2022 CVE Vulnerabilities
27,538 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-40157 | — | — | — | Oct 6, 2022 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2022-3398 | CRITICAL | 9.8 | 0.6% | Oct 6, 2022 | OMRON CX-Programmer 9.78 and prior is vulnerable to an Out-of-Bounds Write, which may allow an attacker to execute arbit... |
| CVE-2022-3397 | CRITICAL | 9.8 | 0.6% | Oct 6, 2022 | OMRON CX-Programmer 9.78 and prior is vulnerable to an Out-of-Bounds Write, which may allow an attacker to execute arbit... |
| CVE-2022-3396 | CRITICAL | 9.8 | 0.6% | Oct 6, 2022 | OMRON CX-Programmer 9.78 and prior is vulnerable to an Out-of-Bounds Write, which may allow an attacker to execute arbit... |
| CVE-2022-3389 | HIGH | 7.5 | 1.0% | Oct 6, 2022 | Path Traversal in GitHub repository ikus060/rdiffweb prior to 2.4.10. |
| CVE-2022-3376 | MEDIUM | 5.3 | 0.7% | Oct 6, 2022 | Weak Password Requirements in GitHub repository ikus060/rdiffweb prior to 2.5.0a4. |
| CVE-2022-3273 | CRITICAL | 9.8 | 0.4% | Oct 6, 2022 | Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.5.0a4. |
| CVE-2022-3002 | MEDIUM | 5.4 | 0.5% | Oct 6, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0. |
| CVE-2022-39988 | MEDIUM | 5.4 | 0.6% | Oct 6, 2022 | A cross-site scripting (XSS) vulnerability in Centreon 22.04.0 allows attackers to execute arbitrary web script or HTML ... |
| CVE-2022-39280 | HIGH | 7.5 | 1.0% | Oct 6, 2022 | dparse is a parser for Python dependency files. dparse in versions before 0.5.2 contain a regular expression that is vul... |
| CVE-2022-39275 | MEDIUM | 4.3 | 0.5% | Oct 6, 2022 | Saleor is a headless, GraphQL commerce platform. In affected versions some GraphQL mutations were not properly checking ... |
| CVE-2022-39274 | CRITICAL | 9.8 | 1.4% | Oct 6, 2022 | LoRaMac-node is a reference implementation and documentation of a LoRa network node. Versions of LoRaMac-node prior to 4... |
| CVE-2022-39273 | HIGH | 7.5 | 0.7% | Oct 6, 2022 | FlyteAdmin is the control plane for the data processing platform Flyte. Users who enable the default Flyte’s authorizati... |
| CVE-2022-39270 | MEDIUM | 5.4 | 0.4% | Oct 6, 2022 | DiscoTOC is a Discourse theme component that generates a table of contents for topics. Users that can create topics in T... |
| CVE-2022-39269 | CRITICAL | 9.1 | 0.5% | Oct 6, 2022 | PJSIP is a free and open source multimedia communication library written in C. When processing certain packets, PJSIP ma... |
| CVE-2022-39265 | HIGH | 7.2 | 2.2% | Oct 6, 2022 | MyBB is a free and open source forum software. The _Mail Settings_ → Additional Parameters for PHP's mail() function mai... |
| CVE-2022-39244 | CRITICAL | 9.8 | 1.1% | Oct 6, 2022 | PJSIP is a free and open source multimedia communication library written in C. In versions of PJSIP prior to 2.13 the PJ... |
| CVE-2022-39237 | CRITICAL | 9.8 | 0.5% | Oct 6, 2022 | syslabs/sif is the Singularity Image Format (SIF) reference implementation. In versions prior to 2.8.1the `github.com/sy... |
| CVE-2022-39222 | MEDIUM | 6.5 | 1.1% | Oct 6, 2022 | Dex is an identity service that uses OpenID Connect to drive authentication for other apps. Dex instances with public cl... |
| CVE-2022-38709 | MEDIUM | 6.1 | 0.4% | Oct 6, 2022 | IBM Robotic Process Automation 21.0.1, 21.0.2, and 21.0.3 for Cloud Pak is vulnerable to cross-site scripting. This vuln... |
| CVE-2022-37888 | CRITICAL | 9.8 | 1.5% | Oct 6, 2022 | There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code... |
| CVE-2022-36774 | MEDIUM | 5.3 | 0.3% | Oct 6, 2022 | IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 is vulnerable to man in the middle attacks through manipulatio... |
| CVE-2022-32172 | — | — | 0.6% | Oct 6, 2022 | In Zinc, versions v0.1.9 through v0.3.1 are vulnerable to Stored Cross-Site Scripting when using the delete template fun... |
| CVE-2022-32171 | — | — | 0.6% | Oct 6, 2022 | In Zinc, versions v0.1.9 through v0.3.1 are vulnerable to Stored Cross-Site Scripting when using the delete user functio... |
| CVE-2022-31252 | MEDIUM | 4.4 | 0.1% | Oct 6, 2022 | A Incorrect Authorization vulnerability in chkstat of SUSE Linux Enterprise Server 12-SP5; openSUSE Leap 15.3, openSUSE ... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now