2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-31282MEDIUM5.5Bento4 MP4Dump v1.2 was discovered to contain a segmentation violation via an unknown address at /Source/C++/Core/Ap4Dat...
CVE-2022-31402MEDIUM6.1ITOP v3.0.1 was discovered to contain a cross-site scripting (XSS) vulnerability via /itop/webservices/export-v2.php.
CVE-2022-29948MEDIUM4.6Due to an insecure design, the Lepin EP-KP001 flash drive through KP001_V19 is vulnerable to an authentication bypass at...
CVE-2022-31769MEDIUM5.3IBM Spectrum Copy Data Management 2.2.0.0 through 2.2.15.0 could allow a remote attacker to view product configuration i...
CVE-2022-30611MEDIUM5.4IBM Spectrum Copy Data Management 2.2.0.0 through 2.2.15.0 is vulnerable to cross-site scripting, caused by improper val...
CVE-2022-30610MEDIUM4.5IBM Spectrum Copy Data Management 2.2.0.0 through 2.2.15.0 is vulnerable to reverse tabnabbing where it could allow a pa...
CVE-2022-32978MEDIUM6.5There is an assertion failure in SingleComponentLSScan::ParseMCU in singlecomponentlsscan.cpp in libjpeg before 1.64 via...
CVE-2022-30702MEDIUM5.5Trend Micro Security 2022 and 2021 (Consumer) is vulnerable to an Out-Of-Bounds Read Information Disclosure vulnerabilit...
CVE-2022-21499MEDIUM6.7KGDB and KDB allow read and write access to kernel memory, and thus should be restricted during lockdown. An attacker wi...
CVE-2022-29250MEDIUM6.5GLPI is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and...
CVE-2022-30898MEDIUM6.5A Cross-site request forgery (CSRF) vulnerability in Cscms music portal system v4.2 allows remote attackers to change th...
CVE-2022-29224MEDIUM5.9Envoy is a cloud-native high-performance proxy. Versions of envoy prior to 1.22.1 are subject to a segmentation fault in...
CVE-2022-24876MEDIUM5.4GLPI is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and...
CVE-2022-31038MEDIUM5.4Gogs is an open source self-hosted Git service. In versions of gogs prior to 0.12.9 `DisplayName` does not filter charac...
CVE-2022-2036MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository francoisjacquet/rosariosis prior to 9.0.1.
CVE-2022-2029MEDIUM5.4Cross-site Scripting (XSS) - DOM in GitHub repository kromitgmbh/titra prior to 0.77.0.
CVE-2022-2028MEDIUM5.4Cross-site Scripting (XSS) - Generic in GitHub repository kromitgmbh/titra prior to 0.77.0.
CVE-2022-2026MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository kromitgmbh/titra prior to 0.77.0.
CVE-2022-2015MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository jgraph/drawio prior to 19.0.2.
CVE-2022-2014MEDIUM5.4Code Injection in GitHub repository jgraph/drawio prior to 19.0.2.
CVE-2022-28614MEDIUM5.3The ap_rwrite() function in Apache HTTP Server 2.4.53 and earlier may read unintended memory if an attacker can cause th...
CVE-2022-28330MEDIUM5.3Apache HTTP Server 2.4.53 and earlier on Windows may read beyond bounds when configured to process requests with the mod...
CVE-2022-26364MEDIUM6.7x86 pv: Insufficient care with non-coherent mappings T[his CNA information record relates to multiple CVEs; the text exp...
CVE-2022-26363MEDIUM6.7x86 pv: Insufficient care with non-coherent mappings T[his CNA information record relates to multiple CVEs; the text exp...
CVE-2022-26362MEDIUM6.4x86 pv: Race condition in typeref acquisition Xen maintains a type reference count for pages, in addition to a regular r...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now