2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-28356 | MEDIUM | 5.5 | 0.6% | Apr 2, 2022 | In the Linux kernel before 5.17.1, a refcount leak bug was found in net/llc/af_llc.c. |
| CVE-2022-28352 | MEDIUM | 4.8 | 0.4% | Apr 2, 2022 | WeeChat (aka Wee Enhanced Environment for Chat) 3.2 to 3.4 before 3.4.1 does not properly verify the TLS certificate of ... |
| CVE-2022-1201 | MEDIUM | 6.5 | 0.4% | Apr 2, 2022 | NULL Pointer Dereference in mrb_vm_exec with super in GitHub repository mruby/mruby prior to 3.2. This vulnerability is ... |
| CVE-2022-25160 | MEDIUM | 5.9 | 1.1% | Apr 1, 2022 | Cleartext Storage of Sensitive Information vulnerability in Mitsubishi Electric MELSEC iQ-F series FX5U(C) CPU all versi... |
| CVE-2022-22950 | MEDIUM | 6.5 | 36.7% | Apr 1, 2022 | n Spring Framework versions 5.3.0 - 5.3.16 and older unsupported versions, it is possible for a user to provide a specia... |
| CVE-2022-21830 | MEDIUM | 6.1 | 0.8% | Apr 1, 2022 | A blind self XSS vulnerability exists in RocketChat LiveChat <v1.9 that could allow an attacker to trick a victim pastin... |
| CVE-2022-1018 | MEDIUM | 5.5 | 2.1% | Apr 1, 2022 | When opening a malicious solution file provided by an attacker, the application suffers from an XML external entity vuln... |
| CVE-2022-0922 | MEDIUM | 6.5 | 0.4% | Apr 1, 2022 | The software does not perform any authentication for critical system functionality. |
| CVE-2022-0489 | MEDIUM | 5.7 | 1.5% | Apr 1, 2022 | An issue has been discovered in GitLab CE/EE affecting all versions starting with 8.15 . It was possible to trigger a DO... |
| CVE-2022-0390 | MEDIUM | 4.3 | 0.9% | Apr 1, 2022 | Improper access control in Gitlab CE/EE versions 12.7 to 14.5.4, 14.6 to 14.6.4, and 14.7 to 14.7.1 allowed for project ... |
| CVE-2022-0373 | MEDIUM | 4.3 | 0.9% | Apr 1, 2022 | Improper access control in GitLab CE/EE versions 12.4 to 14.5.4, 14.5 to 14.6.4, and 12.6 to 14.7.1 allows project non-m... |
| CVE-2022-26565 | MEDIUM | 4.8 | 0.5% | Apr 1, 2022 | A cross-site scripting (XSS) vulnerability in Totaljs all versions before commit 95f54a5commit, allows attackers to exec... |
| CVE-2022-23158 | MEDIUM | 4.4 | 0.7% | Apr 1, 2022 | Wyse Device Agent version 14.6.1.4 and below contain a sensitive data exposure vulnerability. A local authenticated user... |
| CVE-2022-23157 | MEDIUM | 4.4 | 0.2% | Apr 1, 2022 | Wyse Device Agent version 14.6.1.4 and below contain a sensitive data exposure vulnerability. A authenticated malicious ... |
| CVE-2022-23156 | MEDIUM | 6.7 | 0.2% | Apr 1, 2022 | Wyse Device Agent version 14.6.1.4 and below contain an Improper Authentication vulnerability. A malicious user could po... |
| CVE-2022-1207 | MEDIUM | 6.6 | 0.9% | Apr 1, 2022 | Out-of-bounds read in GitHub repository radareorg/radare2 prior to 5.6.8. This vulnerability allows attackers to read se... |
| CVE-2022-22404 | MEDIUM | 6.5 | 0.9% | Apr 1, 2022 | IBM App Connect Enterprise Certified Container Dashboard UI (IBM App Connect Enterprise Certified Container 1.5, 2.0, 2.... |
| CVE-2022-22328 | MEDIUM | 6.2 | 0.2% | Apr 1, 2022 | IBM SterlingPartner Engagement Manager 6.2.0 could allow a malicious user to elevate their privileges and perform uninte... |
| CVE-2022-24181 | MEDIUM | 6.1 | 6.1% | Apr 1, 2022 | Cross-site scripting (XSS) via Host Header injection in PKP Open Journals System 2.4.8 >= 3.3 allows remote attackers to... |
| CVE-2022-27966 | MEDIUM | 6.5 | 0.5% | Mar 31, 2022 | Xshell v7.0.0099 and below contains a binary hijack vulnerability which allows attackers to execute arbitrary code via a... |
| CVE-2022-27965 | MEDIUM | 6.5 | 0.5% | Mar 31, 2022 | Xlpd v7.0.0094 and below contains a binary hijack vulnerability which allows attackers to execute arbitrary code via a c... |
| CVE-2022-27964 | MEDIUM | 6.5 | 0.5% | Mar 31, 2022 | Xmanager v7.0.0096 and below contains a binary hijack vulnerability which allows attackers to execute arbitrary code via... |
| CVE-2022-27963 | MEDIUM | 6.5 | 0.4% | Mar 31, 2022 | Xftp 7.0.0088p and below contains a binary hijack vulnerability which allows attackers to execute arbitrary code via a c... |
| CVE-2022-24794 | MEDIUM | 6.1 | 0.7% | Mar 31, 2022 | Express OpenID Connect is an Express JS middleware implementing sign on for Express web apps using OpenID Connect. Users... |
| CVE-2022-22311 | MEDIUM | 6.5 | 0.7% | Mar 31, 2022 | IBM Security Verify Access could allow a user, using man in the middle techniques, to obtain sensitive information or po... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now