2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-1389 | MEDIUM | 4.3 | 0.3% | May 5, 2022 | On all versions of 16.1.x, 15.1.x, 14.1.x, 13.1.x, 12.1.x, and 11.6.x of F5 BIG-IP (fixed in 17.0.0), a cross-site reque... |
| CVE-2022-22434 | MEDIUM | 4.6 | 0.2% | May 5, 2022 | IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 could allow a user with physical access to create an API reque... |
| CVE-2022-22415 | MEDIUM | 6.5 | 0.7% | May 5, 2022 | A vulnerability exists where an IBM Robotic Process Automation 21.0.1 regular user is able to obtain view-only access to... |
| CVE-2022-1516 | MEDIUM | 5.5 | 0.3% | May 5, 2022 | A NULL pointer dereference flaw was found in the Linux kernel’s X.25 set of standardized network protocols functionality... |
| CVE-2022-1464 | MEDIUM | 5.4 | 0.7% | May 5, 2022 | Stored xss bug in GitHub repository gogs/gogs prior to 0.12.7. As the repo is public , any user can view the report and ... |
| CVE-2022-28471 | MEDIUM | 6.5 | 0.9% | May 5, 2022 | In ffjpeg (commit hash: caade60), the function bmp_load() in bmp.c contains an integer overflow vulnerability, which eve... |
| CVE-2022-29940 | MEDIUM | 5.4 | 0.8% | May 5, 2022 | In LibreHealth EHR 2.0.0, lack of sanitization of the GET parameters formseq and formid in interface\orders\find_order_p... |
| CVE-2022-29939 | MEDIUM | 5.4 | 0.8% | May 5, 2022 | In LibreHealth EHR 2.0.0, lack of sanitization of the GET parameters debug and InsId in interface\billing\sl_eob_process... |
| CVE-2022-1411 | MEDIUM | 6.1 | 0.7% | May 5, 2022 | Unrestructed file upload in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0. Attacker can send malicious ... |
| CVE-2022-1590 | MEDIUM | 5.4 | 0.6% | May 5, 2022 | A vulnerability was found in Bludit 3.13.1. It has been declared as problematic. This vulnerability affects the endpoint... |
| CVE-2022-30241 | MEDIUM | 6.1 | 0.7% | May 4, 2022 | The jquery.json-viewer library through 1.4.0 for Node.js does not properly escape characters such as < in a JSON object,... |
| CVE-2022-29943 | MEDIUM | 6.5 | 0.8% | May 4, 2022 | Talend Administration Center has a vulnerability that allows an authenticated user to use XML External Entity (XXE) proc... |
| CVE-2022-29942 | MEDIUM | 6.5 | 0.6% | May 4, 2022 | Talend Administration Center has a vulnerability that allows an authenticated user to use the Service Registry 'Add' fun... |
| CVE-2022-25786 | MEDIUM | 4.9 | 0.7% | May 4, 2022 | Unprotected Alternate Channel vulnerability in debug console of GateManager allows system administrator to obtain sensit... |
| CVE-2022-1584 | MEDIUM | 6.1 | 0.8% | May 4, 2022 | Reflected XSS in GitHub repository microweber/microweber prior to 1.2.16. Executing JavaScript as the victim |
| CVE-2022-20796 | MEDIUM | 5.5 | 0.4% | May 4, 2022 | On May 4, 2022, the following vulnerability in the ClamAV scanning library versions 0.103.5 and earlier and 0.104.2 and ... |
| CVE-2022-20794 | MEDIUM | 4.7 | 0.7% | May 4, 2022 | Multiple vulnerabilities in the web engine of Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS S... |
| CVE-2022-20734 | MEDIUM | 4.4 | 0.2% | May 4, 2022 | A vulnerability in Cisco SD-WAN vManage Software could allow an authenticated, local attacker to view sensitive informat... |
| CVE-2022-29950 | MEDIUM | 4.3 | 0.9% | May 4, 2022 | Experian Hunter 1.16 allows remote authenticated users to modify assumed-immutable elements via the (1) rule name parame... |
| CVE-2022-27461 | MEDIUM | 6.1 | 0.7% | May 4, 2022 | In nopCommerce 4.50.1, an open redirect vulnerability can be triggered by luring a user to authenticate to a nopCommerce... |
| CVE-2022-28508 | MEDIUM | 6.1 | 4.9% | May 4, 2022 | An XSS issue was discovered in browser_search_plugin.php in MantisBT before 2.25.2. Unescaped output of the return param... |
| CVE-2022-28090 | MEDIUM | 6.5 | 1.0% | May 4, 2022 | Jspxcms v10.2.0 allows attackers to execute a Server-Side Request Forgery (SSRF) via /cmscp/ext/collect/fetch_url.do?url... |
| CVE-2022-28081 | MEDIUM | 6.1 | 0.5% | May 4, 2022 | A reflected cross-site scripting (XSS) vulnerability in the component Query.php of arPHP v3.6.0 allows attackers to exec... |
| CVE-2022-25787 | MEDIUM | 6.7 | 0.2% | May 4, 2022 | Information Exposure Through Query Strings in GET Request vulnerability in LMM API of Secomea GateManager allows system ... |
| CVE-2022-25784 | MEDIUM | 4.8 | 0.6% | May 4, 2022 | Cross-site Scripting (XSS) vulnerability in Web GUI of SiteManager allows logged-in user to inject scripting. This issue... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now