2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-24238MEDIUM6.1ACEweb Online Portal 3.5.065 was discovered to contain a cross-site scripting (XSS) vulnerability via the txtNmName1 par...
CVE-2022-23237MEDIUM6.1E-Series SANtricity OS Controller Software 11.x versions through 11.70.2 are vulnerable to host header injection attacks...
CVE-2022-23236MEDIUM4.4E-Series SANtricity OS Controller Software versions 11.40 through 11.70.2 store the LDAP BIND password in plaintext with...
CVE-2022-1789MEDIUM6.8With shadow paging enabled, the INVPCID instruction results in a call to kvm_mmu_invpcid_gva. If INVPCID is executed wit...
CVE-2022-1462MEDIUM6.3An out-of-bounds read flaw was found in the Linux kernel’s TeleTYpe subsystem. The issue occurs in how a user triggers a...
CVE-2022-29236MEDIUM4.3BigBlueButton is an open source web conferencing system. Starting in version 2.2 and prior to versions 2.3.18 and 2.4-rc...
CVE-2022-29235MEDIUM5.3BigBlueButton is an open source web conferencing system. Starting in version 2.2 and prior to versions 2.3.18 and 2.4-rc...
CVE-2022-29234MEDIUM4.3BigBlueButton is an open source web conferencing system. Starting in version 2.2 and prior to versions 2.3.18 and 2.4.1,...
CVE-2022-29233MEDIUM4.3BigBlueButton is an open source web conferencing system. In BigBlueButton starting with 2.2 but before 2.3.18 and 2.4-rc...
CVE-2022-29232MEDIUM6.5BigBlueButton is an open source web conferencing system. Starting with version 2.2 and prior to versions 2.3.9 and 2.4-b...
CVE-2022-31022MEDIUM5.5Bleve is a text indexing library for go. Bleve includes HTTP utilities under bleve/http package, that are used by its sa...
CVE-2022-26905MEDIUM4.3Microsoft Edge (Chromium-based) Spoofing Vulnerability
CVE-2022-31000MEDIUM4.3solidus_backend is the admin interface for the Solidus e-commerce framework. Versions prior to 3.1.6, 3.0.6, and 2.11.16...
CVE-2022-1285MEDIUM6.5Server-Side Request Forgery (SSRF) in GitHub repository gogs/gogs prior to 0.12.8.
CVE-2022-31015MEDIUM5.9Waitress is a Web Server Gateway Interface server for Python 2 and 3. Waitress versions 2.1.0 and 2.1.1 may terminate ea...
CVE-2022-1947MEDIUM6.5Use of Incorrect Operator in GitHub repository polonel/trudesk prior to 1.2.3.
CVE-2022-1893MEDIUM5.3Improper Removal of Sensitive Information Before Storage or Transfer in GitHub repository polonel/trudesk prior to 1.2.3...
CVE-2022-29258MEDIUM6.1XWiki Platform Filter UI provides a generic user interface to convert from a XWiki Filter input stream to an output stre...
CVE-2022-29245MEDIUM5.9SSH.NET is a Secure Shell (SSH) library for .NET. In versions 2020.0.0 and 2020.0.1, during an `X25519` key exchange, th...
CVE-2022-29243MEDIUM4.3Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform. Prior to versions 22.2....
CVE-2022-29220MEDIUM6.5github-action-merge-dependabot is an action that automatically approves and merges dependabot pull requests (PRs). Prior...
CVE-2022-22361MEDIUM6.5IBM Business Automation Workflow traditional 21.0.1 through 21.0.3, 20.0.0.1 through 20.0.0.2, 19.0.0.1 through 19.0.0.3...
CVE-2022-30973MEDIUM5.5We failed to apply the fix for CVE-2022-30126 to the 1.x branch in the 1.28.2 release. In Apache Tika, a regular express...
CVE-2022-1926MEDIUM4.9Integer Overflow or Wraparound in GitHub repository polonel/trudesk prior to 1.2.3.
CVE-2022-1646MEDIUM4.8The Simple Real Estate Pack WordPress plugin through 1.4.8 does not sanitise and escape some of its settings, which coul...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now