2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-31897 | MEDIUM | 6.1 | 0.9% | Jun 29, 2022 | SourceCodester Zoo Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via public_html/register_visitor?ms... |
| CVE-2022-31266 | MEDIUM | 4.3 | 0.7% | Jun 29, 2022 | In ILIAS through 7.10, lack of verification when changing an email address (on the Profile Page) allows remote attackers... |
| CVE-2022-29272 | MEDIUM | 6.1 | 3.3% | Jun 29, 2022 | In Nagios XI through 5.8.5, an open redirect vulnerability exists in the login function that could lead to spoofing. |
| CVE-2022-29271 | MEDIUM | 6.5 | 1.5% | Jun 29, 2022 | In Nagios XI through 5.8.5, a read-only Nagios user (due to an incorrect permission check) is able to schedule downtime ... |
| CVE-2022-29270 | MEDIUM | 4.3 | 1.9% | Jun 29, 2022 | In Nagios XI through 5.8.5, it is possible for a user without password verification to change his e-mail address. |
| CVE-2022-29269 | MEDIUM | 6.5 | 2.4% | Jun 29, 2022 | In Nagios XI through 5.8.5, in the schedule report function, an authenticated attacker is able to inject HTML tags that ... |
| CVE-2022-28803 | MEDIUM | 5.4 | 0.5% | Jun 29, 2022 | In SilverStripe Framework through 2022-04-07, Stored XSS can occur in javascript link tags added via XMLHttpRequest (XHR... |
| CVE-2022-31884 | MEDIUM | 6.5 | 1.1% | Jun 28, 2022 | Marval MSM v14.19.0.12476 has an Improper Access Control vulnerability which allows a low privilege user to delete other... |
| CVE-2022-29858 | MEDIUM | 4.3 | 1.2% | Jun 28, 2022 | Silverstripe silverstripe/assets through 1.10 is vulnerable to improper access control that allows protected images to b... |
| CVE-2022-25238 | MEDIUM | 5.4 | 0.6% | Jun 28, 2022 | Silverstripe silverstripe/framework through 4.10.0 allows XSS, inside of script tags that can can be added to website co... |
| CVE-2022-24444 | MEDIUM | 6.5 | 0.8% | Jun 28, 2022 | Silverstripe silverstripe/framework through 4.10 allows Session Fixation. |
| CVE-2022-31886 | MEDIUM | 6.5 | 2.1% | Jun 28, 2022 | Marval MSM v14.19.0.12476 is vulnerable to Cross Site Request Forgery (CSRF). An attacker can disable the 2FA by sending... |
| CVE-2022-2231 | MEDIUM | 5.5 | 1.2% | Jun 28, 2022 | NULL Pointer Dereference in GitHub repository vim/vim prior to 8.2. |
| CVE-2022-31229 | MEDIUM | 4.9 | 0.7% | Jun 28, 2022 | Dell PowerScale OneFS, 8.2.x through 9.3.0.x, contain an error message with sensitive information. An administrator coul... |
| CVE-2022-31108 | MEDIUM | 6.1 | 0.8% | Jun 28, 2022 | Mermaid is a JavaScript based diagramming and charting tool that uses Markdown-inspired text definitions and a renderer ... |
| CVE-2022-31068 | MEDIUM | 5.3 | 0.9% | Jun 28, 2022 | GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking an... |
| CVE-2022-31052 | MEDIUM | 6.5 | 1.6% | Jun 28, 2022 | Synapse is an open source home server implementation for the Matrix chat network. In versions prior to 1.61.1 URL previe... |
| CVE-2022-0085 | MEDIUM | 5.3 | 1.0% | Jun 28, 2022 | Server-Side Request Forgery (SSRF) in GitHub repository dompdf/dompdf prior to 2.0.0. |
| CVE-2022-30562 | MEDIUM | 4.7 | 0.7% | Jun 28, 2022 | If the user enables the https function on the device, an attacker can modify the user’s request data packet through a ma... |
| CVE-2022-30561 | MEDIUM | 5.9 | 0.7% | Jun 28, 2022 | When an attacker uses a man-in-the-middle attack to sniff the request packets with success logging in, the attacker coul... |
| CVE-2022-23896 | MEDIUM | 5.4 | 0.5% | Jun 28, 2022 | Admidio 4.1.2 version is affected by stored cross-site scripting (XSS). |
| CVE-2022-34133 | MEDIUM | 6.1 | 0.5% | Jun 28, 2022 | Jorani v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Comment parameter at applicatio... |
| CVE-2022-31104 | MEDIUM | 5.6 | 1.6% | Jun 28, 2022 | Wasmtime is a standalone runtime for WebAssembly. In affected versions wasmtime's implementation of the SIMD proposal fo... |
| CVE-2022-33009 | MEDIUM | 4.8 | 0.6% | Jun 27, 2022 | A stored cross-site scripting (XSS) vulnerability in LightCMS v1.3.11 allows attackers to execute arbitrary web scripts ... |
| CVE-2022-31099 | MEDIUM | 6.5 | 0.9% | Jun 27, 2022 | rulex is a new, portable, regular expression language. When parsing untrusted rulex expressions, the stack may overflow,... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now