2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-28356MEDIUM5.5In the Linux kernel before 5.17.1, a refcount leak bug was found in net/llc/af_llc.c.
CVE-2022-28352MEDIUM4.8WeeChat (aka Wee Enhanced Environment for Chat) 3.2 to 3.4 before 3.4.1 does not properly verify the TLS certificate of ...
CVE-2022-1201MEDIUM6.5NULL Pointer Dereference in mrb_vm_exec with super in GitHub repository mruby/mruby prior to 3.2. This vulnerability is ...
CVE-2022-25160MEDIUM5.9Cleartext Storage of Sensitive Information vulnerability in Mitsubishi Electric MELSEC iQ-F series FX5U(C) CPU all versi...
CVE-2022-22950MEDIUM6.5n Spring Framework versions 5.3.0 - 5.3.16 and older unsupported versions, it is possible for a user to provide a specia...
CVE-2022-21830MEDIUM6.1A blind self XSS vulnerability exists in RocketChat LiveChat <v1.9 that could allow an attacker to trick a victim pastin...
CVE-2022-1018MEDIUM5.5When opening a malicious solution file provided by an attacker, the application suffers from an XML external entity vuln...
CVE-2022-0922MEDIUM6.5The software does not perform any authentication for critical system functionality.
CVE-2022-0489MEDIUM5.7An issue has been discovered in GitLab CE/EE affecting all versions starting with 8.15 . It was possible to trigger a DO...
CVE-2022-0390MEDIUM4.3Improper access control in Gitlab CE/EE versions 12.7 to 14.5.4, 14.6 to 14.6.4, and 14.7 to 14.7.1 allowed for project ...
CVE-2022-0373MEDIUM4.3Improper access control in GitLab CE/EE versions 12.4 to 14.5.4, 14.5 to 14.6.4, and 12.6 to 14.7.1 allows project non-m...
CVE-2022-26565MEDIUM4.8A cross-site scripting (XSS) vulnerability in Totaljs all versions before commit 95f54a5commit, allows attackers to exec...
CVE-2022-23158MEDIUM4.4Wyse Device Agent version 14.6.1.4 and below contain a sensitive data exposure vulnerability. A local authenticated user...
CVE-2022-23157MEDIUM4.4Wyse Device Agent version 14.6.1.4 and below contain a sensitive data exposure vulnerability. A authenticated malicious ...
CVE-2022-23156MEDIUM6.7Wyse Device Agent version 14.6.1.4 and below contain an Improper Authentication vulnerability. A malicious user could po...
CVE-2022-1207MEDIUM6.6Out-of-bounds read in GitHub repository radareorg/radare2 prior to 5.6.8. This vulnerability allows attackers to read se...
CVE-2022-22404MEDIUM6.5IBM App Connect Enterprise Certified Container Dashboard UI (IBM App Connect Enterprise Certified Container 1.5, 2.0, 2....
CVE-2022-22328MEDIUM6.2IBM SterlingPartner Engagement Manager 6.2.0 could allow a malicious user to elevate their privileges and perform uninte...
CVE-2022-24181MEDIUM6.1Cross-site scripting (XSS) via Host Header injection in PKP Open Journals System 2.4.8 >= 3.3 allows remote attackers to...
CVE-2022-27966MEDIUM6.5Xshell v7.0.0099 and below contains a binary hijack vulnerability which allows attackers to execute arbitrary code via a...
CVE-2022-27965MEDIUM6.5Xlpd v7.0.0094 and below contains a binary hijack vulnerability which allows attackers to execute arbitrary code via a c...
CVE-2022-27964MEDIUM6.5Xmanager v7.0.0096 and below contains a binary hijack vulnerability which allows attackers to execute arbitrary code via...
CVE-2022-27963MEDIUM6.5Xftp 7.0.0088p and below contains a binary hijack vulnerability which allows attackers to execute arbitrary code via a c...
CVE-2022-24794MEDIUM6.1Express OpenID Connect is an Express JS middleware implementing sign on for Express web apps using OpenID Connect. Users...
CVE-2022-22311MEDIUM6.5IBM Security Verify Access could allow a user, using man in the middle techniques, to obtain sensitive information or po...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now