2022 CVE Vulnerabilities
27,528 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-23258 | MEDIUM | 4.3 | 1.6% | Jan 25, 2022 | Microsoft Edge for Android Spoofing Vulnerability |
| CVE-2022-23032 | MEDIUM | 5.3 | 0.4% | Jan 25, 2022 | In all versions before 7.2.1.4, when proxy settings are configured in the network access resource of a BIG-IP APM system... |
| CVE-2022-23031 | MEDIUM | 4.9 | 0.8% | Jan 25, 2022 | On BIG-IP FPS, ASM, and Advanced WAF versions 16.1.x before 16.1.1, 15.1.x before 15.1.4, and 14.1.x before 14.1.4.4, an... |
| CVE-2022-23030 | MEDIUM | 5.3 | 0.9% | Jan 25, 2022 | On version 16.1.x before 16.1.2, 15.1.x before 15.1.4.1, 14.1.x before 14.1.4.5, and all versions of 13.1.x, when the BI... |
| CVE-2022-23029 | MEDIUM | 5.3 | 0.7% | Jan 25, 2022 | On BIG-IP version 16.x before 16.1.0, 15.1.x before 15.1.4.1, 14.1.x before 14.1.4.4, and all versions of 13.1.x, 12.1.x... |
| CVE-2022-23028 | MEDIUM | 5.3 | 0.9% | Jan 25, 2022 | On BIG-IP AFM version 16.x before 16.1.0, 15.1.x before 15.1.5, 14.1.x before 14.1.4.5, and all versions of 13.1.x, when... |
| CVE-2022-23027 | MEDIUM | 5.3 | 0.9% | Jan 25, 2022 | On BIG-IP versions 15.1.x before 15.1.4, 14.1.x before 14.1.4.4, 13.1.x beginning in 13.1.3.6, 12.1.5.3-12.1.6, and 11.6... |
| CVE-2022-23026 | MEDIUM | 4.3 | 0.7% | Jan 25, 2022 | On BIG-IP ASM & Advanced WAF version 16.1.x before 16.1.2, 15.1.x before 15.1.4.1, 14.1.x before 14.1.4.5, and all versi... |
| CVE-2022-23023 | MEDIUM | 6.5 | 0.9% | Jan 25, 2022 | On BIG-IP version 16.1.x before 16.1.2.1, 15.1.x before 15.1.5, 14.1.x before 14.1.4.5, and all versions of 13.1.x and 1... |
| CVE-2022-23014 | MEDIUM | 6.5 | 0.8% | Jan 25, 2022 | On versions 16.1.x before 16.1.2 and 15.1.x before 15.1.4.1, when BIG-IP APM portal access is configured on a virtual se... |
| CVE-2022-23008 | MEDIUM | 5.4 | 0.5% | Jan 25, 2022 | On NGINX Controller API Management versions 3.18.0-3.19.0, an authenticated attacker with access to the "user" or "admin... |
| CVE-2022-0334 | MEDIUM | 4.3 | 0.7% | Jan 25, 2022 | A flaw was found in Moodle in versions 3.11 to 3.11.4, 3.10 to 3.10.8, 3.9 to 3.9.11 and earlier unsupported versions. I... |
| CVE-2022-23035 | MEDIUM | 4.6 | 0.4% | Jan 25, 2022 | Insufficient cleanup of passed-through device IRQs The management of IRQs associated with physical devices exposed to x8... |
| CVE-2022-23034 | MEDIUM | 5.5 | 0.3% | Jan 25, 2022 | A PV guest could DoS Xen while unmapping a grant To address XSA-380, reference counting was introduced for grant mapping... |
| CVE-2022-0268 | MEDIUM | 5.4 | 1.4% | Jan 25, 2022 | Cross-site Scripting (XSS) - Stored in Packagist getgrav/grav prior to 1.7.28. |
| CVE-2022-0338 | MEDIUM | 4.3 | 0.8% | Jan 25, 2022 | Insertion of Sensitive Information into Log File in Conda loguru prior to 0.5.3. |
| CVE-2022-22554 | MEDIUM | 5.5 | 0.2% | Jan 24, 2022 | Dell EMC System Update, version 1.9.2 and prior, contain an Unprotected Storage of Credentials vulnerability. A local at... |
| CVE-2022-21715 | MEDIUM | 6.1 | 1.0% | Jan 24, 2022 | CodeIgniter4 is the 4.x branch of CodeIgniter, a PHP full-stack web framework. A cross-site scripting (XSS) vulnerabilit... |
| CVE-2022-21710 | MEDIUM | 6.1 | 1.0% | Jan 24, 2022 | ShortDescription is a MediaWiki extension that provides local short description support. A cross-site scripting (XSS) vu... |
| CVE-2022-23437 | MEDIUM | 6.5 | 4.4% | Jan 24, 2022 | There's a vulnerability within the Apache Xerces Java (XercesJ) XML parser when handling specially crafted XML document ... |
| CVE-2022-22296 | MEDIUM | 5.3 | 1.0% | Jan 24, 2022 | Sourcecodester Hospital's Patient Records Management System 1.0 is vulnerable to Insecure Permissions via the id paramet... |
| CVE-2022-23857 | MEDIUM | 6.5 | 0.9% | Jan 24, 2022 | model/criteria/criteria.go in Navidrome before 0.47.5 is vulnerable to SQL injection attacks when processing crafted Sma... |
| CVE-2022-23856 | MEDIUM | 5.3 | 1.0% | Jan 24, 2022 | An issue was discovered in Saviynt Enterprise Identity Cloud (EIC) 5.5 SP2.x. An attacker can enumerate users by changin... |
| CVE-2022-23808 | MEDIUM | 6.1 | 8.0% | Jan 22, 2022 | An issue was discovered in phpMyAdmin 5.1 before 5.1.2. An attacker can inject malicious code into aspects of the setup ... |
| CVE-2022-23807 | MEDIUM | 4.3 | 0.7% | Jan 22, 2022 | An issue was discovered in phpMyAdmin 4.9 before 4.9.8 and 5.1 before 5.1.2. A valid user who is already authenticated t... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now