2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-28648 | MEDIUM | 5.4 | 1.3% | Apr 5, 2022 | In JetBrains YouTrack before 2022.1.43563 HTML code from the issue description was being rendered |
| CVE-2022-22356 | MEDIUM | 6.5 | 0.8% | Apr 5, 2022 | IBM MQ Appliance 9.2 CD and 9.2 LTS could allow an attacker to enumerate account credentials due to an observable discre... |
| CVE-2022-22355 | MEDIUM | 5.3 | 1.1% | Apr 5, 2022 | IBM MQ Appliance 9.2 CD and 9.2 LTS are vulnerable to a denial of service in the Login component of the application whic... |
| CVE-2022-27463 | MEDIUM | 6.1 | 0.6% | Apr 5, 2022 | Open redirect vulnerability in objects/login.json.php in WWBN AVideo through 11.6, allows attackers to arbitrarily redir... |
| CVE-2022-27462 | MEDIUM | 6.1 | 0.6% | Apr 5, 2022 | Cross Site Scripting (XSS) vulnerability in objects/function.php in function getDeviceID in WWBN AVideo through 11.6, vi... |
| CVE-2022-0602 | MEDIUM | 5.4 | 0.7% | Apr 5, 2022 | Cross-site Scripting (XSS) - DOM in GitHub repository tastyigniter/tastyigniter prior to 3.3.0. |
| CVE-2022-1243 | MEDIUM | 6.1 | 0.7% | Apr 5, 2022 | CRHTLF can lead to invalid protocol extraction potentially leading to XSS in GitHub repository medialize/uri.js prior to... |
| CVE-2022-26356 | MEDIUM | 5.6 | 0.2% | Apr 5, 2022 | Racy interactions between dirty vram tracking and paging log dirty hypercalls Activation of log dirty mode done by XEN_D... |
| CVE-2022-1236 | MEDIUM | 6.5 | 0.5% | Apr 5, 2022 | Weak Password Requirements in GitHub repository weseek/growi prior to v5.0.0. |
| CVE-2022-26615 | MEDIUM | 5.4 | 0.5% | Apr 5, 2022 | A cross-site scripting (XSS) vulnerability in College Website Content Management System v1.0 allows attackers to execute... |
| CVE-2022-25356 | MEDIUM | 5.3 | 5.9% | Apr 5, 2022 | Alt-N MDaemon Security Gateway through 8.5.0 allows SecurityGateway.dll?view=login XML Injection. |
| CVE-2022-0807 | MEDIUM | 6.5 | 0.9% | Apr 5, 2022 | Inappropriate implementation in Autofill in Google Chrome prior to 99.0.4844.51 allowed a remote attacker to bypass navi... |
| CVE-2022-0806 | MEDIUM | 6.5 | 1.0% | Apr 5, 2022 | Data leak in Canvas in Google Chrome prior to 99.0.4844.51 allowed a remote attacker who convinced a user to engage in s... |
| CVE-2022-0804 | MEDIUM | 6.5 | 0.9% | Apr 5, 2022 | Inappropriate implementation in Full screen mode in Google Chrome on Android prior to 99.0.4844.51 allowed a remote atta... |
| CVE-2022-0803 | MEDIUM | 6.5 | 0.8% | Apr 5, 2022 | Inappropriate implementation in Permissions in Google Chrome prior to 99.0.4844.51 allowed a remote attacker to tamper w... |
| CVE-2022-0802 | MEDIUM | 6.5 | 0.9% | Apr 5, 2022 | Inappropriate implementation in Full screen mode in Google Chrome on Android prior to 99.0.4844.51 allowed a remote atta... |
| CVE-2022-0792 | MEDIUM | 6.5 | 1.0% | Apr 5, 2022 | Out of bounds read in ANGLE in Google Chrome prior to 99.0.4844.51 allowed a remote attacker to potentially exploit heap... |
| CVE-2022-0462 | MEDIUM | 6.5 | 0.8% | Apr 5, 2022 | Inappropriate implementation in Scroll in Google Chrome prior to 98.0.4758.80 allowed a remote attacker to leak cross-or... |
| CVE-2022-0461 | MEDIUM | 6.5 | 0.8% | Apr 5, 2022 | Policy bypass in COOP in Google Chrome prior to 98.0.4758.80 allowed a remote attacker to bypass iframe sandbox via a cr... |
| CVE-2022-0455 | MEDIUM | 6.5 | 0.6% | Apr 5, 2022 | Inappropriate implementation in Full Screen Mode in Google Chrome on Android prior to 98.0.4758.80 allowed a remote atta... |
| CVE-2022-27441 | MEDIUM | 4.8 | 0.4% | Apr 4, 2022 | A stored cross-site scripting (XSS) vulnerability in TPCMS v3.2 allows attackers to execute arbitrary web scripts or HTM... |
| CVE-2022-27651 | MEDIUM | 6.8 | 1.2% | Apr 4, 2022 | A flaw was found in buildah where containers were incorrectly started with non-empty default permissions. A bug was foun... |
| CVE-2022-27609 | MEDIUM | 6 | 0.2% | Apr 4, 2022 | Forcepoint One Endpoint prior to version 22.01 installed on Microsoft Windows does not provide sufficient anti-tampering... |
| CVE-2022-27608 | MEDIUM | 6 | 0.2% | Apr 4, 2022 | Forcepoint One Endpoint prior to version 22.01 installed on Microsoft Windows is vulnerable to registry key tampering by... |
| CVE-2022-25618 | MEDIUM | 4.8 | 0.5% | Apr 4, 2022 | Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in wpDataTables (WordPress plugin) versions <= 2.... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now