2022 CVE Vulnerabilities
27,528 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-44088 | CRITICAL | 9.8 | 21.6% | Nov 10, 2022 | ESPCMS P8.21120101 was discovered to contain a remote code execution (RCE) vulnerability in the component INPUT_ISDESCRI... |
| CVE-2022-44087 | CRITICAL | 9.8 | 1.6% | Nov 10, 2022 | ESPCMS P8.21120101 was discovered to contain a remote code execution (RCE) vulnerability in the component UPFILE_PIC_ZOO... |
| CVE-2022-43754 | MEDIUM | 5.4 | 0.4% | Nov 10, 2022 | An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in spacewalk/Uyuni... |
| CVE-2022-43753 | MEDIUM | 4.3 | 0.7% | Nov 10, 2022 | A Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in spacewalk/Uyuni of SUS... |
| CVE-2022-39038 | HIGH | 8.8 | 0.9% | Nov 10, 2022 | Agentflow BPM enterprise management system has improper authentication. A remote attacker with general user privilege ca... |
| CVE-2022-39037 | HIGH | 7.5 | 1.2% | Nov 10, 2022 | Agentflow BPM file download function has a path traversal vulnerability. An unauthenticated remote attacker can exploit ... |
| CVE-2022-39036 | CRITICAL | 9.8 | 1.2% | Nov 10, 2022 | The file upload function of Agentflow BPM has insufficient filtering for special characters in URLs. An unauthenticated ... |
| CVE-2022-38122 | HIGH | 7.5 | 0.5% | Nov 10, 2022 | UPSMON PRO transmits sensitive data in cleartext over HTTP protocol. An unauthenticated remote attacker can exploit this... |
| CVE-2022-38121 | MEDIUM | 6.5 | 3.4% | Nov 10, 2022 | UPSMON PRO configuration file stores user password in plaintext under public user directory. A remote attacker with gene... |
| CVE-2022-38120 | MEDIUM | 6.5 | 5.6% | Nov 10, 2022 | UPSMON PRO’s has a path traversal vulnerability. A remote attacker with general user privilege can exploit this vulnerab... |
| CVE-2022-38119 | CRITICAL | 9.8 | 1.0% | Nov 10, 2022 | UPSMON Pro login function has insufficient authentication. An unauthenticated remote attacker can exploit this vulnerabi... |
| CVE-2022-31255 | MEDIUM | 4.3 | 0.7% | Nov 10, 2022 | An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in spacewalk/Uyuni of SU... |
| CVE-2022-42787 | HIGH | 8.8 | 0.7% | Nov 10, 2022 | Multiple W&T products of the Comserver Series use a small number space for allocating sessions ids. After login of an us... |
| CVE-2022-42786 | MEDIUM | 5.4 | 0.4% | Nov 10, 2022 | Multiple W&T Products of the ComServer Series are prone to an XSS attack. An authenticated remote Attacker can execute a... |
| CVE-2022-45130 | MEDIUM | 6.5 | 0.3% | Nov 10, 2022 | Plesk Obsidian allows a CSRF attack, e.g., via the /api/v2/cli/commands REST API to change an Admin password. NOTE: Obsi... |
| CVE-2022-45129 | HIGH | 7.5 | 1.3% | Nov 10, 2022 | Payara before 2022-11-04, when deployed to the root context, allows attackers to visit META-INF and WEB-INF, a different... |
| CVE-2022-3867 | MEDIUM | 4.3 | 0.5% | Nov 10, 2022 | HashiCorp Nomad and Nomad Enterprise 1.4.0 up to 1.4.1 event stream subscribers using a token with TTL receive updates u... |
| CVE-2022-3866 | MEDIUM | 4.3 | 0.5% | Nov 10, 2022 | HashiCorp Nomad and Nomad Enterprise 1.4.0 up to 1.4.1 workload identity token can list non-sensitive metadata for paths... |
| CVE-2022-39398 | MEDIUM | 6.1 | 0.5% | Nov 10, 2022 | tasklists is a tasklists plugin for GLPI (Kanban). Versions prior to 2.0.3 are vulnerable to Cross-site Scripting. Cross... |
| CVE-2022-39396 | CRITICAL | 9.8 | 41.2% | Nov 10, 2022 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Versions prior t... |
| CVE-2022-3819 | MEDIUM | 4.3 | 0.4% | Nov 10, 2022 | An improper authorization issue in GitLab CE/EE affecting all versions from 15.0 prior to 15.3.5, 15.4 prior to 15.4.4, ... |
| CVE-2022-3818 | MEDIUM | 5.3 | 0.7% | Nov 10, 2022 | An uncontrolled resource consumption issue when parsing URLs in GitLab CE/EE affecting all versions prior to 15.3.5, 15.... |
| CVE-2022-3793 | MEDIUM | 5.3 | 0.5% | Nov 10, 2022 | An improper authorization issue in GitLab CE/EE affecting all versions from 14.4 prior to 15.3.5, 15.4 prior to 15.4.4, ... |
| CVE-2022-3726 | CRITICAL | 9 | 0.8% | Nov 10, 2022 | Lack of sand-boxing of OpenAPI documents in GitLab CE/EE affecting all versions from 12.6 prior to 15.3.5, 15.4 prior to... |
| CVE-2022-3706 | MEDIUM | 4.3 | 0.5% | Nov 10, 2022 | Improper authorization in GitLab CE/EE affecting all versions from 7.14 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 ... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now