2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-24238 | MEDIUM | 6.1 | 0.7% | Jun 2, 2022 | ACEweb Online Portal 3.5.065 was discovered to contain a cross-site scripting (XSS) vulnerability via the txtNmName1 par... |
| CVE-2022-23237 | MEDIUM | 6.1 | 0.6% | Jun 2, 2022 | E-Series SANtricity OS Controller Software 11.x versions through 11.70.2 are vulnerable to host header injection attacks... |
| CVE-2022-23236 | MEDIUM | 4.4 | 0.2% | Jun 2, 2022 | E-Series SANtricity OS Controller Software versions 11.40 through 11.70.2 store the LDAP BIND password in plaintext with... |
| CVE-2022-1789 | MEDIUM | 6.8 | 0.3% | Jun 2, 2022 | With shadow paging enabled, the INVPCID instruction results in a call to kvm_mmu_invpcid_gva. If INVPCID is executed wit... |
| CVE-2022-1462 | MEDIUM | 6.3 | 0.3% | Jun 2, 2022 | An out-of-bounds read flaw was found in the Linux kernel’s TeleTYpe subsystem. The issue occurs in how a user triggers a... |
| CVE-2022-29236 | MEDIUM | 4.3 | 0.8% | Jun 2, 2022 | BigBlueButton is an open source web conferencing system. Starting in version 2.2 and prior to versions 2.3.18 and 2.4-rc... |
| CVE-2022-29235 | MEDIUM | 5.3 | 1.0% | Jun 2, 2022 | BigBlueButton is an open source web conferencing system. Starting in version 2.2 and prior to versions 2.3.18 and 2.4-rc... |
| CVE-2022-29234 | MEDIUM | 4.3 | 0.8% | Jun 2, 2022 | BigBlueButton is an open source web conferencing system. Starting in version 2.2 and prior to versions 2.3.18 and 2.4.1,... |
| CVE-2022-29233 | MEDIUM | 4.3 | 1.0% | Jun 2, 2022 | BigBlueButton is an open source web conferencing system. In BigBlueButton starting with 2.2 but before 2.3.18 and 2.4-rc... |
| CVE-2022-29232 | MEDIUM | 6.5 | 1.0% | Jun 1, 2022 | BigBlueButton is an open source web conferencing system. Starting with version 2.2 and prior to versions 2.3.9 and 2.4-b... |
| CVE-2022-31022 | MEDIUM | 5.5 | 0.3% | Jun 1, 2022 | Bleve is a text indexing library for go. Bleve includes HTTP utilities under bleve/http package, that are used by its sa... |
| CVE-2022-26905 | MEDIUM | 4.3 | 1.7% | Jun 1, 2022 | Microsoft Edge (Chromium-based) Spoofing Vulnerability |
| CVE-2022-31000 | MEDIUM | 4.3 | 0.4% | Jun 1, 2022 | solidus_backend is the admin interface for the Solidus e-commerce framework. Versions prior to 3.1.6, 3.0.6, and 2.11.16... |
| CVE-2022-1285 | MEDIUM | 6.5 | 1.2% | Jun 1, 2022 | Server-Side Request Forgery (SSRF) in GitHub repository gogs/gogs prior to 0.12.8. |
| CVE-2022-31015 | MEDIUM | 5.9 | 1.3% | May 31, 2022 | Waitress is a Web Server Gateway Interface server for Python 2 and 3. Waitress versions 2.1.0 and 2.1.1 may terminate ea... |
| CVE-2022-1947 | MEDIUM | 6.5 | 1.2% | May 31, 2022 | Use of Incorrect Operator in GitHub repository polonel/trudesk prior to 1.2.3. |
| CVE-2022-1893 | MEDIUM | 5.3 | 0.8% | May 31, 2022 | Improper Removal of Sensitive Information Before Storage or Transfer in GitHub repository polonel/trudesk prior to 1.2.3... |
| CVE-2022-29258 | MEDIUM | 6.1 | 0.9% | May 31, 2022 | XWiki Platform Filter UI provides a generic user interface to convert from a XWiki Filter input stream to an output stre... |
| CVE-2022-29245 | MEDIUM | 5.9 | 1.4% | May 31, 2022 | SSH.NET is a Secure Shell (SSH) library for .NET. In versions 2020.0.0 and 2020.0.1, during an `X25519` key exchange, th... |
| CVE-2022-29243 | MEDIUM | 4.3 | 1.4% | May 31, 2022 | Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform. Prior to versions 22.2.... |
| CVE-2022-29220 | MEDIUM | 6.5 | 0.5% | May 31, 2022 | github-action-merge-dependabot is an action that automatically approves and merges dependabot pull requests (PRs). Prior... |
| CVE-2022-22361 | MEDIUM | 6.5 | 0.3% | May 31, 2022 | IBM Business Automation Workflow traditional 21.0.1 through 21.0.3, 20.0.0.1 through 20.0.0.2, 19.0.0.1 through 19.0.0.3... |
| CVE-2022-30973 | MEDIUM | 5.5 | 1.9% | May 31, 2022 | We failed to apply the fix for CVE-2022-30126 to the 1.x branch in the 1.28.2 release. In Apache Tika, a regular express... |
| CVE-2022-1926 | MEDIUM | 4.9 | 0.9% | May 31, 2022 | Integer Overflow or Wraparound in GitHub repository polonel/trudesk prior to 1.2.3. |
| CVE-2022-1646 | MEDIUM | 4.8 | 0.6% | May 30, 2022 | The Simple Real Estate Pack WordPress plugin through 1.4.8 does not sanitise and escape some of its settings, which coul... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now