2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-21749 | MEDIUM | 5.5 | 0.1% | Jun 6, 2022 | In telephony, there is a possible information disclosure due to a missing permission check. This could lead to local inf... |
| CVE-2022-21748 | MEDIUM | 5.5 | 0.1% | Jun 6, 2022 | In telephony, there is a possible information disclosure due to a missing permission check. This could lead to local inf... |
| CVE-2022-21747 | MEDIUM | 4.4 | 0.1% | Jun 6, 2022 | In imgsensor, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of s... |
| CVE-2022-21746 | MEDIUM | 4.4 | 0.1% | Jun 6, 2022 | In imgsensor, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of s... |
| CVE-2022-31485 | MEDIUM | 5.3 | 0.8% | Jun 6, 2022 | An unauthenticated attacker can send a specially crafted packets to update the “notes” section of the home page of the w... |
| CVE-2022-1940 | MEDIUM | 5.4 | 6.3% | Jun 6, 2022 | A Stored Cross-Site Scripting vulnerability in Jira integration in GitLab EE affecting all versions from 13.11 prior to ... |
| CVE-2022-1936 | MEDIUM | 6.5 | 0.7% | Jun 6, 2022 | Incorrect authorization in GitLab EE affecting all versions from 12.0 before 14.9.5, all versions starting from 14.10 be... |
| CVE-2022-1935 | MEDIUM | 6.5 | 0.7% | Jun 6, 2022 | Incorrect authorization in GitLab EE affecting all versions from 12.0 before 14.9.5, all versions starting from 14.10 be... |
| CVE-2022-1821 | MEDIUM | 4.3 | 0.8% | Jun 6, 2022 | An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.8 before 14.9.5, all versions start... |
| CVE-2022-30863 | MEDIUM | 4.8 | 0.5% | Jun 6, 2022 | FUDForum 3.1.2 is vulnerable to Cross Site Scripting (XSS) via page_title param in Page Manager in the Admin Control Pan... |
| CVE-2022-30861 | MEDIUM | 4.8 | 0.5% | Jun 6, 2022 | FUDforum 3.1.2 is vulnerable to Stored XSS via Forum Name field in Forum Manager Feature. |
| CVE-2022-29784 | MEDIUM | 5.3 | 1.1% | Jun 3, 2022 | PublicCMS V4.0.202204.a and below contains an information leak via the component /views/directive/sys/SysConfigDataDirec... |
| CVE-2022-29773 | MEDIUM | 6.5 | 0.7% | Jun 3, 2022 | An access control issue in aleksis/core/util/auth_helpers.py: ClientProtectedResourceMixin of AlekSIS-Core v2.8.1 and be... |
| CVE-2022-29770 | MEDIUM | 5.4 | 0.5% | Jun 3, 2022 | XXL-Job v2.3.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via /xxl-job-admin/jobinfo. |
| CVE-2022-1988 | MEDIUM | 6.1 | 0.7% | Jun 3, 2022 | Cross-site Scripting (XSS) - Generic in GitHub repository neorazorx/facturascripts prior to 2022.09. |
| CVE-2022-32265 | MEDIUM | 5.3 | 1.2% | Jun 3, 2022 | qDecoder before 12.1.0 does not ensure that the percent character is followed by two hex digits for URL decoding. |
| CVE-2022-29767 | MEDIUM | 6.5 | 0.9% | Jun 3, 2022 | adbyby v2.7 allows external users to make connections via port 8118. This can cause a program logic error and lead to a ... |
| CVE-2022-30233 | MEDIUM | 6.5 | 0.7% | Jun 2, 2022 | A CWE-20: Improper Input Validation vulnerability exists that could allow the product to be maliciously manipulated when... |
| CVE-2022-31461 | MEDIUM | 6.5 | 0.8% | Jun 2, 2022 | Owl Labs Meeting Owl 5.2.0.15 allows attackers to deactivate the passcode protection mechanism via a certain c 11 messag... |
| CVE-2022-31459 | MEDIUM | 6.5 | 0.8% | Jun 2, 2022 | Owl Labs Meeting Owl 5.2.0.15 allows attackers to retrieve the passcode hash via a certain c 10 value over Bluetooth. |
| CVE-2022-29718 | MEDIUM | 6.1 | 1.0% | Jun 2, 2022 | Caddy v2.4 was discovered to contain an open redirect vulnerability. A remote unauthenticated attacker may exploit this ... |
| CVE-2022-29085 | MEDIUM | 6.7 | 0.2% | Jun 2, 2022 | Dell Unity, Dell UnityVSA, and Dell Unity XT versions prior to 5.2.0.0.5.173 contain a plain-text password storage vulne... |
| CVE-2022-26866 | MEDIUM | 5.5 | 0.4% | Jun 2, 2022 | Dell PowerStore Versions before v2.1.1.0. contains a Stored Cross-Site Scripting vulnerability. A high privileged networ... |
| CVE-2022-31024 | MEDIUM | 6.5 | 0.6% | Jun 2, 2022 | richdocuments is the repository for NextCloud Collabra, the app for Nextcloud Office collaboration. Prior to versions 6.... |
| CVE-2022-30429 | MEDIUM | 5.4 | 0.6% | Jun 2, 2022 | Multiple cross-site scripting (XSS) vulnerabilities in Neos CMS allow attackers with the editor role or higher to inject... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now