2022 CVE Vulnerabilities

27,528 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-44088CRITICAL9.8ESPCMS P8.21120101 was discovered to contain a remote code execution (RCE) vulnerability in the component INPUT_ISDESCRI...
CVE-2022-44087CRITICAL9.8ESPCMS P8.21120101 was discovered to contain a remote code execution (RCE) vulnerability in the component UPFILE_PIC_ZOO...
CVE-2022-43754MEDIUM5.4An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in spacewalk/Uyuni...
CVE-2022-43753MEDIUM4.3A Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in spacewalk/Uyuni of SUS...
CVE-2022-39038HIGH8.8Agentflow BPM enterprise management system has improper authentication. A remote attacker with general user privilege ca...
CVE-2022-39037HIGH7.5Agentflow BPM file download function has a path traversal vulnerability. An unauthenticated remote attacker can exploit ...
CVE-2022-39036CRITICAL9.8The file upload function of Agentflow BPM has insufficient filtering for special characters in URLs. An unauthenticated ...
CVE-2022-38122HIGH7.5UPSMON PRO transmits sensitive data in cleartext over HTTP protocol. An unauthenticated remote attacker can exploit this...
CVE-2022-38121MEDIUM6.5UPSMON PRO configuration file stores user password in plaintext under public user directory. A remote attacker with gene...
CVE-2022-38120MEDIUM6.5UPSMON PRO’s has a path traversal vulnerability. A remote attacker with general user privilege can exploit this vulnerab...
CVE-2022-38119CRITICAL9.8UPSMON Pro login function has insufficient authentication. An unauthenticated remote attacker can exploit this vulnerabi...
CVE-2022-31255MEDIUM4.3An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in spacewalk/Uyuni of SU...
CVE-2022-42787HIGH8.8Multiple W&T products of the Comserver Series use a small number space for allocating sessions ids. After login of an us...
CVE-2022-42786MEDIUM5.4Multiple W&T Products of the ComServer Series are prone to an XSS attack. An authenticated remote Attacker can execute a...
CVE-2022-45130MEDIUM6.5Plesk Obsidian allows a CSRF attack, e.g., via the /api/v2/cli/commands REST API to change an Admin password. NOTE: Obsi...
CVE-2022-45129HIGH7.5Payara before 2022-11-04, when deployed to the root context, allows attackers to visit META-INF and WEB-INF, a different...
CVE-2022-3867MEDIUM4.3HashiCorp Nomad and Nomad Enterprise 1.4.0 up to 1.4.1 event stream subscribers using a token with TTL receive updates u...
CVE-2022-3866MEDIUM4.3HashiCorp Nomad and Nomad Enterprise 1.4.0 up to 1.4.1 workload identity token can list non-sensitive metadata for paths...
CVE-2022-39398MEDIUM6.1tasklists is a tasklists plugin for GLPI (Kanban). Versions prior to 2.0.3 are vulnerable to Cross-site Scripting. Cross...
CVE-2022-39396CRITICAL9.8Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Versions prior t...
CVE-2022-3819MEDIUM4.3An improper authorization issue in GitLab CE/EE affecting all versions from 15.0 prior to 15.3.5, 15.4 prior to 15.4.4, ...
CVE-2022-3818MEDIUM5.3An uncontrolled resource consumption issue when parsing URLs in GitLab CE/EE affecting all versions prior to 15.3.5, 15....
CVE-2022-3793MEDIUM5.3An improper authorization issue in GitLab CE/EE affecting all versions from 14.4 prior to 15.3.5, 15.4 prior to 15.4.4, ...
CVE-2022-3726CRITICAL9Lack of sand-boxing of OpenAPI documents in GitLab CE/EE affecting all versions from 12.6 prior to 15.3.5, 15.4 prior to...
CVE-2022-3706MEDIUM4.3Improper authorization in GitLab CE/EE affecting all versions from 7.14 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 ...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now