2022 CVE Vulnerabilities

27,538 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-40157Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2022-3398CRITICAL9.8OMRON CX-Programmer 9.78 and prior is vulnerable to an Out-of-Bounds Write, which may allow an attacker to execute arbit...
CVE-2022-3397CRITICAL9.8OMRON CX-Programmer 9.78 and prior is vulnerable to an Out-of-Bounds Write, which may allow an attacker to execute arbit...
CVE-2022-3396CRITICAL9.8OMRON CX-Programmer 9.78 and prior is vulnerable to an Out-of-Bounds Write, which may allow an attacker to execute arbit...
CVE-2022-3389HIGH7.5Path Traversal in GitHub repository ikus060/rdiffweb prior to 2.4.10.
CVE-2022-3376MEDIUM5.3Weak Password Requirements in GitHub repository ikus060/rdiffweb prior to 2.5.0a4.
CVE-2022-3273CRITICAL9.8Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.5.0a4.
CVE-2022-3002MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0.
CVE-2022-39988MEDIUM5.4A cross-site scripting (XSS) vulnerability in Centreon 22.04.0 allows attackers to execute arbitrary web script or HTML ...
CVE-2022-39280HIGH7.5dparse is a parser for Python dependency files. dparse in versions before 0.5.2 contain a regular expression that is vul...
CVE-2022-39275MEDIUM4.3Saleor is a headless, GraphQL commerce platform. In affected versions some GraphQL mutations were not properly checking ...
CVE-2022-39274CRITICAL9.8LoRaMac-node is a reference implementation and documentation of a LoRa network node. Versions of LoRaMac-node prior to 4...
CVE-2022-39273HIGH7.5FlyteAdmin is the control plane for the data processing platform Flyte. Users who enable the default Flyte’s authorizati...
CVE-2022-39270MEDIUM5.4DiscoTOC is a Discourse theme component that generates a table of contents for topics. Users that can create topics in T...
CVE-2022-39269CRITICAL9.1PJSIP is a free and open source multimedia communication library written in C. When processing certain packets, PJSIP ma...
CVE-2022-39265HIGH7.2MyBB is a free and open source forum software. The _Mail Settings_ → Additional Parameters for PHP's mail() function mai...
CVE-2022-39244CRITICAL9.8PJSIP is a free and open source multimedia communication library written in C. In versions of PJSIP prior to 2.13 the PJ...
CVE-2022-39237CRITICAL9.8syslabs/sif is the Singularity Image Format (SIF) reference implementation. In versions prior to 2.8.1the `github.com/sy...
CVE-2022-39222MEDIUM6.5Dex is an identity service that uses OpenID Connect to drive authentication for other apps. Dex instances with public cl...
CVE-2022-38709MEDIUM6.1IBM Robotic Process Automation 21.0.1, 21.0.2, and 21.0.3 for Cloud Pak is vulnerable to cross-site scripting. This vuln...
CVE-2022-37888CRITICAL9.8There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code...
CVE-2022-36774MEDIUM5.3IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 is vulnerable to man in the middle attacks through manipulatio...
CVE-2022-32172In Zinc, versions v0.1.9 through v0.3.1 are vulnerable to Stored Cross-Site Scripting when using the delete template fun...
CVE-2022-32171In Zinc, versions v0.1.9 through v0.3.1 are vulnerable to Stored Cross-Site Scripting when using the delete user functio...
CVE-2022-31252MEDIUM4.4A Incorrect Authorization vulnerability in chkstat of SUSE Linux Enterprise Server 12-SP5; openSUSE Leap 15.3, openSUSE ...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now