2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-22589MEDIUM6.1A validation issue was addressed with improved input sanitization. This issue is fixed in iOS 15.3 and iPadOS 15.3, watc...
CVE-2022-22588MEDIUM5.5A resource exhaustion issue was addressed with improved input validation. This issue is fixed in iOS 15.2.1 and iPadOS 1...
CVE-2022-22583MEDIUM5.5A permissions issue was addressed with improved validation. This issue is fixed in Security Update 2022-001 Catalina, ma...
CVE-2022-1003MEDIUM4.9One of the API in Mattermost version 6.3.0 and earlier fails to properly protect the permissions, which allows the syste...
CVE-2022-1002MEDIUM5.4Mattermost 6.3.0 and earlier fails to properly sanitize the HTML content in the email invitation sent to guest users, wh...
CVE-2022-24773MEDIUM5.3Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version ...
CVE-2022-0758MEDIUM6.1Rapid7 Nexpose versions 6.6.129 and earlier suffer from a reflected cross site scripting vulnerability, within the share...
CVE-2022-24302MEDIUM5.9In Paramiko before 2.10.1, a race condition (between creation and chmod) in the write_private_key_file function could al...
CVE-2022-24075MEDIUM6.5Whale browser before 3.12.129.18 allowed extensions to replace JavaScript files of the HWP viewer website which could ac...
CVE-2022-24072MEDIUM6.1The devtools API in Whale browser before 3.12.129.18 allowed extension developers to inject arbitrary JavaScript into th...
CVE-2022-25516MEDIUM6.5stb_truetype.h v1.26 was discovered to contain a heap-buffer-overflow via the function stbtt__find_table at stb_truetype...
CVE-2022-25515MEDIUM6.5stb_truetype.h v1.26 was discovered to contain a heap-buffer-overflow via the function ttULONG() at stb_truetype.h. NOTE...
CVE-2022-26295MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in /ptms/?page=user of Online Project Time Management System v1.0 allo...
CVE-2022-24728MEDIUM5.4CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A vulnerability has been discovered in the core HT...
CVE-2022-25248MEDIUM5.3When connecting to a certain port Axeda agent (All versions) and Axeda Desktop Server for Windows (All versions) supplie...
CVE-2022-23234MEDIUM5.5SnapCenter versions prior to 4.5 are susceptible to a vulnerability which could allow a local authenticated attacker to ...
CVE-2022-0959MEDIUM6.5A malicious, but authorised and authenticated user can construct an HTTP request using their existing CSRF token and ses...
CVE-2022-0986MEDIUM6.1Reflected Cross-site Scripting (XSS) Vulnerability in GitHub repository hestiacp/hestiacp prior to 1.5.11.
CVE-2022-0705MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.4.0.
CVE-2022-21946MEDIUM5.3A Incorrect Permission Assignment for Critical Resource vulnerability in the sudoers configuration in cscreen of openSUS...
CVE-2022-21945MEDIUM6.1A Insecure Temporary File vulnerability in cscreen of openSUSE Factory allows local attackers to cause DoS for cscreen a...
CVE-2022-0704MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.4.0.
CVE-2022-0911MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.4.0.
CVE-2022-27225MEDIUM6.5Gradle Enterprise before 2021.4.3 relies on cleartext data transmission in some situations. It uses Keycloak for identit...
CVE-2022-25497MEDIUM5.3CuppaCMS v1.0 was discovered to contain an arbitrary file read via the copy function.

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now