2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-31133 | MEDIUM | 4.8 | 0.6% | Jul 7, 2022 | HumHub is an Open Source Enterprise Social Network. Affected versions of HumHub are vulnerable to a stored Cross-Site Sc... |
| CVE-2022-32441 | MEDIUM | 5.5 | 0.6% | Jul 7, 2022 | A memory corruption in Hex Rays Ida Pro v6.6 allows attackers to cause a Denial of Service (DoS) via a crafted file. Rel... |
| CVE-2022-32208 | MEDIUM | 5.9 | 5.6% | Jul 7, 2022 | When curl < 7.84.0 does FTP transfers secured by krb5, it handles message verification failures wrongly. This flaw makes... |
| CVE-2022-32206 | MEDIUM | 6.5 | 32.0% | Jul 7, 2022 | curl < 7.84.0 supports "chained" HTTP compression algorithms, meaning that a serverresponse can be compressed multiple t... |
| CVE-2022-32205 | MEDIUM | 4.3 | 26.9% | Jul 7, 2022 | A malicious server can serve excessive amounts of `Set-Cookie:` headers in a HTTP response to curl and curl < 7.84.0 sto... |
| CVE-2022-34007 | MEDIUM | 6.1 | 1.2% | Jul 7, 2022 | EQS Integrity Line Professional through 2022-07-01 allows a stored XSS via a crafted whistleblower entry. |
| CVE-2022-25047 | MEDIUM | 5.9 | 1.5% | Jul 7, 2022 | The password reset token in CWP v0.9.8.1126 is generated using known or predictable values. |
| CVE-2022-32567 | MEDIUM | 5.4 | 0.5% | Jul 7, 2022 | The Appfire Jira Misc Custom Fields (JMCF) app 2.4.6 for Atlassian Jira allows XSS via a crafted project name to the Add... |
| CVE-2022-2342 | MEDIUM | 5.4 | 0.6% | Jul 7, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository outline/outline prior to v0.64.4. |
| CVE-2022-27549 | MEDIUM | 5.5 | 0.1% | Jul 6, 2022 | HCL Launch may store certain data for recurring activities in a plain text format. |
| CVE-2022-27548 | MEDIUM | 5.5 | 0.4% | Jul 6, 2022 | HCL Launch stores user credentials in plain clear text which can be read by a local user. |
| CVE-2022-20862 | MEDIUM | 4.3 | 1.2% | Jul 6, 2022 | A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) and Cisco Uni... |
| CVE-2022-20815 | MEDIUM | 6.1 | 0.7% | Jul 6, 2022 | A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM), Cisco Unifie... |
| CVE-2022-20813 | MEDIUM | 5.9 | 1.0% | Jul 6, 2022 | Multiple vulnerabilities in the API and in the web-based management interface of Cisco Expressway Series and Cisco TeleP... |
| CVE-2022-20812 | MEDIUM | 6.5 | 1.7% | Jul 6, 2022 | Multiple vulnerabilities in the API and in the web-based management interface of Cisco Expressway Series and Cisco TeleP... |
| CVE-2022-20808 | MEDIUM | 6.5 | 0.9% | Jul 6, 2022 | A vulnerability in Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an authenticated, remote attacker to c... |
| CVE-2022-20800 | MEDIUM | 6.1 | 0.7% | Jul 6, 2022 | A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM), Cisco Unifie... |
| CVE-2022-20791 | MEDIUM | 6.5 | 1.3% | Jul 6, 2022 | A vulnerability in the database user privileges of Cisco Unified Communications Manager (Unified CM), Cisco Unified Comm... |
| CVE-2022-20768 | MEDIUM | 4.9 | 0.8% | Jul 6, 2022 | A vulnerability in the logging component of Cisco TelePresence Collaboration Endpoint (CE) and RoomOS Software could all... |
| CVE-2022-20752 | MEDIUM | 5.3 | 0.9% | Jul 6, 2022 | A vulnerability in Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Manag... |
| CVE-2022-2318 | MEDIUM | 5.5 | 0.4% | Jul 6, 2022 | There are use-after-free vulnerabilities caused by timer handler in net/rose/rose_timer.c of linux that allow attackers ... |
| CVE-2022-2316 | MEDIUM | 5.4 | 0.5% | Jul 6, 2022 | HTML injection vulnerability in secure messages of Devolutions Server before 2022.2 allows attackers to alter the render... |
| CVE-2022-31131 | MEDIUM | 4.3 | 0.6% | Jul 6, 2022 | Nextcloud mail is a Mail app for the Nextcloud home server product. Versions of Nextcloud mail prior to 1.12.2 were foun... |
| CVE-2022-31127 | MEDIUM | 6.1 | 0.9% | Jul 6, 2022 | NextAuth.js is a complete open source authentication solution for Next.js applications. An attacker can pass a compromis... |
| CVE-2022-31124 | MEDIUM | 6.5 | 1.0% | Jul 6, 2022 | openssh_key_parser is an open source Python package providing utilities to parse and pack OpenSSH private and public key... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now