2022 CVE Vulnerabilities
27,528 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-23456 | MEDIUM | 5.5 | 0.3% | Jan 28, 2022 | Potential arbitrary file deletion vulnerability has been identified in HP Support Assistant software. |
| CVE-2022-22938 | MEDIUM | 6.5 | 0.4% | Jan 28, 2022 | VMware Workstation (16.x prior to 16.2.2) and Horizon Client for Windows (5.x prior to 5.5.3) contains a denial-of-servi... |
| CVE-2022-22791 | MEDIUM | 5.4 | 0.4% | Jan 28, 2022 | SYNEL - eharmony Authenticated Blind & Stored XSS. Inject JS code into the "comments" field could lead to potential stea... |
| CVE-2022-21199 | MEDIUM | 5.9 | 0.9% | Jan 28, 2022 | An information disclosure vulnerability exists due to the hardcoded TLS key of reolink RLC-410W v3.0.0.136_20121102. A s... |
| CVE-2022-22868 | MEDIUM | 4.8 | 0.9% | Jan 28, 2022 | Gibbon CMS v22.0.01 was discovered to contain a cross-site scripting (XSS) vulnerability, that allows attackers to injec... |
| CVE-2022-23863 | MEDIUM | 6.5 | 1.9% | Jan 28, 2022 | Zoho ManageEngine Desktop Central before 10.1.2137.10 allows an authenticated user to change any user's login password. |
| CVE-2022-24071 | MEDIUM | 4.3 | 0.7% | Jan 28, 2022 | A Built-in extension in Whale browser before 3.12.129.46 allows attackers to compromise the rendering process which coul... |
| CVE-2022-21720 | MEDIUM | 4.9 | 1.1% | Jan 28, 2022 | GLPI is a free asset and IT management software package. Prior to version 9.5.7, an entity administrator is capable of r... |
| CVE-2022-0394 | MEDIUM | 5.4 | 0.5% | Jan 28, 2022 | Cross-site Scripting (XSS) - Stored in Packagist remdex/livehelperchat prior to 3.93v. |
| CVE-2022-21719 | MEDIUM | 6.1 | 1.0% | Jan 28, 2022 | GLPI is a free asset and IT management software package. All GLPI versions prior to 9.5.7 are vulnerable to reflected cr... |
| CVE-2022-0348 | MEDIUM | 5.4 | 0.6% | Jan 27, 2022 | Cross-site Scripting (XSS) - Stored in Packagist pimcore/pimcore prior to 10.2. |
| CVE-2022-0372 | MEDIUM | 5.4 | 0.6% | Jan 27, 2022 | Cross-site Scripting (XSS) - Stored in Packagist bytefury/crater prior to 6.0.2. |
| CVE-2022-0387 | MEDIUM | 5.4 | 0.6% | Jan 27, 2022 | Cross-site Scripting (XSS) - Stored in Packagist remdex/livehelperchat prior to 3.93v. |
| CVE-2022-0370 | MEDIUM | 5.4 | 0.8% | Jan 27, 2022 | Cross-site Scripting (XSS) - Stored in Packagist remdex/livehelperchat prior to 3.93v. |
| CVE-2022-22852 | MEDIUM | 5.4 | 0.8% | Jan 26, 2022 | A Stored Cross Site Scripting (XSS) vulnerability exists in Sourcecodtester Hospital's Patient Records Management System... |
| CVE-2022-23993 | MEDIUM | 6.1 | 1.5% | Jan 26, 2022 | /usr/local/www/pkg.php in pfSense CE before 2.6.0 and pfSense Plus before 22.01 uses $_REQUEST['pkg_filter'] in a PHP ec... |
| CVE-2022-22850 | MEDIUM | 5.4 | 0.7% | Jan 26, 2022 | A Stored Cross Site Scripting (XSS) vulnerability exists in Sourcecodtester Hospital's Patient Records Management System... |
| CVE-2022-22851 | MEDIUM | 5.4 | 0.6% | Jan 26, 2022 | A Stored Cross Site Scripting (XSS) vulnerability exists in Sourcecodtester Hospital's Patient Records Management System... |
| CVE-2022-0379 | MEDIUM | 5.4 | 0.9% | Jan 26, 2022 | Cross-site Scripting (XSS) - Stored in Packagist microweber/microweber prior to 1.2.11. |
| CVE-2022-0378 | MEDIUM | 5.4 | 3.9% | Jan 26, 2022 | Cross-site Scripting (XSS) - Reflected in Packagist microweber/microweber prior to 1.2.11. |
| CVE-2022-0203 | MEDIUM | 5.3 | 1.2% | Jan 26, 2022 | Improper Access Control in GitHub repository crater-invoice/crater prior to 6.0.2. |
| CVE-2022-22932 | MEDIUM | 5.3 | 2.8% | Jan 26, 2022 | Apache Karaf obr:* commands and run goal on the karaf-maven-plugin have partial path traversal which allows to break out... |
| CVE-2022-0251 | MEDIUM | 5.4 | 0.7% | Jan 26, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.2.10. |
| CVE-2022-0375 | MEDIUM | 4.8 | 0.7% | Jan 26, 2022 | Cross-site Scripting (XSS) - Stored in Packagist remdex/livehelperchat prior to 3.93v. |
| CVE-2022-0374 | MEDIUM | 5.4 | 0.7% | Jan 26, 2022 | Cross-site Scripting (XSS) - Stored in Packagist remdex/livehelperchat prior to 3.93v. |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now