2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-21820 | MEDIUM | 6.3 | 17.0% | Mar 24, 2022 | NVIDIA DCGM contains a vulnerability in nvhostengine, where a network user can cause detection of error conditions witho... |
| CVE-2022-1058 | MEDIUM | 6.1 | 53.2% | Mar 24, 2022 | Open Redirect on login in GitHub repository go-gitea/gitea prior to 1.16.5. |
| CVE-2022-0955 | MEDIUM | 4.8 | 0.6% | Mar 24, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/data-hub prior to 1.2.4. |
| CVE-2022-1052 | MEDIUM | 5.5 | 0.4% | Mar 24, 2022 | Heap Buffer Overflow in iterate_chained_fixups in GitHub repository radareorg/radare2 prior to 5.6.6. |
| CVE-2022-0145 | MEDIUM | 5.4 | 0.7% | Mar 24, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository forkcms/forkcms prior to 5.11.1. |
| CVE-2022-27820 | MEDIUM | 4 | 0.7% | Mar 24, 2022 | OWASP Zed Attack Proxy (ZAP) through w2022-03-21 does not verify the TLS certificate chain of an HTTPS server. |
| CVE-2022-25269 | MEDIUM | 6.1 | 0.5% | Mar 23, 2022 | Passwork On-Premise Edition before 4.6.13 has multiple XSS issues. |
| CVE-2022-25266 | MEDIUM | 4.3 | 0.9% | Mar 23, 2022 | Passwork On-Premise Edition before 4.6.13 allows migration/downloadExportFile Directory Traversal (to read files). |
| CVE-2022-27254 | MEDIUM | 5.3 | 1.1% | Mar 23, 2022 | The remote keyless system on Honda Civic 2018 vehicles sends the same RF signal for each door-open request, which allows... |
| CVE-2022-25041 | MEDIUM | 4.3 | 0.8% | Mar 23, 2022 | OpenEMR v6.0.0 was discovered to contain an incorrect access control issue. |
| CVE-2022-24731 | MEDIUM | 4.9 | 0.9% | Mar 23, 2022 | Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Argo CD starting with version 1.5.0 but before... |
| CVE-2022-24730 | MEDIUM | 6.5 | 0.9% | Mar 23, 2022 | Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Argo CD starting with version 1.3.0 but before... |
| CVE-2022-25609 | MEDIUM | 5.4 | 0.5% | Mar 23, 2022 | Stored Cross-Site Scripting (XSS) in Yoo Slider – Image Slider & Video Slider (WordPress plugin) allows attackers with c... |
| CVE-2022-25608 | MEDIUM | 5.4 | 0.3% | Mar 23, 2022 | Cross-Site Request Forgery (CSRF) in Yoo Slider – Image Slider & Video Slider (WordPress plugin) allows attackers to tri... |
| CVE-2022-25223 | MEDIUM | 4.3 | 0.8% | Mar 23, 2022 | Money Transfer Management System Version 1.0 allows an authenticated user to inject SQL queries in 'mtms/admin/?page=tra... |
| CVE-2022-25221 | MEDIUM | 6.1 | 0.7% | Mar 23, 2022 | Money Transfer Management System Version 1.0 allows an attacker to inject JavaScript code in the URL and then trick a us... |
| CVE-2022-0996 | MEDIUM | 6.5 | 1.5% | Mar 23, 2022 | A vulnerability was found in the 389 Directory Server that allows expired passwords to access the database to cause impr... |
| CVE-2022-0889 | MEDIUM | 6.1 | 0.7% | Mar 23, 2022 | The Ninja Forms - File Uploads Extension WordPress plugin is vulnerable to reflected cross-site scripting due to missing... |
| CVE-2022-0854 | MEDIUM | 5.5 | 0.5% | Mar 23, 2022 | A memory leak flaw was found in the Linux kernel’s DMA subsystem, in the way a user calls DMA_FROM_DEVICE. This flaw all... |
| CVE-2022-0834 | MEDIUM | 5.4 | 0.5% | Mar 23, 2022 | The Amelia WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escaping and sanitization of the l... |
| CVE-2022-0750 | MEDIUM | 5.4 | 4.4% | Mar 23, 2022 | The Photoswipe Masonry Gallery WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escaping and s... |
| CVE-2022-22316 | MEDIUM | 6.5 | 0.9% | Mar 23, 2022 | IBM MQ Appliance 9.2 CD and 9.2 LTS could allow an authenticated and authorized user to cause a denial of service due to... |
| CVE-2022-23242 | MEDIUM | 4.2 | 0.2% | Mar 23, 2022 | TeamViewer Linux versions before 15.28 do not properly execute a deletion command for the connection password in case of... |
| CVE-2022-0862 | MEDIUM | 5.3 | 0.7% | Mar 23, 2022 | A lack of password change protection vulnerability in a depreciated API of McAfee Enterprise ePolicy Orchestrator (ePO) ... |
| CVE-2022-0859 | MEDIUM | 6.7 | 0.2% | Mar 23, 2022 | McAfee Enterprise ePolicy Orchestrator (ePO) prior to 5.10 Update 13 allows a local attacker to point an ePO server to a... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now