MEDIUM6.1A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM), Cisco Unifie...
CVE-2022-20791MEDIUM6.5A vulnerability in the database user privileges of Cisco Unified Communications Manager (Unified CM), Cisco Unified Comm...
CVE-2022-20768MEDIUM4.9A vulnerability in the logging component of Cisco TelePresence Collaboration Endpoint (CE) and RoomOS Software could all...
CVE-2022-20752MEDIUM5.3A vulnerability in Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Manag...
CVE-2022-2318MEDIUM5.5There are use-after-free vulnerabilities caused by timer handler in net/rose/rose_timer.c of linux that allow attackers ...
CVE-2022-2316MEDIUM5.4HTML injection vulnerability in secure messages of Devolutions Server before 2022.2 allows attackers to alter the render...
CVE-2022-31131MEDIUM4.3Nextcloud mail is a Mail app for the Nextcloud home server product. Versions of Nextcloud mail prior to 1.12.2 were foun...
CVE-2022-31127MEDIUM6.1NextAuth.js is a complete open source authentication solution for Next.js applications. An attacker can pass a compromis...
CVE-2022-31124MEDIUM6.5openssh_key_parser is an open source Python package providing utilities to parse and pack OpenSSH private and public key...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now