2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-32128 | MEDIUM | 6.1 | 0.6% | Jun 23, 2022 | 74cmsSE v3.5.1 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the path /company/ser... |
| CVE-2022-32127 | MEDIUM | 6.1 | 0.6% | Jun 23, 2022 | 74cmsSE v3.5.1 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the path /company/vie... |
| CVE-2022-32126 | MEDIUM | 6.1 | 0.6% | Jun 23, 2022 | 74cmsSE v3.5.1 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the path /company. |
| CVE-2022-32125 | MEDIUM | 6.1 | 0.6% | Jun 23, 2022 | 74cmsSE v3.5.1 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the path /job. |
| CVE-2022-32124 | MEDIUM | 6.1 | 0.6% | Jun 23, 2022 | 74cmsSE v3.5.1 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the component /index/... |
| CVE-2022-29526 | MEDIUM | 5.3 | 2.6% | Jun 23, 2022 | Go before 1.17.10 and 1.18.x before 1.18.2 has Incorrect Privilege Assignment. When called with a non-zero flags paramet... |
| CVE-2022-34305 | MEDIUM | 6.1 | 6.2% | Jun 23, 2022 | In Apache Tomcat 10.1.0-M1 to 10.1.0-M16, 10.0.0-M1 to 10.0.22, 9.0.30 to 9.0.64 and 8.5.50 to 8.5.81 the Form authentic... |
| CVE-2022-31009 | MEDIUM | 6.5 | 0.6% | Jun 23, 2022 | wire-ios is an iOS client for the Wire secure messaging application. Invalid accent colors of Wire communication partner... |
| CVE-2022-23080 | MEDIUM | 5 | 0.8% | Jun 22, 2022 | In directus versions v9.0.0-beta.2 through 9.6.0 are vulnerable to server-side request forgery (SSRF) in the media uploa... |
| CVE-2022-32549 | MEDIUM | 5.3 | 2.2% | Jun 22, 2022 | Apache Sling Commons Log <= 5.4.0 and Apache Sling API <= 2.25.0 are vulnerable to log injection. The ability to forge l... |
| CVE-2022-20651 | MEDIUM | 5.5 | 0.4% | Jun 22, 2022 | A vulnerability in the logging component of Cisco Adaptive Security Device Manager (ASDM) could allow an authenticated, ... |
| CVE-2022-2174 | MEDIUM | 6.1 | 2.8% | Jun 22, 2022 | Cross-site Scripting (XSS) - Reflected in GitHub repository microweber/microweber prior to 1.2.18. |
| CVE-2022-23077 | MEDIUM | 6.1 | 0.7% | Jun 22, 2022 | In habitica versions v4.119.0 through v4.232.2 are vulnerable to DOM XSS via the login page. |
| CVE-2022-31248 | MEDIUM | 5.3 | 1.0% | Jun 22, 2022 | A Observable Response Discrepancy vulnerability in spacewalk-java of SUSE Manager Server 4.1, SUSE Manager Server 4.2 al... |
| CVE-2022-23057 | MEDIUM | 5.4 | 0.6% | Jun 22, 2022 | In ERPNext, versions v12.0.9--v13.0.3 are vulnerable to Stored Cross-Site-Scripting (XSS), due to user input not being v... |
| CVE-2022-31095 | MEDIUM | 6.5 | 0.5% | Jun 21, 2022 | discourse-chat is a chat plugin for the Discourse application. Versions prior to 0.4 are vulnerable to an exposure of se... |
| CVE-2022-32974 | MEDIUM | 6.5 | 0.7% | Jun 21, 2022 | An authenticated attacker could read arbitrary files from the underlying operating system of the scanner using a custom ... |
| CVE-2022-31786 | MEDIUM | 6.1 | 0.7% | Jun 21, 2022 | IdeaLMS 2022 allows reflected Cross Site Scripting (XSS) via the IdeaLMS/Class/Assessment/ PATH_INFO. |
| CVE-2022-30874 | MEDIUM | 5.4 | 0.8% | Jun 21, 2022 | There is a Cross Site Scripting Stored (XSS) vulnerability in NukeViet CMS before 4.5.02. |
| CVE-2022-1596 | MEDIUM | 6.5 | 0.6% | Jun 21, 2022 | Incorrect Permission Assignment for Critical Resource vulnerability in ABB REX640 PCL1, REX640 PCL2, REX640 PCL3 allows ... |
| CVE-2022-31478 | MEDIUM | 4.3 | 0.6% | Jun 21, 2022 | The UserTakeOver plugin before 4.0.1 for ILIAS allows an attacker to list all users via the search function. |
| CVE-2022-25585 | MEDIUM | 5.4 | 0.4% | Jun 21, 2022 | Unioncms v1.0.13 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Default settings. |
| CVE-2022-23342 | MEDIUM | 5.3 | 1.2% | Jun 21, 2022 | The Hyland Onbase Application Server releases prior to 20.3.58.1000 and OnBase releases 21.1.1.1000 through 21.1.15.1000... |
| CVE-2022-33119 | MEDIUM | 6.1 | 1.5% | Jun 21, 2022 | NUUO Network Video Recorder NVRsolo v03.06.02 was discovered to contain a reflected cross-site scripting (XSS) vulnerabi... |
| CVE-2022-32414 | MEDIUM | 5.5 | 0.6% | Jun 21, 2022 | Nginx NJS v0.7.2 was discovered to contain a segmentation violation in the function njs_vmcode_interpreter at src/njs_vm... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now