2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-24837 | MEDIUM | 5.3 | 1.1% | Apr 11, 2022 | HedgeDoc is an open-source, web-based, self-hosted, collaborative markdown editor. Images uploaded with HedgeDoc version... |
| CVE-2022-24833 | MEDIUM | 6.1 | 1.2% | Apr 11, 2022 | PrivateBin is minimalist, open source online pastebin clone where the server has zero knowledge of pasted data. In Priva... |
| CVE-2022-24832 | MEDIUM | 6.8 | 1.6% | Apr 11, 2022 | GoCD is an open source a continuous delivery server. The bundled gocd-ldap-authentication-plugin included with the GoCD ... |
| CVE-2022-28544 | MEDIUM | 5.5 | 0.9% | Apr 11, 2022 | Path traversal vulnerability in unzip method of InstallAgentCommonHelper in Galaxy store prior to version 4.5.40.5 allow... |
| CVE-2022-28543 | MEDIUM | 5.5 | 0.3% | Apr 11, 2022 | Path traversal vulnerability in Samsung Flow prior to version 4.8.07.4 allows local attackers to read arbitrary files as... |
| CVE-2022-28542 | MEDIUM | 5.5 | 0.3% | Apr 11, 2022 | Improper sanitization of incoming intent in Galaxy Store prior to version 4.5.40.5 allows local attackers to access priv... |
| CVE-2022-27845 | MEDIUM | 4.8 | 0.8% | Apr 11, 2022 | Authenticated (admin or higher user role) Stored Cross-Site Scripting (XSS) in PlausibleHQ Plausible Analytics (WordPres... |
| CVE-2022-27841 | MEDIUM | 4.3 | 0.3% | Apr 11, 2022 | Improper exception handling in Samsung Pass prior to version 3.7.07.5 allows physical attacker to view the screen that i... |
| CVE-2022-27840 | MEDIUM | 4.4 | 0.2% | Apr 11, 2022 | Improper access control vulnerability in SamsungRecovery prior to version 8.1.43.0 allows local attckers to delete arbit... |
| CVE-2022-27839 | MEDIUM | 4 | 0.5% | Apr 11, 2022 | Improper authentication vulnerability in SecretMode in Samsung Internet prior to version 16.2.1 allows attackers to acce... |
| CVE-2022-27831 | MEDIUM | 4.4 | 0.1% | Apr 11, 2022 | Improper boundary check in sflvd_rdbuf_bits of libsflvextractor prior to SMR Apr-2022 Release 1 allows attackers to read... |
| CVE-2022-27822 | MEDIUM | 5.5 | 0.1% | Apr 11, 2022 | Information exposure vulnerability in ril property setting prior to SMR April-2022 Release 1 allows access to EF_RUIMID ... |
| CVE-2022-27821 | MEDIUM | 5.5 | 0.3% | Apr 11, 2022 | Improper boundary check in Quram Agif library prior to SMR Apr-2022 Release 1 allows attackers to cause denial of servic... |
| CVE-2022-26091 | MEDIUM | 6.8 | 0.1% | Apr 11, 2022 | Improper access control vulnerability in Knox Manage prior to SMR Apr-2022 Release 1 allows that physical attackers can ... |
| CVE-2022-25832 | MEDIUM | 6.8 | 0.1% | Apr 11, 2022 | Improper authentication vulnerability in S Secure prior to SMR Apr-2022 Release 1 allows physical attackers to use locke... |
| CVE-2022-25831 | MEDIUM | 4.6 | 0.1% | Apr 11, 2022 | Improper access control vulnerability in S Secure prior to SMR Apr-2022 Release 1 allows physical attackers to access se... |
| CVE-2022-25615 | MEDIUM | 4.3 | 0.4% | Apr 11, 2022 | Cross-Site Request Forgery (CSRF) in StylemixThemes eRoom – Zoom Meetings & Webinar (WordPress plugin) <= 1.3.8 allows c... |
| CVE-2022-25614 | MEDIUM | 4.3 | 0.4% | Apr 11, 2022 | Cross-Site Request Forgery (CSRF) in StylemixThemes eRoom – Zoom Meetings & Webinar (WordPress plugin) <= 1.3.7 allows a... |
| CVE-2022-24804 | MEDIUM | 5.3 | 0.8% | Apr 11, 2022 | Discourse is an open source platform for community discussion. In stable versions prior to 2.8.3 and beta versions prior... |
| CVE-2022-22571 | MEDIUM | 4.8 | 1.1% | Apr 11, 2022 | An authenticated high privileged user can perform a stored XSS attack due to incorrect output encoding in Incapptic conn... |
| CVE-2022-20081 | MEDIUM | 5.9 | 0.5% | Apr 11, 2022 | In A-GPS, there is a possible man in the middle attack due to improper certificate validation. This could lead to remote... |
| CVE-2022-20080 | MEDIUM | 6.4 | 0.1% | Apr 11, 2022 | In SUB2AF, there is a possible memory corruption due to a race condition. This could lead to local escalation of privile... |
| CVE-2022-20079 | MEDIUM | 4.4 | 0.1% | Apr 11, 2022 | In vow, there is a possible read of uninitialized data due to a improper input validation. This could lead to local info... |
| CVE-2022-20078 | MEDIUM | 6.4 | 0.1% | Apr 11, 2022 | In vow, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege ... |
| CVE-2022-20077 | MEDIUM | 6.4 | 0.1% | Apr 11, 2022 | In vow, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege ... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now