2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-27135 | MEDIUM | 5.5 | 1.0% | Apr 25, 2022 | xpdf 4.03 has heap buffer overflow in the function readXRefTable located in XRef.cc. An attacker can exploit this bug to... |
| CVE-2022-27103 | MEDIUM | 6.1 | 0.9% | Apr 25, 2022 | element-plus 2.0.5 is vulnerable to Cross Site Scripting (XSS) via el-table-column. |
| CVE-2022-1461 | MEDIUM | 6.5 | 0.9% | Apr 25, 2022 | Non Privilege User can Enable or Disable Registered in GitHub repository openemr/openemr prior to 6.1.0.1. |
| CVE-2022-1458 | MEDIUM | 5.4 | 0.7% | Apr 25, 2022 | Stored XSS Leads To Session Hijacking in GitHub repository openemr/openemr prior to 6.1.0.1. |
| CVE-2022-1457 | MEDIUM | 5.4 | 0.7% | Apr 25, 2022 | Store XSS in title parameter executing at EditUser Page & EditProducto page in GitHub repository neorazorx/facturascript... |
| CVE-2022-1445 | MEDIUM | 5.4 | 0.7% | Apr 24, 2022 | Stored Cross Site Scripting vulnerability in the checked_out_to parameter in GitHub repository snipe/snipe-it prior to 5... |
| CVE-2022-1444 | MEDIUM | 5.5 | 0.8% | Apr 23, 2022 | heap-use-after-free in GitHub repository radareorg/radare2 prior to 5.7.0. This vulnerability is capable of inducing den... |
| CVE-2022-1108 | MEDIUM | 6.7 | 0.2% | Apr 22, 2022 | A potential vulnerability due to improper buffer validation in the SMI handler LenovoFlashDeviceInterface in Thinkpad X1... |
| CVE-2022-1107 | MEDIUM | 6.7 | 0.3% | Apr 22, 2022 | During an internal product security audit a potential vulnerability due to use of Boot Services in the SmmOEMInt15 SMI h... |
| CVE-2022-0636 | MEDIUM | 5.5 | 0.2% | Apr 22, 2022 | A denial of service vulnerability was reported in Lenovo Thin Installer prior to version 1.3.0039 that could trigger a s... |
| CVE-2022-29589 | MEDIUM | 6.1 | 0.6% | Apr 22, 2022 | Crypt Server before 3.3.0 allows XSS in the index view. This is related to serial, computername, and username. |
| CVE-2022-1439 | MEDIUM | 6.1 | 3.2% | Apr 22, 2022 | Reflected XSS on demo.microweber.org/demo/module/ in GitHub repository microweber/microweber prior to 1.2.15. Execute Ar... |
| CVE-2022-28074 | MEDIUM | 4.8 | 0.4% | Apr 22, 2022 | Halo-1.5.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via \admin\index.html#/system/too... |
| CVE-2022-26673 | MEDIUM | 5.4 | 0.6% | Apr 22, 2022 | ASUS RT-AX88U has insufficient filtering for special characters in the HTTP header parameter. A remote attacker with gen... |
| CVE-2022-29577 | MEDIUM | 6.1 | 1.2% | Apr 21, 2022 | OWASP AntiSamy before 1.6.7 allows XSS via HTML tag smuggling on STYLE content with crafted input. The output serializer... |
| CVE-2022-28367 | MEDIUM | 6.1 | 1.0% | Apr 21, 2022 | OWASP AntiSamy before 1.6.6 allows XSS via HTML tag smuggling on STYLE content with crafted input. The output serializer... |
| CVE-2022-22558 | MEDIUM | 6 | 0.2% | Apr 21, 2022 | Dell PowerEdge Server BIOS and Dell Precision Workstation 7910 and 7920 Rack BIOS contain an Improper SMM communication ... |
| CVE-2022-28445 | MEDIUM | 6.5 | 1.0% | Apr 21, 2022 | KiteCMS v1.1.1 was discovered to contain an arbitrary file read vulnerability via the background management module. |
| CVE-2022-28820 | MEDIUM | 6.1 | 1.0% | Apr 21, 2022 | ACS Commons version 5.1.x (and earlier) suffers from a Reflected Cross-site Scripting (XSS) vulnerability in /apps/acs-c... |
| CVE-2022-28743 | MEDIUM | 6.6 | 1.1% | Apr 21, 2022 | Time-of-check Time-of-use (TOCTOU) Race Condition vulerability in Foscam R2C IP camera running System FW <= 1.13.1.6, an... |
| CVE-2022-23711 | MEDIUM | 5.3 | 0.9% | Apr 21, 2022 | A vulnerability in Kibana could expose sensitive information related to Elastic Stack monitoring in the Kibana page sour... |
| CVE-2022-22969 | MEDIUM | 6.5 | 1.2% | Apr 21, 2022 | <Issue Description> Spring Security OAuth versions 2.5.x prior to 2.5.2 and older unsupported versions are susceptible t... |
| CVE-2022-20805 | MEDIUM | 4.1 | 0.2% | Apr 21, 2022 | A vulnerability in the automatic decryption process in Cisco Umbrella Secure Web Gateway (SWG) could allow an authentica... |
| CVE-2022-20804 | MEDIUM | 6.5 | 0.3% | Apr 21, 2022 | A vulnerability in the Cisco Discovery Protocol of Cisco Unified Communications Manager (Unified CM) and Cisco Unified C... |
| CVE-2022-20790 | MEDIUM | 6.5 | 2.0% | Apr 21, 2022 | A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) and Cisco Uni... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now