2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-24329 | MEDIUM | 5.3 | 2.2% | Feb 25, 2022 | In JetBrains Kotlin before 1.6.0, it was not possible to lock dependencies for Multiplatform Gradle Projects. |
| CVE-2022-24328 | MEDIUM | 6.5 | 0.8% | Feb 25, 2022 | In JetBrains Hub before 2021.1.13956, an unprivileged user could perform DoS. |
| CVE-2022-24612 | MEDIUM | 5.4 | 0.5% | Feb 25, 2022 | An authenticated user can upload an XML file containing an XSS via the ITSM module of EyesOfNetwork 5.3.11, resulting in... |
| CVE-2022-24594 | MEDIUM | 5.3 | 0.8% | Feb 25, 2022 | In waline 1.6.1, an attacker can submit messages using X-Forwarded-For to forge any IP address. |
| CVE-2022-25327 | MEDIUM | 5.5 | 0.1% | Feb 25, 2022 | The PAM module for fscrypt doesn't adequately validate fscrypt metadata files, allowing users to create malicious metada... |
| CVE-2022-25326 | MEDIUM | 5.5 | 0.1% | Feb 25, 2022 | fscrypt through v0.3.2 creates a world-writable directory by default when setting up a filesystem, allowing unprivileged... |
| CVE-2022-0247 | MEDIUM | 5.5 | 0.1% | Feb 25, 2022 | An issue exists in Fuchsia where VMO data can be modified through access to copy-on-write snapshots. A local attacker co... |
| CVE-2022-24948 | MEDIUM | 6.1 | 2.2% | Feb 25, 2022 | A carefully crafted user preferences for submission could trigger an XSS vulnerability on Apache JSPWiki, related to the... |
| CVE-2022-0746 | MEDIUM | 4.3 | 0.9% | Feb 25, 2022 | Business Logic Errors in GitHub repository dolibarr/dolibarr prior to 16.0. |
| CVE-2022-23701 | MEDIUM | 5.3 | 0.7% | Feb 24, 2022 | A potential remote host header injection security vulnerability has been identified in HPE Integrated Lights-Out 4 (iLO ... |
| CVE-2022-24709 | MEDIUM | 6.1 | 0.7% | Feb 24, 2022 | @awsui/components-react is the main AWS UI package which contains React components, with TypeScript definitions designed... |
| CVE-2022-25307 | MEDIUM | 6.1 | 1.4% | Feb 24, 2022 | The WP Statistics WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escaping and sanitization o... |
| CVE-2022-25306 | MEDIUM | 6.1 | 1.4% | Feb 24, 2022 | The WP Statistics WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escaping and sanitization o... |
| CVE-2022-25305 | MEDIUM | 6.1 | 81.2% | Feb 24, 2022 | The WP Statistics WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escaping and sanitization o... |
| CVE-2022-23135 | MEDIUM | 6.5 | 1.4% | Feb 24, 2022 | There is a directory traversal vulnerability in some home gateway products of ZTE. Due to the lack of verification of us... |
| CVE-2022-0710 | MEDIUM | 6.1 | 2.4% | Feb 24, 2022 | The Header Footer Code Manager plugin <= 1.1.16 for WordPress is vulnerable to Reflected Cross-Site Scripting (XSS) via ... |
| CVE-2022-0683 | MEDIUM | 6.1 | 3.2% | Feb 24, 2022 | The Essential Addons for Elementor Lite WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escap... |
| CVE-2022-0653 | MEDIUM | 6.1 | 2.7% | Feb 24, 2022 | The Profile Builder – User Profile & User Registration Forms WordPress plugin is vulnerable to Cross-Site Scripting due ... |
| CVE-2022-0544 | MEDIUM | 5.5 | 1.1% | Feb 24, 2022 | An integer underflow in the DDS loader of Blender leads to an out-of-bounds read, possibly allowing an attacker to read ... |
| CVE-2022-22349 | MEDIUM | 4.3 | 1.0% | Feb 24, 2022 | IBM Sterling External Authentication Server 3.4.3.2, 6.0.2.0, and 6.0.3.0 is vulnerable to path traversals, due to not p... |
| CVE-2022-24708 | MEDIUM | 5.4 | 0.5% | Feb 24, 2022 | Anuko Time Tracker is an open source, web-based time tracking application written in PHP. ttUser.class.php in Time Track... |
| CVE-2022-24687 | MEDIUM | 6.5 | 1.4% | Feb 24, 2022 | HashiCorp Consul and Consul Enterprise 1.9.0 through 1.9.14, 1.10.7, and 1.11.2 clusters with at least one Ingress Gatew... |
| CVE-2022-25638 | MEDIUM | 6.5 | 0.6% | Feb 24, 2022 | In wolfSSL before 5.2.0, certificate validation may be bypassed during attempted authentication by a TLS 1.3 client to a... |
| CVE-2022-25363 | MEDIUM | 6.5 | 0.9% | Feb 24, 2022 | WatchGuard Firebox and XTM appliances allow an authenticated remote attacker with unprivileged credentials to modify pri... |
| CVE-2022-25355 | MEDIUM | 5.3 | 1.1% | Feb 24, 2022 | EC-CUBE 3.0.0 to 3.0.18-p3 and EC-CUBE 4.0.0 to 4.1.1 improperly handle HTTP Host header values, which may lead a remote... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now