2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-28364 | MEDIUM | 5.4 | 0.9% | Apr 9, 2022 | Reprise License Manager 14.2 is affected by a reflected cross-site scripting vulnerability (XSS) in the /goform/rlmswitc... |
| CVE-2022-28363 | MEDIUM | 6.1 | 4.2% | Apr 9, 2022 | Reprise License Manager 14.2 is affected by a reflected cross-site scripting vulnerability (XSS) in the /goform/login_pr... |
| CVE-2022-26877 | MEDIUM | 6.5 | 1.1% | Apr 9, 2022 | Asana Desktop before 1.6.0 allows remote attackers to exfiltrate local files if they can trick the Asana desktop app int... |
| CVE-2022-26588 | MEDIUM | 6.5 | 0.6% | Apr 8, 2022 | A Cross-Site Request Forgery (CSRF) in IceHrm 31.0.0.OS allows attackers to delete arbitrary users or achieve account ta... |
| CVE-2022-26855 | MEDIUM | 5.5 | 0.2% | Apr 8, 2022 | Dell PowerScale OneFS, versions 8.2.x-9.3.0.x, contains an incorrect default permissions vulnerability. A local maliciou... |
| CVE-2022-24820 | MEDIUM | 5.3 | 1.0% | Apr 8, 2022 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. A guest user wi... |
| CVE-2022-24819 | MEDIUM | 5.3 | 3.3% | Apr 8, 2022 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. A guest user wi... |
| CVE-2022-22563 | MEDIUM | 4.4 | 0.2% | Apr 8, 2022 | Dell EMC Powerscale OneFS 8.2.x - 9.2.x omit security-relevant information in /etc/master.passwd. A high-privileged user... |
| CVE-2022-1284 | MEDIUM | 5.5 | 0.8% | Apr 8, 2022 | heap-use-after-free in GitHub repository radareorg/radare2 prior to 5.6.8. This vulnerability is capable of inducing den... |
| CVE-2022-27152 | MEDIUM | 5.7 | 0.3% | Apr 8, 2022 | Roku devices running RokuOS v9.4.0 build 4200 or earlier that uses a Realtek WiFi chip is vulnerable to Arbitrary file m... |
| CVE-2022-1283 | MEDIUM | 5.5 | 0.7% | Apr 8, 2022 | NULL Pointer Dereference in r_bin_ne_get_entrypoints function in GitHub repository radareorg/radare2 prior to 5.6.8. Thi... |
| CVE-2022-27148 | MEDIUM | 5.5 | 0.8% | Apr 8, 2022 | GPAC mp4box 1.1.0-DEV-rev1663-g881c6a94a-master is vulnerable to Integer Overflow. |
| CVE-2022-27147 | MEDIUM | 5.5 | 0.7% | Apr 8, 2022 | GPAC mp4box 1.1.0-DEV-rev1727-g8be34973d-master has a use-after-free vulnerability in function gf_node_get_attribute_by_... |
| CVE-2022-27146 | MEDIUM | 5.5 | 0.8% | Apr 8, 2022 | GPAC mp4box 1.1.0-DEV-rev1759-geb2d1e6dd-has a heap-buffer-overflow vulnerability in function gf_isom_apple_enum_tag. |
| CVE-2022-27145 | MEDIUM | 5.5 | 0.8% | Apr 8, 2022 | GPAC mp4box 1.1.0-DEV-rev1727-g8be34973d-master has a stack-overflow vulnerability in function gf_isom_get_sample_for_mo... |
| CVE-2022-24229 | MEDIUM | 6.1 | 1.8% | Apr 8, 2022 | A cross-site scripting (XSS) vulnerability in ONLYOFFICE Document Server Example before v7.0.0 allows remote attackers i... |
| CVE-2022-27991 | MEDIUM | 6.5 | 1.0% | Apr 8, 2022 | Online Banking System in PHP v1 was discovered to contain multiple SQL injection vulnerabilities at /staff_login.php via... |
| CVE-2022-27348 | MEDIUM | 4.8 | 1.1% | Apr 8, 2022 | Social Codia SMS v1 was discovered to contain a stored cross-site scripting (XSS) vulnerability via add_post.php. This v... |
| CVE-2022-27063 | MEDIUM | 6.1 | 1.4% | Apr 8, 2022 | AeroCMS v0.0.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability via view_all_comments.php. Th... |
| CVE-2022-27062 | MEDIUM | 4.8 | 1.1% | Apr 8, 2022 | AeroCMS v0.0.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability via add_post.php. This vulner... |
| CVE-2022-26624 | MEDIUM | 6.1 | 0.9% | Apr 8, 2022 | Bootstrap v3.1.11 and v3.3.7 was discovered to contain a cross-site scripting (XSS) vulnerability via the Title paramete... |
| CVE-2022-24681 | MEDIUM | 6.1 | 3.6% | Apr 7, 2022 | Zoho ManageEngine ADSelfService Plus before 6121 allows XSS via the welcome name attribute to the Reset Password, Unlock... |
| CVE-2022-25595 | MEDIUM | 6.5 | 0.4% | Apr 7, 2022 | ASUS RT-AC86U has improper user request handling, which allows an unauthenticated LAN attacker to cause a denial of serv... |
| CVE-2022-25594 | MEDIUM | 5.3 | 1.0% | Apr 7, 2022 | Microprogram’s parking lot management system is vulnerable to sensitive information exposure. An unauthorized remote att... |
| CVE-2022-22518 | MEDIUM | 6.5 | 0.6% | Apr 7, 2022 | A bug in CmpUserMgr component can lead to only partially applied security policies. This can result in enabled, anonymou... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now