2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-20789 | MEDIUM | 6.5 | 1.3% | Apr 21, 2022 | A vulnerability in the software upgrade process of Cisco Unified Communications Manager (Unified CM) and Cisco Unified C... |
| CVE-2022-20788 | MEDIUM | 6.1 | 0.8% | Apr 21, 2022 | A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM), Cisco Unifie... |
| CVE-2022-20787 | MEDIUM | 6.8 | 0.4% | Apr 21, 2022 | A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) Software and ... |
| CVE-2022-20778 | MEDIUM | 6.1 | 0.8% | Apr 21, 2022 | A vulnerability in the authentication component of Cisco Webex Meetings could allow an unauthenticated, remote attacker ... |
| CVE-2022-24870 | MEDIUM | 5.4 | 0.9% | Apr 21, 2022 | Combodo iTop is a web based IT Service Management tool. In 3.0.0 beta releases prior to 3.0.0 beta3 a malicious script c... |
| CVE-2022-24869 | MEDIUM | 5.4 | 0.7% | Apr 21, 2022 | GLPI is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and... |
| CVE-2022-24868 | MEDIUM | 5.4 | 0.6% | Apr 21, 2022 | GLPI is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and... |
| CVE-2022-22436 | MEDIUM | 5.4 | 0.4% | Apr 21, 2022 | IBM Maximo Asset Management 7.6.1.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbi... |
| CVE-2022-22435 | MEDIUM | 5.4 | 0.4% | Apr 21, 2022 | IBM Maximo Asset Management 7.6.1.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbi... |
| CVE-2022-1022 | MEDIUM | 5.4 | 4.5% | Apr 21, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository chatwoot/chatwoot prior to 2.5.0. |
| CVE-2022-24272 | MEDIUM | 6.5 | 0.8% | Apr 21, 2022 | An authenticated user may trigger an invariant assertion during command dispatch due to incorrect validation on the $ext... |
| CVE-2022-1420 | MEDIUM | 5.5 | 1.4% | Apr 21, 2022 | Use of Out-of-range Pointer Offset in GitHub repository vim/vim prior to 8.2.4774. |
| CVE-2022-27237 | MEDIUM | 6.1 | 0.5% | Apr 21, 2022 | There is a cross-site scripting (XSS) vulnerability in an NI Web Server component installed with several NI products. De... |
| CVE-2022-29548 | MEDIUM | 6.1 | 40.5% | Apr 21, 2022 | A reflected XSS issue exists in the Management Console of several WSO2 products. This affects API Manager 2.2.0, 2.5.0, ... |
| CVE-2022-27926 | MEDIUM | 6.1 | 17.3% | Apr 21, 2022 | A reflected cross-site scripting (XSS) vulnerability in the /public/launchNewWindow.jsp component of Zimbra Collaboratio... |
| CVE-2022-29537 | MEDIUM | 5.5 | 0.6% | Apr 20, 2022 | gp_rtp_builder_do_hevc in ietf/rtp_pck_mpeg4.c in GPAC 2.0.0 has a heap-based buffer over-read, as demonstrated by MP4Bo... |
| CVE-2022-29533 | MEDIUM | 6.1 | 0.8% | Apr 20, 2022 | An issue was discovered in MISP before 2.4.158. There is XSS in app/Controller/OrganisationsController.php in a situatio... |
| CVE-2022-29532 | MEDIUM | 4.8 | 0.8% | Apr 20, 2022 | An issue was discovered in MISP before 2.4.158. There is XSS in the cerebrate view if one administrator puts a javascrip... |
| CVE-2022-29531 | MEDIUM | 5.4 | 0.8% | Apr 20, 2022 | An issue was discovered in MISP before 2.4.158. There is stored XSS in the event graph via a tag name. |
| CVE-2022-29530 | MEDIUM | 5.4 | 0.8% | Apr 20, 2022 | An issue was discovered in MISP before 2.4.158. There is stored XSS in the galaxy clusters. |
| CVE-2022-29529 | MEDIUM | 5.4 | 0.8% | Apr 20, 2022 | An issue was discovered in MISP before 2.4.158. There is stored XSS via the LinOTP login field. |
| CVE-2022-24865 | MEDIUM | 6.5 | 1.2% | Apr 20, 2022 | HumHub is an Open Source Enterprise Social Network. In affected versions users who are forced to change their password b... |
| CVE-2022-24871 | MEDIUM | 5.5 | 1.0% | Apr 20, 2022 | Shopware is an open commerce platform based on Symfony Framework and Vue. In affected versions an attacker can abuse the... |
| CVE-2022-24864 | MEDIUM | 5.4 | 0.6% | Apr 20, 2022 | Origin Protocol is a blockchain based project. The Origin Protocol project website allows for malicious users to inject ... |
| CVE-2022-24799 | MEDIUM | 6.1 | 0.9% | Apr 20, 2022 | wire-webapp is the web application interface for the wire messaging service. Insufficient escaping in markdown “code hig... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now