2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-22513 | MEDIUM | 6.5 | 1.0% | Apr 7, 2022 | An authenticated remote attacker can cause a null pointer dereference in the CmpSettings component of the affected CODES... |
| CVE-2022-25339 | MEDIUM | 5.5 | 0.2% | Apr 7, 2022 | ownCloud owncloud/android 2.20 has Incorrect Access Control for local attackers. |
| CVE-2022-25338 | MEDIUM | 6.8 | 0.2% | Apr 7, 2022 | ownCloud owncloud/android before 2.20 has Incorrect Access Control for physically proximate attackers. |
| CVE-2022-27819 | MEDIUM | 5.3 | 0.8% | Apr 7, 2022 | SWHKD 1.1.5 allows unsafe parsing via the -c option. An information leak might occur but there is a simple denial of ser... |
| CVE-2022-20782 | MEDIUM | 6.5 | 1.0% | Apr 6, 2022 | A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticat... |
| CVE-2022-20781 | MEDIUM | 5.4 | 0.6% | Apr 6, 2022 | A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Web Security Appliance (WSA) c... |
| CVE-2022-20741 | MEDIUM | 5.4 | 0.6% | Apr 6, 2022 | A vulnerability in the web-based management interface of the Network Diagrams application for Cisco Secure Network Analy... |
| CVE-2022-20675 | MEDIUM | 5.3 | 1.2% | Apr 6, 2022 | A vulnerability in the TCP/IP stack of Cisco Email Security Appliance (ESA), Cisco Web Security Appliance (WSA), and Cis... |
| CVE-2022-20665 | MEDIUM | 6.7 | 0.3% | Apr 6, 2022 | A vulnerability in the CLI of Cisco StarOS could allow an authenticated, local attacker to elevate privileges on an affe... |
| CVE-2022-26850 | MEDIUM | 4.3 | 1.4% | Apr 6, 2022 | When creating or updating credentials for single-user access, Apache NiFi wrote a copy of the Login Identity Providers c... |
| CVE-2022-20784 | MEDIUM | 5.3 | 0.9% | Apr 6, 2022 | A vulnerability in the Web-Based Reputation Score (WBRS) engine of Cisco AsyncOS Software for Cisco Web Security Applian... |
| CVE-2022-27110 | MEDIUM | 5.4 | 0.5% | Apr 6, 2022 | OrangeHRM 4.10 is vulnerable to a Host header injection redirect via viewPersonalDetails endpoint. |
| CVE-2022-27109 | MEDIUM | 5.4 | 0.5% | Apr 6, 2022 | OrangeHRM 4.10 suffers from a Referer header injection redirect vulnerability. |
| CVE-2022-27108 | MEDIUM | 4.3 | 0.6% | Apr 6, 2022 | OrangeHRM 4.10 is vulnerable to Insecure Direct Object Reference (IDOR) via the end point symfony/web/index.php/time/cre... |
| CVE-2022-27107 | MEDIUM | 5.4 | 0.5% | Apr 6, 2022 | OrangeHRM 4.10 is vulnerable to Stored XSS in the "Share Video" section under "OrangeBuzz" via the GET/POST "createVideo... |
| CVE-2022-23446 | MEDIUM | 4.4 | 0.2% | Apr 6, 2022 | A improper control of a resource through its lifetime in Fortinet FortiEDR version 5.0.3 and earlier allows attacker to ... |
| CVE-2022-1234 | MEDIUM | 6.1 | 0.7% | Apr 6, 2022 | XSS in livehelperchat in GitHub repository livehelperchat/livehelperchat prior to 3.97. This vulnerability has the poten... |
| CVE-2022-24523 | MEDIUM | 4.3 | 1.3% | Apr 5, 2022 | Microsoft Edge (Chromium-based) Spoofing Vulnerability |
| CVE-2022-25373 | MEDIUM | 5.4 | 1.1% | Apr 5, 2022 | Zoho ManageEngine SupportCenter Plus before 11020 allows Stored XSS in the request history. |
| CVE-2022-25245 | MEDIUM | 5.3 | 1.3% | Apr 5, 2022 | Zoho ManageEngine ServiceDesk Plus before 13001 allows anyone to know the organisation's default currency name. |
| CVE-2022-24811 | MEDIUM | 5.4 | 0.7% | Apr 5, 2022 | Combodi iTop is a web based IT Service Management tool. Prior to versions 2.7.6 and 3.0.0, cross-site scripting is possi... |
| CVE-2022-1244 | MEDIUM | 5.5 | 0.8% | Apr 5, 2022 | heap-buffer-overflow in GitHub repository radareorg/radare2 prior to 5.6.8. This vulnerability is capable of inducing de... |
| CVE-2022-28651 | MEDIUM | 5.5 | 0.3% | Apr 5, 2022 | In JetBrains IntelliJ IDEA before 2021.3.3 it was possible to get passwords from protected fields |
| CVE-2022-28650 | MEDIUM | 5.4 | 0.6% | Apr 5, 2022 | In JetBrains YouTrack before 2022.1.43700 it was possible to inject JavaScript into Markdown in the YouTrack Classic UI |
| CVE-2022-28649 | MEDIUM | 5.4 | 0.4% | Apr 5, 2022 | In JetBrains YouTrack before 2022.1.43563 it was possible to include an iframe from a third-party domain in the issue de... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now