2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-20692 | MEDIUM | 6.5 | 1.1% | Apr 15, 2022 | A vulnerability in the NETCONF over SSH feature of Cisco IOS XE Software could allow a low-privileged, authenticated, re... |
| CVE-2022-20684 | MEDIUM | 6.5 | 0.5% | Apr 15, 2022 | A vulnerability in Simple Network Management Protocol (SNMP) trap generation for wireless clients of Cisco IOS XE Wirele... |
| CVE-2022-20677 | MEDIUM | 6.7 | 0.6% | Apr 15, 2022 | Multiple vulnerabilities in the Cisco IOx application hosting environment on multiple Cisco platforms could allow an att... |
| CVE-2022-20676 | MEDIUM | 6.7 | 0.3% | Apr 15, 2022 | A vulnerability in the Tool Command Language (Tcl) interpreter of Cisco IOS XE Software could allow an authenticated, lo... |
| CVE-2022-20661 | MEDIUM | 4.6 | 0.2% | Apr 15, 2022 | Multiple vulnerabilities that affect Cisco Catalyst Digital Building Series Switches and Cisco Catalyst Micro Switches c... |
| CVE-2022-1231 | MEDIUM | 6.1 | 1.8% | Apr 15, 2022 | XSS via Embedded SVG in SVG Diagram Format in GitHub repository plantuml/plantuml prior to 1.2022.4. Stored XSS in the c... |
| CVE-2022-28049 | MEDIUM | 5.5 | 0.8% | Apr 15, 2022 | NGINX NJS 0.7.2 was discovered to contain a NULL pointer dereference via the component njs_vmcode_array at /src/njs_vmco... |
| CVE-2022-28041 | MEDIUM | 6.5 | 2.0% | Apr 15, 2022 | stb_image.h v2.27 was discovered to contain an integer overflow via the function stbi__jpeg_decode_block_prog_dc. This v... |
| CVE-2022-28870 | MEDIUM | 4.3 | 0.4% | Apr 15, 2022 | A vulnerability affecting F-Secure SAFE browser was discovered. A maliciously crafted website could make a phishing atta... |
| CVE-2022-28869 | MEDIUM | 4.3 | 0.4% | Apr 15, 2022 | A vulnerability affecting F-Secure SAFE browser was discovered. A maliciously crafted website could make a phishing atta... |
| CVE-2022-28868 | MEDIUM | 4.3 | 0.5% | Apr 15, 2022 | An Address bar spoofing vulnerability was discovered in Safe Browser for Android. When user clicks on a specially crafte... |
| CVE-2022-24855 | MEDIUM | 5.4 | 0.7% | Apr 14, 2022 | Metabase is an open source business intelligence and analytics application. In affected versions Metabase ships with an ... |
| CVE-2022-24853 | MEDIUM | 5.3 | 2.4% | Apr 14, 2022 | Metabase is an open source business intelligence and analytics application. Metabase has a proxy to load arbitrary URLs ... |
| CVE-2022-24850 | MEDIUM | 4.3 | 0.6% | Apr 14, 2022 | Discourse is an open source platform for community discussion. A category's group permissions settings can be viewed by ... |
| CVE-2022-24849 | MEDIUM | 6.5 | 0.8% | Apr 14, 2022 | DisCatSharp is a Discord API wrapper for .NET. Users of versions 9.8.5, 9.8.6, 9.9.0 and previously published prerelease... |
| CVE-2022-24824 | MEDIUM | 5.3 | 0.9% | Apr 14, 2022 | Discourse is an open source platform for community discussion. In affected versions an attacker can poison the cache for... |
| CVE-2022-27848 | MEDIUM | 4.8 | 0.5% | Apr 14, 2022 | Authenticated (admin+ user) Stored Cross-Site Scripting (XSS) in Modern Events Calendar Lite (WordPress plugin) <= 6.5.1 |
| CVE-2022-22968 | MEDIUM | 5.3 | 5.4% | Apr 14, 2022 | In Spring Framework versions 5.3.0 - 5.3.18, 5.2.0 - 5.2.20, and older unsupported versions, the patterns for disallowed... |
| CVE-2022-1328 | MEDIUM | 5.3 | 1.6% | Apr 14, 2022 | Buffer Overflow in uudecoder in Mutt affecting all versions starting from 0.94.13 before 2.2.3 allows read past end of i... |
| CVE-2022-21145 | MEDIUM | 4.8 | 77.2% | Apr 14, 2022 | A stored cross-site scripting vulnerability exists in the WebUserActions.aspx functionality of Lansweeper lansweeper 9.1... |
| CVE-2022-22391 | MEDIUM | 4.3 | 0.7% | Apr 14, 2022 | IBM Aspera High-Speed Transfer 4.3.1 and earlier could allow an authenticated user to obtain information from non sensit... |
| CVE-2022-27817 | MEDIUM | 4.4 | 0.4% | Apr 14, 2022 | SWHKD 1.1.5 consumes the keyboard events of unintended users. This could potentially cause an information leak, but is u... |
| CVE-2022-25166 | MEDIUM | 5 | 1.4% | Apr 14, 2022 | An issue was discovered in Amazon AWS VPN Client 2.0.0. It is possible to include a UNC path in the OpenVPN configuratio... |
| CVE-2022-22196 | MEDIUM | 6.5 | 0.4% | Apr 14, 2022 | An Improper Check for Unusual or Exceptional Conditions vulnerability in the Routing Protocol Daemon (rpd) of Juniper Ne... |
| CVE-2022-22193 | MEDIUM | 5.5 | 0.2% | Apr 14, 2022 | An Improper Handling of Unexpected Data Type vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Juno... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now