2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-22946 | MEDIUM | 5.5 | 4.7% | Mar 4, 2022 | In spring cloud gateway versions prior to 3.1.1+ , applications that are configured to enable HTTP2 and no key store or ... |
| CVE-2022-23397 | MEDIUM | 6.1 | 0.9% | Mar 4, 2022 | The Cedar Gate EZ-NET portal 6.5.5 6.8.0 Internet portal has a call to display messages to users which does not properly... |
| CVE-2022-0832 | MEDIUM | 5.4 | 66.6% | Mar 4, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.3.3. |
| CVE-2022-0831 | MEDIUM | 5.4 | 1.3% | Mar 4, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.3.3. |
| CVE-2022-0752 | MEDIUM | 6.1 | 1.0% | Mar 4, 2022 | Cross-site Scripting (XSS) - Generic in GitHub repository hestiacp/hestiacp prior to 1.5.9. |
| CVE-2022-0838 | MEDIUM | 6.1 | 1.1% | Mar 4, 2022 | Cross-site Scripting (XSS) - Reflected in GitHub repository hestiacp/hestiacp prior to 1.5.10. |
| CVE-2022-25220 | MEDIUM | 4.8 | 0.5% | Mar 3, 2022 | PeteReport Version 0.5 allows an authenticated admin user to inject persistent JavaScript code inside the markdown descr... |
| CVE-2022-24725 | MEDIUM | 5.5 | 0.5% | Mar 3, 2022 | Shescape is a shell escape package for JavaScript. An issue in versions 1.4.0 to 1.5.1 allows for exposure of the home d... |
| CVE-2022-23710 | MEDIUM | 6.1 | 0.7% | Mar 3, 2022 | A cross-site-scripting (XSS) vulnerability was discovered in the Data Preview Pane (previously known as Index Pattern Pr... |
| CVE-2022-23709 | MEDIUM | 4.3 | 0.5% | Mar 3, 2022 | A flaw was discovered in Kibana in which users with Read access to the Uptime feature could modify alerting rules. A use... |
| CVE-2022-23708 | MEDIUM | 4.3 | 0.9% | Mar 3, 2022 | A flaw was discovered in Elasticsearch 7.17.0’s upgrade assistant, in which upgrading from version 6.x to 7.x would disa... |
| CVE-2022-23052 | MEDIUM | 6.5 | 0.4% | Mar 3, 2022 | PeteReport Version 0.5 contains a Cross Site Request Forgery (CSRF) vulnerability allowing an attacker to trick users in... |
| CVE-2022-23051 | MEDIUM | 5.4 | 0.5% | Mar 3, 2022 | PeteReport Version 0.5 allows an authenticated admin user to inject persistent JavaScript code while adding an 'Attack T... |
| CVE-2022-22943 | MEDIUM | 6.7 | 1.2% | Mar 3, 2022 | VMware Tools for Windows (11.x.y and 10.x.y prior to 12.0.0) contains an uncontrolled search path vulnerability. A malic... |
| CVE-2022-24723 | MEDIUM | 5.3 | 2.0% | Mar 3, 2022 | URI.js is a Javascript URL mutation library. Before version 1.19.9, whitespace characters are not removed from the begin... |
| CVE-2022-22700 | MEDIUM | 5.3 | 1.1% | Mar 3, 2022 | CyberArk Identity versions up to and including 22.1 in the 'StartAuthentication' resource, exposes the response header '... |
| CVE-2022-25138 | MEDIUM | 5.4 | 0.6% | Mar 3, 2022 | Axelor Open Suite v5.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Name paramete... |
| CVE-2022-0753 | MEDIUM | 6.1 | 0.8% | Mar 3, 2022 | Cross-site Scripting (XSS) - Reflected in GitHub repository hestiacp/hestiacp prior to 1.5.9. |
| CVE-2022-23849 | MEDIUM | 6.6 | 0.2% | Mar 3, 2022 | The biometric lock in Devolutions Password Hub for iOS before 2021.3.4 allows attackers to access the application becaus... |
| CVE-2022-24573 | MEDIUM | 6.1 | 0.6% | Mar 3, 2022 | A stored cross-site scripting (XSS) vulnerability in the admin interface in Element-IT HTTP Commander 7.0.0 allows unaut... |
| CVE-2022-24563 | MEDIUM | 5.4 | 0.9% | Mar 3, 2022 | In Genixcms v1.1.11, a stored Cross-Site Scripting (XSS) vulnerability exists in /gxadmin/index.php?page=themes&view=opt... |
| CVE-2022-25146 | MEDIUM | 5.3 | 0.6% | Mar 3, 2022 | The Remote App module in Liferay Portal Liferay Portal v7.4.3.4 through v7.4.3.8 and Liferay DXP 7.4 before update 5 doe... |
| CVE-2022-25114 | MEDIUM | 6.1 | 0.7% | Mar 2, 2022 | Event Management v1.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the full_name p... |
| CVE-2022-24722 | MEDIUM | 6.1 | 1.1% | Mar 2, 2022 | VIewComponent is a framework for building view components in Ruby on Rails. Versions prior to 2.31.2 and 2.49.1 contain ... |
| CVE-2022-23958 | MEDIUM | 5.5 | 0.2% | Mar 2, 2022 | Potential vulnerabilities have been identified in the BIOS for some HP PC products which may allow denial of service. |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now