2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-22443 | MEDIUM | 5.4 | 0.4% | Apr 28, 2022 | IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed a... |
| CVE-2022-22441 | MEDIUM | 6.5 | 0.8% | Apr 28, 2022 | IBM InfoSphere Information Server 11.7 could allow an authenticated user to view information of higher privileged users ... |
| CVE-2022-22427 | MEDIUM | 6.1 | 0.6% | Apr 28, 2022 | IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed a... |
| CVE-2022-22322 | MEDIUM | 5.4 | 0.4% | Apr 28, 2022 | IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed a... |
| CVE-2022-1514 | MEDIUM | 5.4 | 0.7% | Apr 28, 2022 | Stored XSS via upload plugin functionality in zip format in GitHub repository neorazorx/facturascripts prior to 2022.06.... |
| CVE-2022-28117 | MEDIUM | 4.9 | 21.9% | Apr 28, 2022 | A Server-Side Request Forgery (SSRF) in feed_parser class of Navigate CMS v2.9.4 allows remote attackers to force the ap... |
| CVE-2022-1511 | MEDIUM | 6.5 | 1.0% | Apr 28, 2022 | Missing Authorization in GitHub repository snipe/snipe-it prior to 5.4.4. |
| CVE-2022-28102 | MEDIUM | 5.4 | 0.5% | Apr 28, 2022 | A cross-site scripting (XSS) vulnerability in PHP MySQL Admin Panel Generator v1 allows attackers to execute arbitrary w... |
| CVE-2022-24873 | MEDIUM | 6.1 | 0.7% | Apr 28, 2022 | Shopware is an open source e-commerce software platform. Prior to version 5.7.9, Shopware is vulnerable to non-stored cr... |
| CVE-2022-29152 | MEDIUM | 6.1 | 0.5% | Apr 28, 2022 | The Ericom PowerTerm WebConnect 6.0 login portal can unsafely write an XSS payload from the AppPortal cookie into the pa... |
| CVE-2022-29817 | MEDIUM | 6.1 | 0.4% | Apr 28, 2022 | In JetBrains IntelliJ IDEA before 2022.1 reflected XSS via error messages in internal web server was possible |
| CVE-2022-29815 | MEDIUM | 6.7 | 0.2% | Apr 28, 2022 | In JetBrains IntelliJ IDEA before 2022.1 local code execution via workspace settings was possible |
| CVE-2022-29813 | MEDIUM | 6.7 | 0.2% | Apr 28, 2022 | In JetBrains IntelliJ IDEA before 2022.1 local code execution via custom Pandoc path was possible |
| CVE-2022-29811 | MEDIUM | 4.8 | 0.5% | Apr 28, 2022 | In JetBrains Hub before 2022.1.14638 stored XSS via project icon was possible. |
| CVE-2022-29869 | MEDIUM | 5.3 | 1.8% | Apr 28, 2022 | cifs-utils through 6.14, with verbose logging, can cause an information leak when a file contains = (equal sign) charact... |
| CVE-2022-24891 | MEDIUM | 6.1 | 1.6% | Apr 27, 2022 | ESAPI (The OWASP Enterprise Security API) is a free, open source, web application security control library. Prior to ver... |
| CVE-2022-24736 | MEDIUM | 5.5 | 1.5% | Apr 27, 2022 | Redis is an in-memory database that persists on disk. Prior to versions 6.2.7 and 7.0.0, an attacker attempting to load ... |
| CVE-2022-28197 | MEDIUM | 5 | 0.2% | Apr 27, 2022 | NVIDIA Jetson Linux Driver Package contains a vulnerability in the Cboot ext4_mount function, where Insufficient validat... |
| CVE-2022-28196 | MEDIUM | 4.6 | 0.2% | Apr 27, 2022 | NVIDIA Jetson Linux Driver Package contains a vulnerability in the Cboot blob_decompress function, where insufficient va... |
| CVE-2022-28195 | MEDIUM | 5.7 | 0.2% | Apr 27, 2022 | NVIDIA Jetson Linux Driver Package contains a vulnerability in the Cboot ext4_read_file function, where insufficient val... |
| CVE-2022-28194 | MEDIUM | 5.6 | 0.3% | Apr 27, 2022 | NVIDIA Jetson Linux Driver Package contains a vulnerability in the Cboot module tegrabl_cbo.c, where, if TFTP is enabled... |
| CVE-2022-28193 | MEDIUM | 5.6 | 0.3% | Apr 27, 2022 | NVIDIA Jetson Linux Driver Package contains a vulnerability in the Cboot module tegrabl_cbo.c, where insufficient valida... |
| CVE-2022-24372 | MEDIUM | 4.6 | 0.5% | Apr 27, 2022 | Linksys MR9600 devices before 2.0.5 allow attackers to read arbitrary files via a symbolic link to the root directory of... |
| CVE-2022-23822 | MEDIUM | 6.8 | 0.3% | Apr 27, 2022 | In this physical attack, an attacker may potentially exploit the Zynq-7000 SoC First Stage Boot Loader (FSBL) by bypassi... |
| CVE-2022-22277 | MEDIUM | 5.3 | 0.7% | Apr 27, 2022 | A vulnerability in SonicOS SNMP service resulting exposure of Wireless Access Point sensitive information in cleartext. |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now