2022 CVE Vulnerabilities
27,531 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-39365 | CRITICAL | 9.8 | 1.7% | Oct 27, 2022 | Pimcore is an open source data and experience management platform. Prior to version 10.5.9, the user controlled twig tem... |
| CVE-2022-39364 | MEDIUM | 6.5 | 0.5% | Oct 27, 2022 | Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform. In Nextcloud Server pri... |
| CVE-2022-42993 | MEDIUM | 5.4 | 0.6% | Oct 27, 2022 | Password Storage Application v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Setup pag... |
| CVE-2022-42991 | MEDIUM | 5.4 | 0.6% | Oct 27, 2022 | A stored cross-site scripting (XSS) vulnerability in Simple Online Public Access Catalog v1.0 allows attackers to execut... |
| CVE-2022-39330 | MEDIUM | 4.3 | 0.8% | Oct 27, 2022 | Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform. Nextcloud Server prior ... |
| CVE-2022-39329 | MEDIUM | 5.3 | 0.6% | Oct 27, 2022 | Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform. Nextcloud Server and Ne... |
| CVE-2022-38744 | HIGH | 7.5 | 1.1% | Oct 27, 2022 | An unauthenticated attacker with network access to a victim's Rockwell Automation FactoryTalk Alarm and Events service... |
| CVE-2022-3409 | HIGH | 7.5 | 0.6% | Oct 27, 2022 | A vulnerability in bmcweb of OpenBMC Project allows user to cause denial of service. This vulnerability was identified d... |
| CVE-2022-36182 | MEDIUM | 6.1 | 0.5% | Oct 27, 2022 | Hashicorp Boundary v0.8.0 is vulnerable to Clickjacking which allow for the interception of login credentials, re-direct... |
| CVE-2022-2809 | HIGH | 7.5 | 0.6% | Oct 27, 2022 | A vulnerability in bmcweb of OpenBMC Project allows user to cause denial of service. When fuzzing the multipart_parser c... |
| CVE-2022-42992 | MEDIUM | 5.4 | 0.6% | Oct 27, 2022 | Multiple stored cross-site scripting (XSS) vulnerabilities in Train Scheduler App v1.0 allow attackers to execute arbitr... |
| CVE-2022-3719 | — | — | — | Oct 27, 2022 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2022-3718 | — | — | — | Oct 27, 2022 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2022-3717 | — | — | — | Oct 27, 2022 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2022-3716 | MEDIUM | 5.4 | 0.3% | Oct 27, 2022 | A vulnerability classified as problematic was found in SourceCodester Online Medicine Ordering System 1.0. Affected by t... |
| CVE-2022-3714 | CRITICAL | 9.8 | 0.4% | Oct 27, 2022 | A vulnerability classified as critical has been found in SourceCodester Online Medicine Ordering System 1.0. Affected is... |
| CVE-2022-2782 | CRITICAL | 9.1 | 0.5% | Oct 27, 2022 | In affected versions of Octopus Server it is possible for a session token to be valid indefinitely due to improper valid... |
| CVE-2022-2508 | MEDIUM | 5.3 | 0.5% | Oct 27, 2022 | In affected versions of Octopus Server it is possible to reveal the existence of resources in a space that the user does... |
| CVE-2022-25918 | HIGH | 7.5 | 1.2% | Oct 27, 2022 | The package shescape from 1.5.10 and before 1.6.1 are vulnerable to Regular Expression Denial of Service (ReDoS) via the... |
| CVE-2022-40703 | MEDIUM | 6.1 | 0.3% | Oct 26, 2022 | CWE-302 Authentication Bypass by Assumed-Immutable Data in AliveCor Kardia App version 5.17.1-754993421 and prior on A... |
| CVE-2022-3363 | CRITICAL | 9.8 | 0.8% | Oct 26, 2022 | Business Logic Errors in GitHub repository ikus060/rdiffweb prior to 2.5.0a7. |
| CVE-2022-3705 | HIGH | 7.5 | 1.2% | Oct 26, 2022 | A vulnerability was found in vim and classified as problematic. Affected by this issue is the function qf_update_buffer ... |
| CVE-2022-3704 | MEDIUM | 5.4 | 0.7% | Oct 26, 2022 | A vulnerability classified as problematic has been found in Ruby on Rails. This affects an unknown part of the file acti... |
| CVE-2022-39355 | CRITICAL | 9.8 | 0.8% | Oct 26, 2022 | Discourse Patreon enables syncronization between Discourse Groups and Patreon rewards. On sites with Patreon login enabl... |
| CVE-2022-39348 | MEDIUM | 5.4 | 1.2% | Oct 26, 2022 | Twisted is an event-based framework for internet applications. Started with version 0.9.4, when the host header does not... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now