2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-30760 | MEDIUM | 4.3 | 0.9% | Jun 9, 2022 | An Insecure Direct Object Reference (IDOR) issue in fn2Web in ihb eG FlexNow before 2.04.09.016 allows remote authentica... |
| CVE-2022-2020 | MEDIUM | 4.8 | 0.6% | Jun 9, 2022 | A vulnerability, which was classified as problematic, has been found in SourceCodester Prison Management System 1.0. Aff... |
| CVE-2022-2016 | MEDIUM | 5.4 | 0.6% | Jun 9, 2022 | Cross-site Scripting (XSS) - Reflected in GitHub repository neorazorx/facturascripts prior to 2022.1. |
| CVE-2022-24969 | MEDIUM | 6.1 | 1.7% | Jun 9, 2022 | bypass CVE-2021-25640 > In Apache Dubbo prior to 2.6.12 and 2.7.15, the usage of parseURL method will lead to the bypass... |
| CVE-2022-0823 | MEDIUM | 6.2 | 0.2% | Jun 9, 2022 | An improper control of interaction frequency vulnerability in Zyxel GS1200 series switches could allow a local attacker ... |
| CVE-2022-2035 | MEDIUM | 6.1 | 0.7% | Jun 9, 2022 | A reflected cross-site scripting (XSS) vulnerability exists in the playerConfUrl parameter in the /defaultui/player/mode... |
| CVE-2022-31030 | MEDIUM | 5.5 | 0.4% | Jun 9, 2022 | containerd is an open source container runtime. A bug was found in the containerd's CRI implementation where programs in... |
| CVE-2022-31027 | MEDIUM | 6.5 | 0.4% | Jun 9, 2022 | OAuthenticator is an OAuth token library for the JupyerHub login handler. CILogonOAuthenticator is provided by the OAuth... |
| CVE-2022-29254 | MEDIUM | 6.5 | 0.6% | Jun 9, 2022 | silverstripe-omnipay is a SilverStripe integration with Omnipay PHP payments library. For a subset of Omnipay gateways (... |
| CVE-2022-24896 | MEDIUM | 4.3 | 0.7% | Jun 9, 2022 | Tuleap is a Free & Open Source Suite to manage software developments and collaboration. In versions prior to 13.7.99.239... |
| CVE-2022-32195 | MEDIUM | 6.1 | 2.3% | Jun 9, 2022 | Open edX platform before 2022-06-06 allows XSS via the "next" parameter in the logout URL. |
| CVE-2022-25807 | MEDIUM | 5.5 | 0.3% | Jun 9, 2022 | An issue was discovered in the IGEL Universal Management Suite (UMS) 6.07.100. A hardcoded DES key in the LDAPDesPWEncry... |
| CVE-2022-25805 | MEDIUM | 6.5 | 0.5% | Jun 9, 2022 | An issue was discovered in the IGEL Universal Management Suite (UMS) 6.07.100. The transmission of cleartext LDAP bind c... |
| CVE-2022-25804 | MEDIUM | 5.5 | 0.3% | Jun 9, 2022 | An issue was discovered in the IGEL Universal Management Suite (UMS) 6.07.100. Insecure permissions for the serverconfig... |
| CVE-2022-30875 | MEDIUM | 6.1 | 0.7% | Jun 8, 2022 | Dolibarr 12.0.5 is vulnerable to Cross Site Scripting (XSS) via Sql Error Page. |
| CVE-2022-28386 | MEDIUM | 4.6 | 0.5% | Jun 8, 2022 | An issue was discovered in certain Verbatim drives through 2022-03-31. The security feature for lockout (e.g., requiring... |
| CVE-2022-32273 | MEDIUM | 4.3 | 0.7% | Jun 8, 2022 | As a result of an observable discrepancy in returned messages, OPSWAT MetaDefender Core (MDCore) before 5.1.2 could allo... |
| CVE-2022-30899 | MEDIUM | 4.8 | 0.4% | Jun 8, 2022 | A Cross Site Scripting vulnerabilty exists in PartKeepr 1.4.0 via the 'name' field in /api/part_categories. |
| CVE-2022-28387 | MEDIUM | 4.6 | 0.5% | Jun 8, 2022 | An issue was discovered in certain Verbatim drives through 2022-03-31. Due to an insecure design, they can be unlocked b... |
| CVE-2022-28385 | MEDIUM | 4.6 | 0.3% | Jun 8, 2022 | An issue was discovered in certain Verbatim drives through 2022-03-31. Due to missing integrity checks, an attacker can ... |
| CVE-2022-28384 | MEDIUM | 5.5 | 0.4% | Jun 8, 2022 | An issue was discovered in certain Verbatim drives through 2022-03-31. Due to an insecure design, they allow an offline ... |
| CVE-2022-28383 | MEDIUM | 6.8 | 0.6% | Jun 8, 2022 | An issue was discovered in certain Verbatim drives through 2022-03-31. Due to insufficient firmware validation, an attac... |
| CVE-2022-1997 | MEDIUM | 5.4 | 0.6% | Jun 8, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository francoisjacquet/rosariosis prior to 9.0. |
| CVE-2022-30552 | MEDIUM | 5.5 | 0.4% | Jun 8, 2022 | Das U-Boot 2022.01 has a Buffer Overflow. |
| CVE-2022-31497 | MEDIUM | 6.1 | 0.9% | Jun 8, 2022 | LibreHealth EHR Base 2.0.0 allows interface/main/finder/finder_navigation.php patient XSS. |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now