2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-22589 | MEDIUM | 6.1 | 2.0% | Mar 18, 2022 | A validation issue was addressed with improved input sanitization. This issue is fixed in iOS 15.3 and iPadOS 15.3, watc... |
| CVE-2022-22588 | MEDIUM | 5.5 | 9.4% | Mar 18, 2022 | A resource exhaustion issue was addressed with improved input validation. This issue is fixed in iOS 15.2.1 and iPadOS 1... |
| CVE-2022-22583 | MEDIUM | 5.5 | 1.6% | Mar 18, 2022 | A permissions issue was addressed with improved validation. This issue is fixed in Security Update 2022-001 Catalina, ma... |
| CVE-2022-1003 | MEDIUM | 4.9 | 0.5% | Mar 18, 2022 | One of the API in Mattermost version 6.3.0 and earlier fails to properly protect the permissions, which allows the syste... |
| CVE-2022-1002 | MEDIUM | 5.4 | 0.6% | Mar 18, 2022 | Mattermost 6.3.0 and earlier fails to properly sanitize the HTML content in the email invitation sent to guest users, wh... |
| CVE-2022-24773 | MEDIUM | 5.3 | 0.9% | Mar 18, 2022 | Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version ... |
| CVE-2022-0758 | MEDIUM | 6.1 | 0.4% | Mar 17, 2022 | Rapid7 Nexpose versions 6.6.129 and earlier suffer from a reflected cross site scripting vulnerability, within the share... |
| CVE-2022-24302 | MEDIUM | 5.9 | 2.1% | Mar 17, 2022 | In Paramiko before 2.10.1, a race condition (between creation and chmod) in the write_private_key_file function could al... |
| CVE-2022-24075 | MEDIUM | 6.5 | 0.8% | Mar 17, 2022 | Whale browser before 3.12.129.18 allowed extensions to replace JavaScript files of the HWP viewer website which could ac... |
| CVE-2022-24072 | MEDIUM | 6.1 | 0.6% | Mar 17, 2022 | The devtools API in Whale browser before 3.12.129.18 allowed extension developers to inject arbitrary JavaScript into th... |
| CVE-2022-25516 | MEDIUM | 6.5 | 0.9% | Mar 17, 2022 | stb_truetype.h v1.26 was discovered to contain a heap-buffer-overflow via the function stbtt__find_table at stb_truetype... |
| CVE-2022-25515 | MEDIUM | 6.5 | 0.9% | Mar 17, 2022 | stb_truetype.h v1.26 was discovered to contain a heap-buffer-overflow via the function ttULONG() at stb_truetype.h. NOTE... |
| CVE-2022-26295 | MEDIUM | 5.4 | 0.6% | Mar 16, 2022 | A stored cross-site scripting (XSS) vulnerability in /ptms/?page=user of Online Project Time Management System v1.0 allo... |
| CVE-2022-24728 | MEDIUM | 5.4 | 1.2% | Mar 16, 2022 | CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A vulnerability has been discovered in the core HT... |
| CVE-2022-25248 | MEDIUM | 5.3 | 0.9% | Mar 16, 2022 | When connecting to a certain port Axeda agent (All versions) and Axeda Desktop Server for Windows (All versions) supplie... |
| CVE-2022-23234 | MEDIUM | 5.5 | 0.2% | Mar 16, 2022 | SnapCenter versions prior to 4.5 are susceptible to a vulnerability which could allow a local authenticated attacker to ... |
| CVE-2022-0959 | MEDIUM | 6.5 | 0.9% | Mar 16, 2022 | A malicious, but authorised and authenticated user can construct an HTTP request using their existing CSRF token and ses... |
| CVE-2022-0986 | MEDIUM | 6.1 | 0.9% | Mar 16, 2022 | Reflected Cross-site Scripting (XSS) Vulnerability in GitHub repository hestiacp/hestiacp prior to 1.5.11. |
| CVE-2022-0705 | MEDIUM | 5.4 | 0.5% | Mar 16, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.4.0. |
| CVE-2022-21946 | MEDIUM | 5.3 | 0.3% | Mar 16, 2022 | A Incorrect Permission Assignment for Critical Resource vulnerability in the sudoers configuration in cscreen of openSUS... |
| CVE-2022-21945 | MEDIUM | 6.1 | 0.2% | Mar 16, 2022 | A Insecure Temporary File vulnerability in cscreen of openSUSE Factory allows local attackers to cause DoS for cscreen a... |
| CVE-2022-0704 | MEDIUM | 5.4 | 1.3% | Mar 16, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.4.0. |
| CVE-2022-0911 | MEDIUM | 5.4 | 0.8% | Mar 16, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.4.0. |
| CVE-2022-27225 | MEDIUM | 6.5 | 0.5% | Mar 16, 2022 | Gradle Enterprise before 2021.4.3 relies on cleartext data transmission in some situations. It uses Keycloak for identit... |
| CVE-2022-25497 | MEDIUM | 5.3 | 3.6% | Mar 15, 2022 | CuppaCMS v1.0 was discovered to contain an arbitrary file read via the copy function. |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now