2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-21763 | MEDIUM | 5.5 | 0.1% | Jul 6, 2022 | In telecom service, there is a possible information disclosure due to a missing permission check. This could lead to loc... |
| CVE-2022-24141 | MEDIUM | 5.4 | 0.7% | Jul 6, 2022 | The iTopVPNmini.exe component of iTop VPN 3.2 will try to connect to datastate_iTopVPN_Pipe_Server on a loop. An attacke... |
| CVE-2022-24140 | MEDIUM | 6.6 | 1.0% | Jul 6, 2022 | IOBit Advanced System Care 15, iTop Screen Recorder 2.1, iTop VPN 3.2, Driver Booster 9, and iTop Screenshot sends HTTP ... |
| CVE-2022-32290 | MEDIUM | 4.3 | 0.2% | Jul 6, 2022 | The client in Northern.tech Mender 3.2.0, 3.2.1, and 3.2.2 has Incorrect Access Control. It listens on a random, unprivi... |
| CVE-2022-35230 | MEDIUM | 5.4 | 0.6% | Jul 6, 2022 | An authenticated user can create a link with reflected Javascript code inside it for the graphs page and send it to othe... |
| CVE-2022-35229 | MEDIUM | 5.4 | 0.6% | Jul 6, 2022 | An authenticated user can create a link with reflected Javascript code inside it for the discovery page and send it to o... |
| CVE-2022-33075 | MEDIUM | 5.4 | 0.8% | Jul 5, 2022 | A stored cross-site scripting (XSS) vulnerability in the Add Classification function of Zoo Management System v1.0 allow... |
| CVE-2022-31117 | MEDIUM | 5.9 | 1.4% | Jul 5, 2022 | UltraJSON is a fast JSON encoder and decoder written in pure C with bindings for Python 3.7+. In versions prior to 5.4.0... |
| CVE-2022-34879 | MEDIUM | 6.1 | 0.4% | Jul 5, 2022 | Reflected Cross Site Scripting (XSS) vulnerabilities in AST Agent Time Sheet interface (/vicidial/AST_agent_time_sheet.p... |
| CVE-2022-31770 | MEDIUM | 4.9 | 0.8% | Jul 5, 2022 | IBM App Connect Enterprise Certified Container 4.2 could allow a user from the administration console to cause a denial ... |
| CVE-2022-33744 | MEDIUM | 4.7 | 0.3% | Jul 5, 2022 | Arm guests can cause Dom0 DoS via PV devices When mapping pages of guests on Arm, dom0 is using an rbtree to keep track ... |
| CVE-2022-30289 | MEDIUM | 5.4 | 0.4% | Jul 5, 2022 | A stored Cross-site Scripting (XSS) vulnerability was identified in the Data Import functionality of OpenCTI through 5.2... |
| CVE-2022-2097 | MEDIUM | 5.3 | 2.0% | Jul 5, 2022 | AES OCB mode for 32-bit x86 platforms using the AES-NI assembly optimised implementation will not encrypt the entirety o... |
| CVE-2022-31603 | MEDIUM | 6.7 | 0.2% | Jul 4, 2022 | NVIDIA DGX A100 contains a vulnerability in SBIOS in the IpSecDxe, where a user with high privileges and preconditioned ... |
| CVE-2022-31602 | MEDIUM | 6.7 | 0.2% | Jul 4, 2022 | NVIDIA DGX A100 contains a vulnerability in SBIOS in the IpSecDxe, where a user with elevated privileges and a precondit... |
| CVE-2022-31601 | MEDIUM | 6.7 | 0.2% | Jul 4, 2022 | NVIDIA DGX A100 contains a vulnerability in SBIOS in the SmbiosPei, which may allow a highly privileged local attacker t... |
| CVE-2022-1967 | MEDIUM | 6.5 | 0.4% | Jul 4, 2022 | The WP Championship WordPress plugin before 9.3 is lacking CSRF checks in various places, allowing attackers to make a l... |
| CVE-2022-1946 | MEDIUM | 6.1 | 1.3% | Jul 4, 2022 | The Gallery WordPress plugin before 2.0.0 does not sanitise and escape a parameter before outputting it back in the resp... |
| CVE-2022-1301 | MEDIUM | 4.8 | 0.5% | Jul 4, 2022 | The WP Contact Slider WordPress plugin before 2.4.7 does not sanitize and escape the Text to Display settings of sliders... |
| CVE-2022-0250 | MEDIUM | 6.1 | 1.3% | Jul 4, 2022 | The Redirection for Contact Form 7 WordPress plugin before 2.5.0 does not escape a link generated before outputting it i... |
| CVE-2022-2301 | MEDIUM | 5.5 | 0.6% | Jul 4, 2022 | Buffer Over-read in GitHub repository hpjansson/chafa prior to 1.10.3. |
| CVE-2022-2300 | MEDIUM | 5.4 | 0.5% | Jul 4, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 1.2.19. |
| CVE-2022-29892 | MEDIUM | 6.5 | 0.9% | Jul 4, 2022 | Improper input validation vulnerability in Space of Cybozu Garoon 4.0.0 to 5.5.1 allows a remote authenticated attacker ... |
| CVE-2022-29513 | MEDIUM | 4.8 | 0.5% | Jul 4, 2022 | Cross-site scripting vulnerability in Scheduler of Cybozu Garoon 4.10.0 to 5.5.1 allows a remote authenticated attacker ... |
| CVE-2022-29471 | MEDIUM | 4.3 | 0.7% | Jul 4, 2022 | Browse restriction bypass vulnerability in Bulletin of Cybozu Garoon allows a remote authenticated attacker to obtain th... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now