2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-22191 | MEDIUM | 6.5 | 0.4% | Apr 14, 2022 | A Denial of Service (DoS) vulnerability in the processing of a flood of specific ARP traffic in Juniper Networks Junos O... |
| CVE-2022-22186 | MEDIUM | 6.5 | 0.6% | Apr 14, 2022 | Due to an Improper Initialization vulnerability in Juniper Networks Junos OS on EX4650 devices, packets received on the ... |
| CVE-2022-22182 | MEDIUM | 6.1 | 0.7% | Apr 14, 2022 | A Cross-site Scripting (XSS) vulnerability in Juniper Networks Junos OS J-Web allows an attacker to construct a URL that... |
| CVE-2022-22181 | MEDIUM | 5.4 | 0.6% | Apr 14, 2022 | A reflected Cross-site Scripting (XSS) vulnerability in J-Web of Juniper Networks Junos OS allows a network-based authen... |
| CVE-2022-1257 | MEDIUM | 5.5 | 0.6% | Apr 14, 2022 | Insecure storage of sensitive information vulnerability in MA for Linux, macOS, and Windows prior to 5.7.6 allows a loca... |
| CVE-2022-1351 | MEDIUM | 5.4 | 0.8% | Apr 14, 2022 | Stored XSS in Tooltip in GitHub repository pimcore/pimcore prior to 10.4. |
| CVE-2022-0023 | MEDIUM | 5.9 | 0.7% | Apr 13, 2022 | An improper handling of exceptional conditions vulnerability exists in the DNS proxy feature of Palo Alto Networks PAN-O... |
| CVE-2022-27847 | MEDIUM | 4.3 | 0.4% | Apr 13, 2022 | Cross-Site Request Forgery (CSRF) vulnerability in Yooslider Yoo Slider <= 2.0.0 on WordPress allows attackers to import... |
| CVE-2022-27846 | MEDIUM | 4.3 | 0.4% | Apr 13, 2022 | Cross-Site Request Forgery (CSRF) vulnerability in Yooslider Yoo Slider <= 2.0.0 on WordPress allows attackers to create... |
| CVE-2022-27505 | MEDIUM | 6.1 | 0.5% | Apr 13, 2022 | Reflected cross site scripting (XSS) |
| CVE-2022-27503 | MEDIUM | 6.1 | 0.5% | Apr 13, 2022 | Cross-site Scripting (XSS) vulnerability in Citrix StoreFront affects version 1912 before CU5 and version 3.12 before CU... |
| CVE-2022-22961 | MEDIUM | 5.3 | 0.8% | Apr 13, 2022 | VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an information disclosure vulnerability du... |
| CVE-2022-22959 | MEDIUM | 4.3 | 0.5% | Apr 13, 2022 | VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a cross site request forgery vulnerability... |
| CVE-2022-1337 | MEDIUM | 6.5 | 0.9% | Apr 13, 2022 | The image proxy component in Mattermost version 6.4.1 and earlier allocates memory for multiple copies of a proxied imag... |
| CVE-2022-1333 | MEDIUM | 6.5 | 0.7% | Apr 13, 2022 | Mattermost Playbooks plugin v1.24.0 and earlier fails to properly check the limit on the number of webhooks, which allow... |
| CVE-2022-1332 | MEDIUM | 4.3 | 0.6% | Apr 13, 2022 | One of the API in Mattermost version 6.4.1 and earlier fails to properly protect the permissions, which allows the authe... |
| CVE-2022-1280 | MEDIUM | 6.3 | 0.3% | Apr 13, 2022 | A use-after-free vulnerability was found in drm_lease_held in drivers/gpu/drm/drm_lease.c in the Linux kernel due to a r... |
| CVE-2022-0221 | MEDIUM | 5.5 | 0.9% | Apr 13, 2022 | A CWE-611: Improper Restriction of XML External Entity Reference vulnerability exists that could result in information d... |
| CVE-2022-27256 | MEDIUM | 6.1 | 1.4% | Apr 13, 2022 | A PHP Local File inclusion vulnerability in the Redbasic theme for Hubzilla before version 7.2 allows remote attackers t... |
| CVE-2022-26643 | MEDIUM | 5.3 | 1.2% | Apr 13, 2022 | An issue in EasyIO CPT Graphics v0.8 allows attackers to discover valid users in the application. |
| CVE-2022-26144 | MEDIUM | 6.1 | 0.8% | Apr 13, 2022 | An XSS issue was discovered in MantisBT before 2.25.3. Improper escaping of a Plugin name allows execution of arbitrary ... |
| CVE-2022-24308 | MEDIUM | 5.5 | 0.2% | Apr 13, 2022 | Automox Agent prior to version 37 on Windows and Linux and Version 36 on OSX could allow for a non privileged user to ob... |
| CVE-2022-27475 | MEDIUM | 6.1 | 0.7% | Apr 13, 2022 | Cross site scripting (XSS) vulnerability in tramyardg hotel-mgmt-system, allows attackers to execute arbitrary code when... |
| CVE-2022-22279 | MEDIUM | 4.9 | 1.0% | Apr 13, 2022 | A post-authentication arbitrary file read vulnerability impacting end-of-life Secure Remote Access (SRA) products and ol... |
| CVE-2022-26589 | MEDIUM | 6.5 | 0.5% | Apr 13, 2022 | A Cross-Site Request Forgery (CSRF) in Pluck CMS v4.7.15 allows attackers to delete arbitrary pages. |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now