2022 CVE Vulnerabilities
27,538 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-36254 | MEDIUM | 5.4 | 0.6% | Sep 12, 2022 | Multiple persistent cross-site scripting (XSS) vulnerabilities in index.php in tramyardg Hotel Management System 1.0 all... |
| CVE-2022-34110 | MEDIUM | 5.5 | 0.3% | Sep 12, 2022 | An issue in Micro-Star International MSI Feature Navigator v1.0.1808.0901 allows attackers to download arbitrary files r... |
| CVE-2022-34109 | HIGH | 7.1 | 0.3% | Sep 12, 2022 | An issue in Micro-Star International MSI Feature Navigator v1.0.1808.0901 allows attackers to write arbitrary files to t... |
| CVE-2022-34108 | HIGH | 7.1 | 0.3% | Sep 12, 2022 | An issue in the Feature Navigator of Micro-Star International MSI Feature Nagivator v1.0.1808.0901 allows attackers to c... |
| CVE-2022-38972 | MEDIUM | 6.1 | 0.7% | Sep 12, 2022 | Cross-site scripting vulnerability in Movable Type plugin A-Form versions prior to 4.1.1 (for Movable Type 7 Series) and... |
| CVE-2022-37796 | MEDIUM | 5.4 | 0.4% | Sep 12, 2022 | In Simple Online Book Store System 1.0 in /admin_book.php the Title, Author, and Description parameters are vulnerable t... |
| CVE-2022-37794 | CRITICAL | 9.8 | 0.9% | Sep 12, 2022 | In Library Management System 1.0 the /card/in-card.php file id_no parameters are vulnerable to SQL injection. |
| CVE-2022-40325 | MEDIUM | 6.1 | 0.4% | Sep 11, 2022 | SysAid Help Desk before 22.1.65 allows XSS via the Asset Dashboard, aka FR# 67262. |
| CVE-2022-40324 | MEDIUM | 6.1 | 0.4% | Sep 11, 2022 | SysAid Help Desk before 22.1.65 allows XSS via the Linked SRs field, aka FR# 67258. |
| CVE-2022-40323 | MEDIUM | 6.1 | 0.4% | Sep 11, 2022 | SysAid Help Desk before 22.1.65 allows XSS in the Password Services module, aka FR# 67241. |
| CVE-2022-40322 | MEDIUM | 6.1 | 0.4% | Sep 11, 2022 | SysAid Help Desk before 22.1.65 allows XSS, aka FR# 66542 and 65579. |
| CVE-2022-26049 | HIGH | 8.8 | 1.8% | Sep 11, 2022 | This affects the package com.diffplug.gradle:goomph before 3.37.2. It allows a malicious zip file to potentially break o... |
| CVE-2022-25295 | MEDIUM | 5.4 | 0.5% | Sep 11, 2022 | This affects the package github.com/gophish/gophish before 0.12.0. The Open Redirect vulnerability exists in the next qu... |
| CVE-2022-39135 | CRITICAL | 9.8 | 1.9% | Sep 11, 2022 | Apache Calcite 1.22.0 introduced the SQL operators EXISTS_NODE, EXTRACT_XML, XML_TRANSFORM and EXTRACT_VALUE do not rest... |
| CVE-2022-38266 | MEDIUM | 6.5 | 1.1% | Sep 9, 2022 | An issue in the Leptonica linked library (v1.79.0) allows attackers to cause an arithmetic exception leading to a Denial... |
| CVE-2022-40320 | HIGH | 8.8 | 1.1% | Sep 9, 2022 | cfg_tilde_expand in confuse.c in libConfuse 3.3 has a heap-based buffer over-read. |
| CVE-2022-36087 | MEDIUM | 6.5 | 1.3% | Sep 9, 2022 | OAuthLib is an implementation of the OAuth request-signing logic for Python 3.6+. In OAuthLib versions 3.1.1 until 3.2.1... |
| CVE-2022-38638 | CRITICAL | 9.1 | 1.0% | Sep 9, 2022 | Casdoor v1.97.3 was discovered to contain an arbitrary file write vulnerability via the fullFilePath parameter at /api/u... |
| CVE-2022-36110 | HIGH | 8.8 | 0.7% | Sep 9, 2022 | Netmaker makes networks with WireGuard. Prior to version 0.15.1, Improper Authorization functions lead to non-privileged... |
| CVE-2022-38639 | MEDIUM | 5.4 | 0.4% | Sep 9, 2022 | A cross-site scripting (XSS) vulnerability in Markdown-Nice v1.8.22 allows attackers to execute arbitrary web scripts or... |
| CVE-2022-31006 | HIGH | 7.5 | 0.9% | Sep 9, 2022 | indy-node is the server portion of Hyperledger Indy, a distributed ledger purpose-built for decentralized identity. In v... |
| CVE-2022-3133 | HIGH | 7.8 | 1.3% | Sep 9, 2022 | OS Command Injection in GitHub repository jgraph/drawio prior to 20.3.0. |
| CVE-2022-36109 | MEDIUM | 6.3 | 0.8% | Sep 9, 2022 | Moby is an open-source project created by Docker to enable software containerization. A bug was found in Moby (Docker En... |
| CVE-2022-40317 | MEDIUM | 5.4 | 0.9% | Sep 9, 2022 | OpenKM 6.3.11 allows stored XSS related to the javascript: substring in an A element. |
| CVE-2022-39810 | MEDIUM | 6.1 | 57.3% | Sep 9, 2022 | An issue was discovered in WSO2 Enterprise Integrator 6.4.0. A Reflected Cross-Site Scripting (XSS) vulnerability has be... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now