2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-1754 | MEDIUM | 6.5 | 1.0% | May 20, 2022 | Integer Overflow or Wraparound in GitHub repository polonel/trudesk prior to 1.2.2. |
| CVE-2022-28987 | MEDIUM | 5.3 | 9.7% | May 20, 2022 | Zoho ManageEngine ADSelfService Plus before 6202 allows attackers to perform username enumeration via a crafted POST req... |
| CVE-2022-28985 | MEDIUM | 5.4 | 0.5% | May 20, 2022 | A stored cross-site scripting (XSS) vulnerability in the addNewPost component of OrangeHRM v4.10.1 allows attackers to e... |
| CVE-2022-28965 | MEDIUM | 6.5 | 0.3% | May 20, 2022 | Multiple DLL hijacking vulnerabilities via the components instup.exe and wsc_proxy.exe in Avast Premium Security before ... |
| CVE-2022-29652 | MEDIUM | 6.1 | 0.8% | May 19, 2022 | Online Sports Complex Booking System 1.0 is vulnerable to SQL Injection via /scbs/classes/Users.php?f=save_client. |
| CVE-2022-28959 | MEDIUM | 6.1 | 1.5% | May 19, 2022 | Multiple cross-site scripting (XSS) vulnerabilities in the component /spip.php of Spip Web Framework v3.1.13 and below a... |
| CVE-2022-1416 | MEDIUM | 5.4 | 0.7% | May 19, 2022 | Missing sanitization of data in Pipeline error messages in GitLab CE/EE affecting all versions starting from 1.0.2 befor... |
| CVE-2022-29449 | MEDIUM | 5.4 | 0.5% | May 19, 2022 | Authenticated (contributor or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in Opal Hotel Room Booki... |
| CVE-2022-22976 | MEDIUM | 5.3 | 2.1% | May 19, 2022 | Spring Security versions 5.5.x prior to 5.5.7, 5.6.x prior to 5.6.4, and earlier unsupported versions contain an integer... |
| CVE-2022-1730 | MEDIUM | 4.6 | 0.6% | May 19, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository jgraph/drawio prior to 18.0.4. |
| CVE-2022-29230 | MEDIUM | 5.4 | 0.7% | May 18, 2022 | Hydrogen is a React-based framework for building dynamic, Shopify-powered custom storefronts. There is a potential Cross... |
| CVE-2022-1774 | MEDIUM | 6.1 | 1.1% | May 18, 2022 | Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository jgraph/drawio prior to 18.0.7. |
| CVE-2022-30992 | MEDIUM | 6.1 | 0.5% | May 18, 2022 | Open redirect via user-controlled query parameter. The following products are affected: Acronis Cyber Protect 15 (Linux,... |
| CVE-2022-30991 | MEDIUM | 6.1 | 0.5% | May 18, 2022 | HTML injection via report name. The following products are affected: Acronis Cyber Protect 15 (Linux, Windows) before bu... |
| CVE-2022-1771 | MEDIUM | 5.5 | 1.2% | May 18, 2022 | Uncontrolled Recursion in GitHub repository vim/vim prior to 8.2.4975. |
| CVE-2022-30598 | MEDIUM | 4.3 | 1.0% | May 18, 2022 | A flaw was found in moodle where global search results could include author information on some activities where a user ... |
| CVE-2022-30597 | MEDIUM | 5.3 | 1.2% | May 18, 2022 | A flaw was found in moodle where the description user field was not hidden when being set as a hidden user field. |
| CVE-2022-30111 | MEDIUM | 6.8 | 0.3% | May 18, 2022 | Due to the use of an insecure algorithm for rolling codes in MCK Smartlock 1.0, allows attackers to unlock the mechanism... |
| CVE-2022-28921 | MEDIUM | 6.5 | 0.7% | May 18, 2022 | A Cross-Site Request Forgery (CSRF) vulnerability discovered in BlogEngine.Net v3.3.8.0 allows unauthenticated attackers... |
| CVE-2022-25617 | MEDIUM | 6.1 | 0.8% | May 18, 2022 | Reflected Cross-Site Scripting (XSS) vulnerability in Code Snippets plugin <= 2.14.3 at WordPress via &orderby vulnerabl... |
| CVE-2022-30596 | MEDIUM | 5.4 | 0.8% | May 18, 2022 | A flaw was found in moodle where ID numbers displayed when bulk allocating markers to assignments required additional sa... |
| CVE-2022-28924 | MEDIUM | 6.5 | 0.9% | May 18, 2022 | An information disclosure vulnerability in UniverSIS-Students before v1.5.0 allows attackers to obtain sensitive informa... |
| CVE-2022-25162 | MEDIUM | 5.3 | 2.4% | May 18, 2022 | Improper Input Validation vulnerability in Mitsubishi Electric MELSEC iQ-F series FX5U-xMy/z(x=32,64,80, y=T,R, z=ES,DS,... |
| CVE-2022-22777 | MEDIUM | 6.1 | 0.6% | May 18, 2022 | The Web Server component of TIBCO Software Inc.'s TIBCO BusinessConnect Trading Community Management contains easily exp... |
| CVE-2022-22776 | MEDIUM | 5.4 | 0.5% | May 18, 2022 | The Web Server component of TIBCO Software Inc.'s TIBCO BusinessConnect Trading Community Management contains easily exp... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now