2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-22276 | MEDIUM | 5.3 | 0.7% | Apr 27, 2022 | A vulnerability in SonicOS SNMP service resulting exposure of sensitive information to an unauthorized user. |
| CVE-2022-1507 | MEDIUM | 5.5 | 0.9% | Apr 27, 2022 | chafa: NULL Pointer Dereference in function gif_internal_decode_frame at libnsgif.c:599 allows attackers to cause a deni... |
| CVE-2022-22345 | MEDIUM | 4.8 | 1.8% | Apr 27, 2022 | IBM QRadar 7.3, 7.4, and 7.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary J... |
| CVE-2022-22323 | MEDIUM | 6.5 | 1.0% | Apr 27, 2022 | IBM Security Identity Manager (IBM Security Verify Password Synchronization Plug-in for Windows AD 10.x) is vulnerable t... |
| CVE-2022-22312 | MEDIUM | 6.5 | 1.0% | Apr 27, 2022 | IBM Security Identity Manager (IBM Security Verify Password Synchronization Plug-in for Windows AD 10.x) is vulnerable t... |
| CVE-2022-24889 | MEDIUM | 4.3 | 0.6% | Apr 27, 2022 | Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform. Prior to versions 21.0.... |
| CVE-2022-24888 | MEDIUM | 4.3 | 1.2% | Apr 27, 2022 | Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform. Prior to versions 20.0.... |
| CVE-2022-24887 | MEDIUM | 6.1 | 0.9% | Apr 27, 2022 | Nextcloud Talk is a video and audio conferencing app for Nextcloud, a self-hosted productivity platform. Prior to versio... |
| CVE-2022-1504 | MEDIUM | 6.1 | 1.0% | Apr 27, 2022 | XSS in /demo/module/?module=HERE in GitHub repository microweber/microweber prior to 1.2.15. Typical impact of XSS attac... |
| CVE-2022-1503 | MEDIUM | 5.4 | 0.6% | Apr 27, 2022 | A vulnerability, which was classified as problematic, has been found in GetSimple CMS. Affected by this issue is the fil... |
| CVE-2022-29810 | MEDIUM | 5.5 | 0.4% | Apr 27, 2022 | The Hashicorp go-getter library before 1.5.11 does not redact an SSH key from a URL query parameter. |
| CVE-2022-27331 | MEDIUM | 4.3 | 0.7% | Apr 27, 2022 | An access control issue in Zammad v5.0.3 broadcasts administrative configuration changes to all users who have an active... |
| CVE-2022-27888 | MEDIUM | 5.5 | 0.2% | Apr 26, 2022 | Foundry Issues service versions 2.244.0 to 2.249.0 was found to be logging in a manner that captured sensitive informati... |
| CVE-2022-26564 | MEDIUM | 6.1 | 2.7% | Apr 26, 2022 | HotelDruid Hotel Management Software v3.0.3 contains a cross-site scripting (XSS) vulnerability via the prezzoperiodo4 p... |
| CVE-2022-28522 | MEDIUM | 5.4 | 0.6% | Apr 26, 2022 | ZCMS v20170206 was discovered to contain a stored cross-site scripting (XSS) vulnerability via index.php?m=home&c=messag... |
| CVE-2022-28450 | MEDIUM | 5.4 | 0.7% | Apr 26, 2022 | nopCommerce 4.50.1 is vulnerable to Cross Site Scripting (XSS) via the "Text" parameter (forums) when creating a new pos... |
| CVE-2022-28449 | MEDIUM | 6.1 | 0.7% | Apr 26, 2022 | nopCommerce 4.50.1 is vulnerable to Cross Site Scripting (XSS). At Apply for vendor account feature, an attacker can upl... |
| CVE-2022-28448 | MEDIUM | 5.4 | 0.5% | Apr 26, 2022 | nopCommerce 4.50.1 is vulnerable to Cross Site Scripting (XSS). An attacker (role customer) can inject javascript code t... |
| CVE-2022-27854 | MEDIUM | 5.4 | 0.5% | Apr 26, 2022 | Stored Cross-Site Scripting (XSS) vulnerability in Alexander Ustimenko's Psychological tests & quizzes plugin <= 0.21.19... |
| CVE-2022-24866 | MEDIUM | 4.3 | 0.6% | Apr 26, 2022 | Discourse Assign is a plugin for assigning users to a topic in Discourse, an open-source messaging platform. Prior to ve... |
| CVE-2022-1466 | MEDIUM | 6.5 | 1.0% | Apr 26, 2022 | Due to improper authorization, Red Hat Single Sign-On is vulnerable to users performing actions that they should not be ... |
| CVE-2022-28218 | MEDIUM | 5.5 | 0.2% | Apr 26, 2022 | An issue was discovered in CipherMail Webmail Messenger 1.1.1 through 4.1.4. A local attacker could access secret keys (... |
| CVE-2022-1173 | MEDIUM | 5.4 | 1.5% | Apr 26, 2022 | stored xss in GitHub repository getgrav/grav prior to 1.7.33. |
| CVE-2022-24880 | MEDIUM | 5.3 | 1.1% | Apr 25, 2022 | flask-session-captcha is a package which allows users to extend Flask by adding an image based captcha stored in a serve... |
| CVE-2022-29418 | MEDIUM | 4.8 | 0.5% | Apr 25, 2022 | Authenticated (admin user role) Persistent Cross-Site Scripting (XSS) in Mark Daniels Night Mode plugin <= 1.0.0 on Word... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now