2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-31282 | MEDIUM | 5.5 | 0.6% | Jun 10, 2022 | Bento4 MP4Dump v1.2 was discovered to contain a segmentation violation via an unknown address at /Source/C++/Core/Ap4Dat... |
| CVE-2022-31402 | MEDIUM | 6.1 | 2.1% | Jun 10, 2022 | ITOP v3.0.1 was discovered to contain a cross-site scripting (XSS) vulnerability via /itop/webservices/export-v2.php. |
| CVE-2022-29948 | MEDIUM | 4.6 | 0.5% | Jun 10, 2022 | Due to an insecure design, the Lepin EP-KP001 flash drive through KP001_V19 is vulnerable to an authentication bypass at... |
| CVE-2022-31769 | MEDIUM | 5.3 | 1.1% | Jun 10, 2022 | IBM Spectrum Copy Data Management 2.2.0.0 through 2.2.15.0 could allow a remote attacker to view product configuration i... |
| CVE-2022-30611 | MEDIUM | 5.4 | 0.6% | Jun 10, 2022 | IBM Spectrum Copy Data Management 2.2.0.0 through 2.2.15.0 is vulnerable to cross-site scripting, caused by improper val... |
| CVE-2022-30610 | MEDIUM | 4.5 | 0.5% | Jun 10, 2022 | IBM Spectrum Copy Data Management 2.2.0.0 through 2.2.15.0 is vulnerable to reverse tabnabbing where it could allow a pa... |
| CVE-2022-32978 | MEDIUM | 6.5 | 0.8% | Jun 10, 2022 | There is an assertion failure in SingleComponentLSScan::ParseMCU in singlecomponentlsscan.cpp in libjpeg before 1.64 via... |
| CVE-2022-30702 | MEDIUM | 5.5 | 0.3% | Jun 9, 2022 | Trend Micro Security 2022 and 2021 (Consumer) is vulnerable to an Out-Of-Bounds Read Information Disclosure vulnerabilit... |
| CVE-2022-21499 | MEDIUM | 6.7 | 0.6% | Jun 9, 2022 | KGDB and KDB allow read and write access to kernel memory, and thus should be restricted during lockdown. An attacker wi... |
| CVE-2022-29250 | MEDIUM | 6.5 | 0.7% | Jun 9, 2022 | GLPI is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and... |
| CVE-2022-30898 | MEDIUM | 6.5 | 0.5% | Jun 9, 2022 | A Cross-site request forgery (CSRF) vulnerability in Cscms music portal system v4.2 allows remote attackers to change th... |
| CVE-2022-29224 | MEDIUM | 5.9 | 0.9% | Jun 9, 2022 | Envoy is a cloud-native high-performance proxy. Versions of envoy prior to 1.22.1 are subject to a segmentation fault in... |
| CVE-2022-24876 | MEDIUM | 5.4 | 0.5% | Jun 9, 2022 | GLPI is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and... |
| CVE-2022-31038 | MEDIUM | 5.4 | 0.7% | Jun 9, 2022 | Gogs is an open source self-hosted Git service. In versions of gogs prior to 0.12.9 `DisplayName` does not filter charac... |
| CVE-2022-2036 | MEDIUM | 5.4 | 0.8% | Jun 9, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository francoisjacquet/rosariosis prior to 9.0.1. |
| CVE-2022-2029 | MEDIUM | 5.4 | 0.7% | Jun 9, 2022 | Cross-site Scripting (XSS) - DOM in GitHub repository kromitgmbh/titra prior to 0.77.0. |
| CVE-2022-2028 | MEDIUM | 5.4 | 0.7% | Jun 9, 2022 | Cross-site Scripting (XSS) - Generic in GitHub repository kromitgmbh/titra prior to 0.77.0. |
| CVE-2022-2026 | MEDIUM | 5.4 | 0.7% | Jun 9, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository kromitgmbh/titra prior to 0.77.0. |
| CVE-2022-2015 | MEDIUM | 5.4 | 0.6% | Jun 9, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository jgraph/drawio prior to 19.0.2. |
| CVE-2022-2014 | MEDIUM | 5.4 | 0.7% | Jun 9, 2022 | Code Injection in GitHub repository jgraph/drawio prior to 19.0.2. |
| CVE-2022-28614 | MEDIUM | 5.3 | 4.4% | Jun 9, 2022 | The ap_rwrite() function in Apache HTTP Server 2.4.53 and earlier may read unintended memory if an attacker can cause th... |
| CVE-2022-28330 | MEDIUM | 5.3 | 3.4% | Jun 9, 2022 | Apache HTTP Server 2.4.53 and earlier on Windows may read beyond bounds when configured to process requests with the mod... |
| CVE-2022-26364 | MEDIUM | 6.7 | 0.5% | Jun 9, 2022 | x86 pv: Insufficient care with non-coherent mappings T[his CNA information record relates to multiple CVEs; the text exp... |
| CVE-2022-26363 | MEDIUM | 6.7 | 0.3% | Jun 9, 2022 | x86 pv: Insufficient care with non-coherent mappings T[his CNA information record relates to multiple CVEs; the text exp... |
| CVE-2022-26362 | MEDIUM | 6.4 | 0.4% | Jun 9, 2022 | x86 pv: Race condition in typeref acquisition Xen maintains a type reference count for pages, in addition to a regular r... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now