2022 CVE Vulnerabilities

27,531 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-39326HIGH8.8kartverket/github-workflows are shared reusable workflows for GitHub Actions. Prior to version 2.7.5, all users of the `...
CVE-2022-39322CRITICAL9.8@keystone-6/core is a core package for Keystone 6, a content management system for Node.js. Starting with version 2.2.0 ...
CVE-2022-39321CRITICAL9.9GitHub Actions Runner is the application that runs a job from a GitHub Actions workflow. The actions runner invokes the ...
CVE-2022-39315MEDIUM5.3Kirby is a Content Management System. Prior to versions 3.5.8.2, 3.6.6.2, 3.7.5.1, and 3.8.1, a user enumeration vulnera...
CVE-2022-39312CRITICAL9.8Dataease is an open source data visualization analysis tool. Dataease prior to 1.15.2 has a deserialization vulnerabilit...
CVE-2022-38870HIGH7.5Free5gc v3.2.1 is vulnerable to Information disclosure.
CVE-2022-38580CRITICAL9.8Zalando Skipper v0.13.236 is vulnerable to Server-Side Request Forgery (SSRF).
CVE-2022-38436HIGH7.8Adobe Illustrator versions 26.4 (and earlier) and 25.4.7 (and earlier) are affected by an out-of-bounds read vulnerabili...
CVE-2022-38435HIGH7.8Adobe Illustrator versions 26.4 (and earlier) and 25.4.7 (and earlier) are affected by an Improper Input Validation vuln...
CVE-2022-38200MEDIUM6.1A cross site scripting vulnerability exists in some map service configurations of ArcGIS Server versions 10.8.1 and 10.7...
CVE-2022-38199MEDIUM6.1A remote file download issue can occur in some capabilities of Esri ArcGIS Server web services that may in some edge cas...
CVE-2022-38198MEDIUM6.1There is a reflected cross site scripting issue in the Esri ArcGIS Server services directory versions 10.9.1 and below t...
CVE-2022-38197MEDIUM6.1Esri ArcGIS Server versions 10.9.1 and below have an unvalidated redirect issue that may allow a remote, unauthenticated...
CVE-2022-38196HIGH8.1Esri ArcGIS Server versions 10.9.1 and prior have a path traversal vulnerability that may result in a denial of service ...
CVE-2022-38195MEDIUM6.1There is as reflected cross site scripting issue in Esri ArcGIS Server versions 10.9.1 and below which may allow a remot...
CVE-2022-36783MEDIUM5.4AlgoSec – FireFlow Reflected Cross-Site-Scripting (RXSS) A malicious user injects JavaScript code into a parameter calle...
CVE-2022-35887HIGH8.8Four format string injection vulnerabilities exist in the web interface /action/wirelessConnect functionality of Abode S...
CVE-2022-35886HIGH8.8Four format string injection vulnerabilities exist in the web interface /action/wirelessConnect functionality of Abode S...
CVE-2022-35885HIGH8.8Four format string injection vulnerabilities exist in the web interface /action/wirelessConnect functionality of Abode S...
CVE-2022-35884HIGH8.8Four format string injection vulnerabilities exist in the web interface /action/wirelessConnect functionality of Abode S...
CVE-2022-35881HIGH8.8Four format string injection vulnerabilities exist in the UPnP logging functionality of Abode Systems, Inc. iota All-In-...
CVE-2022-35880HIGH8.8Four format string injection vulnerabilities exist in the UPnP logging functionality of Abode Systems, Inc. iota All-In-...
CVE-2022-35879HIGH8.8Four format string injection vulnerabilities exist in the UPnP logging functionality of Abode Systems, Inc. iota All-In-...
CVE-2022-35878HIGH8.8Four format string injection vulnerabilities exist in the UPnP logging functionality of Abode Systems, Inc. iota All-In-...
CVE-2022-35877CRITICAL9.8Four format string injection vulnerabilities exist in the XCMD testWifiAP functionality of Abode Systems, Inc. iota All-...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now