2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-20809 | MEDIUM | 6.5 | 0.9% | May 26, 2022 | Multiple vulnerabilities in the API and web-based management interfaces of Cisco Expressway Series and Cisco TelePresenc... |
| CVE-2022-31651 | MEDIUM | 5.5 | 1.1% | May 25, 2022 | In SoX 14.4.2, there is an assertion failure in rate_init in rate.c in libsox.a. |
| CVE-2022-31650 | MEDIUM | 5.5 | 1.1% | May 25, 2022 | In SoX 14.4.2, there is a floating-point exception in lsx_aiffstartwrite in aiff.c in libsox.a. |
| CVE-2022-29256 | MEDIUM | 6.7 | 0.4% | May 25, 2022 | sharp is an application for Node.js image processing. Prior to version 0.30.5, there is a possible vulnerability in logi... |
| CVE-2022-31624 | MEDIUM | 5.5 | 0.2% | May 25, 2022 | MariaDB Server before 10.7 is vulnerable to Denial of Service. While executing the plugin/server_audit/server_audit.c me... |
| CVE-2022-31623 | MEDIUM | 5.5 | 0.2% | May 25, 2022 | MariaDB Server before 10.7 is vulnerable to Denial of Service. In extra/mariabackup/ds_compress.cc, when an error occurs... |
| CVE-2022-31622 | MEDIUM | 5.5 | 0.2% | May 25, 2022 | MariaDB Server before 10.7 is vulnerable to Denial of Service. In extra/mariabackup/ds_compress.cc, when an error occurs... |
| CVE-2022-31621 | MEDIUM | 5.5 | 0.2% | May 25, 2022 | MariaDB Server before 10.7 is vulnerable to Denial of Service. In extra/mariabackup/ds_xbstream.cc, when an error occurs... |
| CVE-2022-31620 | MEDIUM | 6.5 | 1.3% | May 25, 2022 | In libjpeg before 1.64, BitStream<false>::Get in bitstream.hpp has an assertion failure that may cause denial of service... |
| CVE-2022-29252 | MEDIUM | 6.1 | 0.9% | May 25, 2022 | XWiki Platform Wiki UI Main Wiki is a package for managing subwikis. Starting with version 5.3-milestone-2, XWiki Platfo... |
| CVE-2022-29251 | MEDIUM | 6.1 | 1.3% | May 25, 2022 | XWiki Platform Flamingo Theme UI is a tool that allows customization and preview of any Flamingo-based skin. Starting wi... |
| CVE-2022-29402 | MEDIUM | 6.8 | 0.4% | May 25, 2022 | TP-Link TL-WR840N EU v6.20 was discovered to contain insecure protections for its UART console. This vulnerability allow... |
| CVE-2022-29408 | MEDIUM | 6.1 | 0.7% | May 25, 2022 | Persistent Cross-Site Scripting (XSS) vulnerability in Vsourz Digital's Advanced Contact form 7 DB plugin <= 1.8.7 at Wo... |
| CVE-2022-28875 | MEDIUM | 6.5 | 0.5% | May 25, 2022 | A Denial-of-Service (DoS) vulnerability was discovered in F-Secure Atlant and in certain WithSecure products whereby the... |
| CVE-2022-1348 | MEDIUM | 6.5 | 1.5% | May 25, 2022 | A vulnerability was found in logrotate in how the state file is created. The state file is used to prevent parallel exec... |
| CVE-2022-29380 | MEDIUM | 4.8 | 0.6% | May 25, 2022 | Academy-LMS v4.3 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the SEO panel. |
| CVE-2022-21951 | MEDIUM | 6.8 | 0.4% | May 25, 2022 | A Cleartext Transmission of Sensitive Information vulnerability in SUSE Rancher, Rancher allows attackers on the network... |
| CVE-2022-29405 | MEDIUM | 6.5 | 1.6% | May 25, 2022 | In Apache Archiva, any registered user can reset password for any users. This is fixed in Archiva 2.2.8 |
| CVE-2022-29710 | MEDIUM | 6.1 | 0.7% | May 25, 2022 | A cross-site scripting (XSS) vulnerability in uploadConfirm.php of LimeSurvey v5.3.9 and below allows attackers to execu... |
| CVE-2022-29362 | MEDIUM | 5.4 | 0.5% | May 25, 2022 | A cross-site scripting (XSS) vulnerability in /navigation/create?ParentID=%23 of ZKEACMS v3.5.2 allows attackers to exec... |
| CVE-2022-29359 | MEDIUM | 6.1 | 1.1% | May 25, 2022 | A stored cross-site scripting (XSS) vulnerability in /scas/?page=clubs/application_form&id=7 of School Club Application ... |
| CVE-2022-29358 | MEDIUM | 5.5 | 0.6% | May 25, 2022 | epub2txt2 v2.04 was discovered to contain an integer overflow via the function bug in _parse_special_tag at sxmlc.c. Thi... |
| CVE-2022-29349 | MEDIUM | 6.1 | 1.7% | May 25, 2022 | kkFileView v4.0.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the url parameter at /control... |
| CVE-2022-22309 | MEDIUM | 6.8 | 0.2% | May 24, 2022 | The POWER systems FSP is vulnerable to unauthenticated logins through the serial port/TTY interface. This vulnerability ... |
| CVE-2022-1849 | MEDIUM | 5.4 | 0.7% | May 24, 2022 | Session Fixation in GitHub repository filegator/filegator prior to 7.8.0. |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now