2022 CVE Vulnerabilities
27,538 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-41473 | MEDIUM | 6.1 | 1.0% | Oct 13, 2022 | RPCMS v3.0.2 was discovered to contain a reflected cross-site scripting (XSS) vulnerability in the Search function. |
| CVE-2022-42889 | CRITICAL | 9.8 | 99.9% | Oct 13, 2022 | Apache Commons Text performs variable interpolation, allowing properties to be dynamically evaluated and expanded. The s... |
| CVE-2022-38902 | MEDIUM | 5.4 | 0.7% | Oct 13, 2022 | A Cross-site scripting (XSS) vulnerability in the Blog module - add new topic functionality in Liferay Digital Experienc... |
| CVE-2022-24697 | CRITICAL | 9.8 | 84.8% | Oct 13, 2022 | Kylin's cube designer function has a command injection vulnerability when overwriting system parameters in the configura... |
| CVE-2022-37208 | HIGH | 8.8 | 1.1% | Oct 13, 2022 | JFinal CMS 5.1.0 is vulnerable to SQL Injection. These interfaces do not use the same component, nor do they have filter... |
| CVE-2022-35081 | MEDIUM | 5.5 | 0.3% | Oct 13, 2022 | SWFTools commit 772e55a2 was discovered to contain a heap-buffer overflow via png_read_header at /src/png2swf.c. |
| CVE-2022-35080 | MEDIUM | 5.5 | 0.3% | Oct 13, 2022 | SWFTools commit 772e55a2 was discovered to contain a heap-buffer overflow via png_load at /lib/png.c. |
| CVE-2022-2828 | MEDIUM | 6.5 | 0.5% | Oct 13, 2022 | In affected versions of Octopus Server it is possible to reveal information about teams via the API due to an Insecure D... |
| CVE-2022-3473 | MEDIUM | 6.5 | 0.5% | Oct 13, 2022 | A vulnerability classified as critical has been found in SourceCodester Human Resource Management System. This affects a... |
| CVE-2022-3472 | MEDIUM | 4.9 | 0.5% | Oct 13, 2022 | A vulnerability was found in SourceCodester Human Resource Management System. It has been rated as critical. Affected by... |
| CVE-2022-3471 | MEDIUM | 4.9 | 0.5% | Oct 13, 2022 | A vulnerability was found in SourceCodester Human Resource Management System. It has been declared as critical. Affected... |
| CVE-2022-3470 | MEDIUM | 6.5 | 0.5% | Oct 13, 2022 | A vulnerability was found in SourceCodester Human Resource Management System. It has been classified as critical. Affect... |
| CVE-2022-42906 | HIGH | 7.8 | 0.4% | Oct 13, 2022 | powerline-gitstatus (aka Powerline Gitstatus) before 1.3.2 allows arbitrary code execution. git repositories can contain... |
| CVE-2022-42902 | HIGH | 8.8 | 1.3% | Oct 13, 2022 | In Linaro Automated Validation Architecture (LAVA) before 2022.10, there is dynamic code execution in lava_server/lavata... |
| CVE-2022-42901 | HIGH | 7.8 | 0.3% | Oct 13, 2022 | Bentley MicroStation and MicroStation-based applications may be affected by out-of-bounds and stack overflow issues when... |
| CVE-2022-42900 | HIGH | 7.8 | 0.3% | Oct 13, 2022 | Bentley MicroStation and MicroStation-based applications may be affected by out-of-bounds read issues when opening craft... |
| CVE-2022-42899 | HIGH | 7.8 | 0.6% | Oct 13, 2022 | Bentley MicroStation and MicroStation-based applications may be affected by out-of-bounds read and stack overflow issues... |
| CVE-2022-40187 | HIGH | 8 | 0.8% | Oct 13, 2022 | Foresight GC3 Launch Monitor 1.3.15.68 ships with a Target Communication Framework (TCF) service enabled. This service l... |
| CVE-2022-34020 | HIGH | 8.8 | 0.4% | Oct 13, 2022 | Cross Site Request Forgery (CSRF) vulnerability in ResIOT ResIOT IOT Platform + LoRaWAN Network Server through 4.1.10001... |
| CVE-2022-42897 | CRITICAL | 9.8 | 1.5% | Oct 13, 2022 | Array Networks AG/vxAG with ArrayOS AG before 9.4.0.469 allows unauthenticated command injection that leads to privilege... |
| CVE-2022-3171 | HIGH | 7.5 | 1.0% | Oct 12, 2022 | A parsing issue with binary data in protobuf-java core and lite versions prior to 3.21.7, 3.20.3, 3.19.6 and 3.16.3 can ... |
| CVE-2022-39298 | CRITICAL | 9.8 | 0.9% | Oct 12, 2022 | MelisFront is the engine that displays website hosted on Melis Platform. It deals with showing pages, plugins, URL rewri... |
| CVE-2022-39297 | CRITICAL | 9.8 | 0.9% | Oct 12, 2022 | MelisCms provides a full CMS for Melis Platform, including templating system, drag'n'drop of plugins, SEO and many admin... |
| CVE-2022-39283 | HIGH | 7.5 | 1.0% | Oct 12, 2022 | FreeRDP is a free remote desktop protocol library and clients. All FreeRDP based clients when using the `/video` command... |
| CVE-2022-39282 | HIGH | 7.5 | 0.8% | Oct 12, 2022 | FreeRDP is a free remote desktop protocol library and clients. FreeRDP based clients on unix systems using `/parallel` c... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now