2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-23137 | MEDIUM | 6.1 | 0.5% | May 11, 2022 | ZTE's ZXCDN product has a reflective XSS vulnerability. The attacker could modify the parameters in the content clearing... |
| CVE-2022-22975 | MEDIUM | 6.6 | 0.9% | May 11, 2022 | An issue was discovered in the Pinniped Supervisor with either LADPIdentityProvider or ActiveDirectoryIdentityProvider r... |
| CVE-2022-22320 | MEDIUM | 4.8 | 0.4% | May 11, 2022 | IBM QRadar SIEM 7.3 and 7.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary Ja... |
| CVE-2022-29613 | MEDIUM | 4.3 | 0.7% | May 11, 2022 | Due to insufficient input validation, SAP Employee Self Service allows an authenticated attacker with user privileges to... |
| CVE-2022-29610 | MEDIUM | 5.4 | 0.4% | May 11, 2022 | SAP NetWeaver Application Server ABAP allows an authenticated attacker to upload malicious files and delete (theme) data... |
| CVE-2022-28774 | MEDIUM | 5.5 | 0.2% | May 11, 2022 | Under certain conditions, the SAP Host Agent logfile shows information which would otherwise be restricted. |
| CVE-2022-27656 | MEDIUM | 6.1 | 0.5% | May 11, 2022 | The Web administration UI of SAP Web Dispatcher and the Internet Communication Manager (ICM) does not sufficiently encod... |
| CVE-2022-1623 | MEDIUM | 5.5 | 1.2% | May 11, 2022 | LibTIFF master branch has an out-of-bounds read in LZWDecode in libtiff/tif_lzw.c:624, allowing attackers to cause a den... |
| CVE-2022-1622 | MEDIUM | 5.5 | 1.7% | May 11, 2022 | LibTIFF master branch has an out-of-bounds read in LZWDecode in libtiff/tif_lzw.c:619, allowing attackers to cause a den... |
| CVE-2022-1545 | MEDIUM | 4.3 | 0.7% | May 11, 2022 | It was possible to disclose details of confidential notes created via the API in Gitlab CE/EE affecting all versions fro... |
| CVE-2022-1460 | MEDIUM | 4.9 | 1.1% | May 11, 2022 | An issue has been discovered in GitLab affecting all versions starting from 9.2 before 14.8.6, all versions starting fro... |
| CVE-2022-1433 | MEDIUM | 6.1 | 0.8% | May 11, 2022 | An issue has been discovered in GitLab affecting all versions starting from 14.4 before 14.8.6, all versions starting fr... |
| CVE-2022-1428 | MEDIUM | 4.3 | 0.6% | May 11, 2022 | An issue has been discovered in GitLab affecting all versions before 14.8.6, all versions starting from 14.9 before 14.9... |
| CVE-2022-1406 | MEDIUM | 6.5 | 1.1% | May 11, 2022 | Improper input validation in GitLab CE/EE affecting all versions from 8.12 prior to 14.8.6, all versions from 14.9.0 pri... |
| CVE-2022-1352 | MEDIUM | 5.3 | 1.2% | May 11, 2022 | Due to an insecure direct object reference vulnerability in Gitlab EE/CE affecting all versions from 11.0 prior to 14.8.... |
| CVE-2022-1124 | MEDIUM | 4.3 | 0.7% | May 11, 2022 | An improper authorization issue has been discovered in GitLab CE/EE affecting all versions prior to 14.8.6, all versions... |
| CVE-2022-29978 | MEDIUM | 6.5 | 1.0% | May 11, 2022 | There is a floating point exception error in sixel_encoder_do_resize, encoder.c:633 in libsixel img2sixel 1.8.6. Remote ... |
| CVE-2022-29977 | MEDIUM | 6.5 | 1.0% | May 11, 2022 | There is an assertion failure error in stbi__jpeg_huff_decode, stb_image.h:1894 in libsixel img2sixel 1.8.6. Remote atta... |
| CVE-2022-29008 | MEDIUM | 6.5 | 1.2% | May 11, 2022 | An insecure direct object reference (IDOR) vulnerability in the viewid parameter of Bus Pass Management System v1.0 allo... |
| CVE-2022-28078 | MEDIUM | 6.1 | 1.1% | May 11, 2022 | Home Owners Collection Management v1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability in t... |
| CVE-2022-28077 | MEDIUM | 6.1 | 0.8% | May 11, 2022 | Home Owners Collection Management v1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability in t... |
| CVE-2022-29976 | MEDIUM | 5.4 | 0.4% | May 11, 2022 | An Authenticated Reflected Cross-site scripting at BCC Parameter was discovered in MDaemon before 22.0.0 . |
| CVE-2022-29975 | MEDIUM | 5.4 | 0.4% | May 11, 2022 | An Authenticated Reflected Cross-site scripting at CC Parameter was discovered in MDaemon before 22.0.0 . |
| CVE-2022-29728 | MEDIUM | 6.1 | 0.5% | May 11, 2022 | Survey Sparrow Enterprise Survey Software 2022 has a Reflected cross-site scripting (XSS) vulnerability in the test para... |
| CVE-2022-29727 | MEDIUM | 5.4 | 2.3% | May 11, 2022 | Survey Sparrow Enterprise Survey Software 2022 has a Stored cross-site scripting (XSS) vulnerability in the Signup param... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now