2022 CVE Vulnerabilities
27,531 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-39326 | HIGH | 8.8 | 1.2% | Oct 25, 2022 | kartverket/github-workflows are shared reusable workflows for GitHub Actions. Prior to version 2.7.5, all users of the `... |
| CVE-2022-39322 | CRITICAL | 9.8 | 1.1% | Oct 25, 2022 | @keystone-6/core is a core package for Keystone 6, a content management system for Node.js. Starting with version 2.2.0 ... |
| CVE-2022-39321 | CRITICAL | 9.9 | 1.5% | Oct 25, 2022 | GitHub Actions Runner is the application that runs a job from a GitHub Actions workflow. The actions runner invokes the ... |
| CVE-2022-39315 | MEDIUM | 5.3 | 0.6% | Oct 25, 2022 | Kirby is a Content Management System. Prior to versions 3.5.8.2, 3.6.6.2, 3.7.5.1, and 3.8.1, a user enumeration vulnera... |
| CVE-2022-39312 | CRITICAL | 9.8 | 1.5% | Oct 25, 2022 | Dataease is an open source data visualization analysis tool. Dataease prior to 1.15.2 has a deserialization vulnerabilit... |
| CVE-2022-38870 | HIGH | 7.5 | 2.9% | Oct 25, 2022 | Free5gc v3.2.1 is vulnerable to Information disclosure. |
| CVE-2022-38580 | CRITICAL | 9.8 | 11.0% | Oct 25, 2022 | Zalando Skipper v0.13.236 is vulnerable to Server-Side Request Forgery (SSRF). |
| CVE-2022-38436 | HIGH | 7.8 | 0.5% | Oct 25, 2022 | Adobe Illustrator versions 26.4 (and earlier) and 25.4.7 (and earlier) are affected by an out-of-bounds read vulnerabili... |
| CVE-2022-38435 | HIGH | 7.8 | 0.3% | Oct 25, 2022 | Adobe Illustrator versions 26.4 (and earlier) and 25.4.7 (and earlier) are affected by an Improper Input Validation vuln... |
| CVE-2022-38200 | MEDIUM | 6.1 | 0.3% | Oct 25, 2022 | A cross site scripting vulnerability exists in some map service configurations of ArcGIS Server versions 10.8.1 and 10.7... |
| CVE-2022-38199 | MEDIUM | 6.1 | 0.3% | Oct 25, 2022 | A remote file download issue can occur in some capabilities of Esri ArcGIS Server web services that may in some edge cas... |
| CVE-2022-38198 | MEDIUM | 6.1 | 0.5% | Oct 25, 2022 | There is a reflected cross site scripting issue in the Esri ArcGIS Server services directory versions 10.9.1 and below t... |
| CVE-2022-38197 | MEDIUM | 6.1 | 0.5% | Oct 25, 2022 | Esri ArcGIS Server versions 10.9.1 and below have an unvalidated redirect issue that may allow a remote, unauthenticated... |
| CVE-2022-38196 | HIGH | 8.1 | 1.0% | Oct 25, 2022 | Esri ArcGIS Server versions 10.9.1 and prior have a path traversal vulnerability that may result in a denial of service ... |
| CVE-2022-38195 | MEDIUM | 6.1 | 0.4% | Oct 25, 2022 | There is as reflected cross site scripting issue in Esri ArcGIS Server versions 10.9.1 and below which may allow a remot... |
| CVE-2022-36783 | MEDIUM | 5.4 | 0.4% | Oct 25, 2022 | AlgoSec – FireFlow Reflected Cross-Site-Scripting (RXSS) A malicious user injects JavaScript code into a parameter calle... |
| CVE-2022-35887 | HIGH | 8.8 | 1.3% | Oct 25, 2022 | Four format string injection vulnerabilities exist in the web interface /action/wirelessConnect functionality of Abode S... |
| CVE-2022-35886 | HIGH | 8.8 | 1.2% | Oct 25, 2022 | Four format string injection vulnerabilities exist in the web interface /action/wirelessConnect functionality of Abode S... |
| CVE-2022-35885 | HIGH | 8.8 | 1.2% | Oct 25, 2022 | Four format string injection vulnerabilities exist in the web interface /action/wirelessConnect functionality of Abode S... |
| CVE-2022-35884 | HIGH | 8.8 | 1.3% | Oct 25, 2022 | Four format string injection vulnerabilities exist in the web interface /action/wirelessConnect functionality of Abode S... |
| CVE-2022-35881 | HIGH | 8.8 | 0.8% | Oct 25, 2022 | Four format string injection vulnerabilities exist in the UPnP logging functionality of Abode Systems, Inc. iota All-In-... |
| CVE-2022-35880 | HIGH | 8.8 | 0.8% | Oct 25, 2022 | Four format string injection vulnerabilities exist in the UPnP logging functionality of Abode Systems, Inc. iota All-In-... |
| CVE-2022-35879 | HIGH | 8.8 | 0.8% | Oct 25, 2022 | Four format string injection vulnerabilities exist in the UPnP logging functionality of Abode Systems, Inc. iota All-In-... |
| CVE-2022-35878 | HIGH | 8.8 | 0.8% | Oct 25, 2022 | Four format string injection vulnerabilities exist in the UPnP logging functionality of Abode Systems, Inc. iota All-In-... |
| CVE-2022-35877 | CRITICAL | 9.8 | 0.9% | Oct 25, 2022 | Four format string injection vulnerabilities exist in the XCMD testWifiAP functionality of Abode Systems, Inc. iota All-... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now