2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-27238 | MEDIUM | 5.4 | 0.4% | Jun 24, 2022 | BigBlueButton version 2.4.7 (or earlier) is vulnerable to stored Cross-Site Scripting (XSS) in the private chat function... |
| CVE-2022-22502 | MEDIUM | 5.4 | 0.5% | Jun 24, 2022 | IBM Robotic Process Automation 21.0.1 and 21.0.2 is vulnerable to cross-site scripting. This vulnerability allows users ... |
| CVE-2022-32209 | MEDIUM | 6.1 | 29.1% | Jun 24, 2022 | # Possible XSS Vulnerability in Rails::Html::SanitizerThere is a possible XSS vulnerability with certain configurations ... |
| CVE-2022-30120 | MEDIUM | 6.1 | 0.9% | Jun 24, 2022 | XSS in /dashboard/blocks/stacks/view_details/ - old browsers only. When using an older browser with built-in XSS protect... |
| CVE-2022-30119 | MEDIUM | 6.1 | 0.8% | Jun 24, 2022 | XSS in /dashboard/reports/logs/view - old browsers only. When using Internet Explorer with the XSS protection disabled, ... |
| CVE-2022-30118 | MEDIUM | 6.1 | 0.8% | Jun 24, 2022 | Title for CVE: XSS in /dashboard/system/express/entities/forms/save_control/[GUID]: old browsers only.Description: When ... |
| CVE-2022-2121 | MEDIUM | 6.5 | 0.7% | Jun 24, 2022 | OFFIS DCMTK's (All versions prior to 3.6.7) has a NULL pointer dereference vulnerability while processing DICOM files, w... |
| CVE-2022-1747 | MEDIUM | 4.6 | 0.2% | Jun 24, 2022 | The authentication mechanism used by voters to activate a voting session on the tested version of Dominion Voting System... |
| CVE-2022-1745 | MEDIUM | 6.8 | 0.3% | Jun 24, 2022 | The authentication mechanism used by technicians on the tested version of Dominion Voting Systems ImageCast X is suscept... |
| CVE-2022-1744 | MEDIUM | 6.8 | 0.3% | Jun 24, 2022 | Applications on the tested version of Dominion Voting Systems ImageCast X can execute code with elevated privileges by e... |
| CVE-2022-1743 | MEDIUM | 6.8 | 0.4% | Jun 24, 2022 | The tested version of Dominion Voting System ImageCast X can be manipulated to cause arbitrary code execution by special... |
| CVE-2022-1742 | MEDIUM | 6.8 | 0.3% | Jun 24, 2022 | The tested version of Dominion Voting Systems ImageCast X allows for rebooting into Android Safe Mode, which allows an a... |
| CVE-2022-1741 | MEDIUM | 6.8 | 0.3% | Jun 24, 2022 | The tested version of Dominion Voting Systems ImageCast X has a Terminal Emulator application which could be leveraged b... |
| CVE-2022-1740 | MEDIUM | 4.6 | 0.2% | Jun 24, 2022 | The tested version of Dominion Voting Systems ImageCast X’s on-screen application hash display feature, audit log export... |
| CVE-2022-1739 | MEDIUM | 6.8 | 0.1% | Jun 24, 2022 | The tested version of Dominion Voting Systems ImageCast X does not validate application signatures to a trusted root cer... |
| CVE-2022-1666 | MEDIUM | 6.5 | 0.7% | Jun 24, 2022 | The default password for the web application’s root user (the vendor’s private account) was weak and the MD5 hash was us... |
| CVE-2022-1524 | MEDIUM | 5.9 | 0.3% | Jun 24, 2022 | LRM version 2.4 and lower does not implement TLS encryption. A malicious actor can MITM attack sensitive data in-transit... |
| CVE-2022-32990 | MEDIUM | 5.5 | 0.6% | Jun 24, 2022 | An issue in gimp_layer_invalidate_boundary of GNOME GIMP 2.10.30 allows attackers to trigger an unhandled exception via ... |
| CVE-2022-32141 | MEDIUM | 6.5 | 1.0% | Jun 24, 2022 | Multiple CODESYS Products are prone to a buffer over read. A low privileged remote attacker may craft a request with an ... |
| CVE-2022-32140 | MEDIUM | 6.5 | 1.0% | Jun 24, 2022 | Multiple CODESYS products are affected to a buffer overflow.A low privileged remote attacker may craft a request, which ... |
| CVE-2022-32139 | MEDIUM | 6.5 | 1.0% | Jun 24, 2022 | In multiple CODESYS products, a low privileged remote attacker may craft a request, which cause an out-of-bounds read, r... |
| CVE-2022-32136 | MEDIUM | 6.5 | 1.0% | Jun 24, 2022 | In multiple CODESYS products, a low privileged remote attacker may craft a request that cause a read access to an uninit... |
| CVE-2022-31803 | MEDIUM | 5.3 | 1.0% | Jun 24, 2022 | In CODESYS Gateway Server V2 an insufficient check for the activity of TCP client connections allows an unauthenticated ... |
| CVE-2022-32987 | MEDIUM | 4.8 | 0.5% | Jun 23, 2022 | Multiple cross-site scripting (XSS) vulnerabilities in /bsms/?page=manage_account of Simple Bakery Shop Management Syste... |
| CVE-2022-34328 | MEDIUM | 6.1 | 2.2% | Jun 23, 2022 | PMB 7.3.10 allows reflected XSS via the id parameter in an lvl=author_see request to index.php. |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now