2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-25290 | MEDIUM | 6.5 | 0.7% | Feb 24, 2022 | WatchGuard Firebox and XTM appliances allow an authenticated remote attacker with unprivileged credentials to retrieve c... |
| CVE-2022-24633 | MEDIUM | 5.3 | 0.8% | Feb 24, 2022 | All versions of FileCloud prior to 21.3 are vulnerable to user enumeration. The vulnerability exists in the parameter "p... |
| CVE-2022-24620 | MEDIUM | 5.4 | 0.6% | Feb 24, 2022 | Piwigo version 12.2.0 is vulnerable to stored cross-site scripting (XSS), which can lead to privilege escalation. In thi... |
| CVE-2022-24615 | MEDIUM | 5.5 | 0.7% | Feb 24, 2022 | zip4j up to v2.10.0 can throw various uncaught exceptions while parsing a specially crafted ZIP file, which could result... |
| CVE-2022-24614 | MEDIUM | 5.5 | 0.7% | Feb 24, 2022 | When reading a specially crafted JPEG file, metadata-extractor up to 2.16.0 can be made to allocate large amounts of mem... |
| CVE-2022-24613 | MEDIUM | 5.5 | 0.8% | Feb 24, 2022 | metadata-extractor up to 2.16.0 can throw various uncaught exceptions while parsing a specially crafted JPEG file, which... |
| CVE-2022-24599 | MEDIUM | 6.5 | 1.7% | Feb 24, 2022 | In autofile Audio File Library 0.3.6, there exists one memory leak vulnerability in printfileinfo, in printinfo.c, which... |
| CVE-2022-24582 | MEDIUM | 5.4 | 0.5% | Feb 24, 2022 | Accounting Journal Management 1.0 is vulnerable to XSS-PHPSESSID-Hijacking. The parameter manage_user from User lists is... |
| CVE-2022-24566 | MEDIUM | 5.4 | 0.6% | Feb 24, 2022 | In Checkmk <=2.0.0p19 fixed in 2.0.0p20 and Checkmk <=1.6.0p27 fixed in 1.6.0p28, the title of a Predefined condition is... |
| CVE-2022-24565 | MEDIUM | 5.4 | 0.6% | Feb 24, 2022 | Checkmk <=2.0.0p19 Fixed in 2.0.0p20 and Checkmk <=1.6.0p27 Fixed in 1.6.0p28 are affected by a Cross Site Scripting (XS... |
| CVE-2022-24435 | MEDIUM | 6.1 | 0.9% | Feb 24, 2022 | Cross-site scripting vulnerability in phpUploader v1.2 and earlier allows a remote unauthenticated attacker to inject an... |
| CVE-2022-24374 | MEDIUM | 6.1 | 0.9% | Feb 24, 2022 | Cross-site scripting vulnerability in a-blog cms Ver.2.8.x series versions prior to Ver.2.8.75, Ver.2.9.x series version... |
| CVE-2022-23916 | MEDIUM | 6.1 | 0.8% | Feb 24, 2022 | Cross-site scripting vulnerability in a-blog cms Ver.2.8.x series versions prior to Ver.2.8.75, Ver.2.9.x series version... |
| CVE-2022-23810 | MEDIUM | 6.5 | 1.1% | Feb 24, 2022 | Template injection (Improper Neutralization of Special Elements Used in a Template Engine) vulnerability in a-blog cms V... |
| CVE-2022-21179 | MEDIUM | 4.3 | 0.5% | Feb 24, 2022 | Cross-site request forgery (CSRF) vulnerability in EC-CUBE plugin 'Mail Magazine Management Plugin' ver4.0.0 to 4.1.1 (f... |
| CVE-2022-0695 | MEDIUM | 5.5 | 0.9% | Feb 24, 2022 | Denial of Service in GitHub repository radareorg/radare2 prior to 5.6.4. |
| CVE-2022-23655 | MEDIUM | 5.3 | 0.6% | Feb 24, 2022 | Octobercms is a self-hosted CMS platform based on the Laravel PHP Framework. Affected versions of OctoberCMS did not val... |
| CVE-2022-23653 | MEDIUM | 4.7 | 0.2% | Feb 23, 2022 | B2 Command Line Tool is the official command line tool for the backblaze cloud storage service. Linux and Mac releases o... |
| CVE-2022-23651 | MEDIUM | 4.7 | 0.2% | Feb 23, 2022 | b2-sdk-python is a python library to access cloud storage provided by backblaze. Linux and Mac releases of the SDK versi... |
| CVE-2022-22333 | MEDIUM | 6.5 | 0.6% | Feb 23, 2022 | IBM Sterling Secure Proxy 6.0.3.0, 6.0.2.0, and 3.4.3.2 and IBM Sterling External Authentication Server are vulnerable a... |
| CVE-2022-0731 | MEDIUM | 6.5 | 1.0% | Feb 23, 2022 | Improper Access Control (IDOR) in GitHub repository dolibarr/dolibarr prior to 16.0. |
| CVE-2022-20625 | MEDIUM | 4.3 | 3.4% | Feb 23, 2022 | A vulnerability in the Cisco Discovery Protocol service of Cisco FXOS Software and Cisco NX-OS Software could allow an u... |
| CVE-2022-0476 | MEDIUM | 5.5 | 1.0% | Feb 23, 2022 | Denial of Service in GitHub repository radareorg/radare2 prior to 5.6.4. |
| CVE-2022-0727 | MEDIUM | 5.4 | 0.7% | Feb 23, 2022 | Improper Access Control in GitHub repository chocobozzz/peertube prior to 4.1.0. |
| CVE-2022-0726 | MEDIUM | 5.4 | 0.7% | Feb 23, 2022 | Missing Authorization in GitHub repository chocobozzz/peertube prior to 4.1.0. |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now