2022 CVE Vulnerabilities
27,538 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-36097 | MEDIUM | 6.1 | 57.4% | Sep 8, 2022 | XWiki Platform Attachment UI provides a macro to easily upload and select attachments for XWiki Platform, a generic wiki... |
| CVE-2022-36096 | CRITICAL | 9 | 59.5% | Sep 8, 2022 | The XWiki Platform Index UI is an Index of all pages, attachments, orphans and deleted pages and attachments for XWiki P... |
| CVE-2022-36095 | MEDIUM | 4.3 | 0.3% | Sep 8, 2022 | XWiki Platform is a generic wiki platform. Prior to versions 13.10.5 and 14.3, it is possible to perform a Cross-Site Re... |
| CVE-2022-36094 | CRITICAL | 9 | 64.1% | Sep 8, 2022 | XWiki Platform Web Parent POM contains Web resources for the XWiki platform, a generic wiki platform. Starting with vers... |
| CVE-2022-3167 | HIGH | 8.8 | 0.9% | Sep 8, 2022 | Improper Restriction of Rendered UI Layers or Frames in GitHub repository ikus060/rdiffweb prior to 2.4.1. |
| CVE-2022-38258 | HIGH | 8.1 | 1.1% | Sep 8, 2022 | A local file inclusion (LFI) vulnerability in D-Link DIR 819 v1.06 allows attackers to cause a Denial of Service (DoS) o... |
| CVE-2022-38256 | MEDIUM | 5.4 | 0.4% | Sep 8, 2022 | TastyIgniter v3.5.0 was discovered to contain a cross-site scripting (XSS) vulnerability which allows attackers to execu... |
| CVE-2022-36093 | HIGH | 7.1 | 0.7% | Sep 8, 2022 | XWiki Platform Web Templates are templates for XWiki Platform, a generic wiki platform. By passing a template of the dis... |
| CVE-2022-36092 | HIGH | 7.5 | 0.8% | Sep 8, 2022 | XWiki Platform Old Core is a core package for XWiki Platform, a generic wiki platform. Prior to versions 14.2 and 13.10.... |
| CVE-2022-38260 | HIGH | 7.2 | 0.8% | Sep 8, 2022 | Interview Management System v1.0 was discovered to contain a SQL injection vulnerability via the component /interview/de... |
| CVE-2022-38255 | HIGH | 7.2 | 0.8% | Sep 8, 2022 | Interview Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /interv... |
| CVE-2022-37857 | HIGH | 7.5 | 0.4% | Sep 8, 2022 | bilde2910 Hauk v1.6.1 requires a hardcoded password which by default is blank. This hardcoded password is hashed but sto... |
| CVE-2022-37164 | CRITICAL | 9.8 | 0.6% | Sep 8, 2022 | Inoda OnTrack v3.4 employs a weak password policy which allows attackers to potentially gain unauthorized access to the ... |
| CVE-2022-37163 | CRITICAL | 9.8 | 0.5% | Sep 8, 2022 | Bminusl IHateToBudget v1.5.7 employs a weak password policy which allows attackers to potentially gain unauthorized acce... |
| CVE-2022-36091 | HIGH | 7.5 | 0.7% | Sep 8, 2022 | XWiki Platform Web Templates are templates for XWiki Platform, a generic wiki platform. Through the suggestion feature, ... |
| CVE-2022-27969 | MEDIUM | 5.3 | 0.6% | Sep 8, 2022 | Cynet 360 Web Portal before v4.5 was discovered to allow attackers to access a list of decoy users via a crafted GET req... |
| CVE-2022-27968 | MEDIUM | 5.3 | 0.6% | Sep 8, 2022 | Cynet 360 Web Portal before v4.5 was discovered to allow attackers to access a list of monitored files and profiles via ... |
| CVE-2022-27967 | MEDIUM | 5.3 | 0.6% | Sep 8, 2022 | Cynet 360 Web Portal before v4.5 was discovered to allow attackers to access a list of excluded files and profiles via a... |
| CVE-2022-22314 | LOW | 3.3 | 0.2% | Sep 8, 2022 | IBM Planning Analytics Local 2.0 allows web pages to be stored locally which can be read by another user on the system. ... |
| CVE-2022-3153 | MEDIUM | 5.5 | 0.5% | Sep 8, 2022 | NULL Pointer Dereference in GitHub repository vim/vim prior to 9.0.0404. |
| CVE-2022-36090 | HIGH | 8.1 | 0.9% | Sep 8, 2022 | XWiki Platform Old Core is a core package for XWiki Platform, a generic wiki platform. Prior to versions 13.1.0.5 and 14... |
| CVE-2022-36085 | CRITICAL | 9.8 | 1.2% | Sep 8, 2022 | Open Policy Agent (OPA) is an open source, general-purpose policy engine. The Rego compiler provides a (deprecated) `Wit... |
| CVE-2022-36736 | MEDIUM | 6.1 | 0.6% | Sep 8, 2022 | Jitsi-2.10.5550 was discovered to contain a vulnerability in its web UI which allows attackers to perform a clickjacking... |
| CVE-2022-20923 | CRITICAL | 9.8 | 0.8% | Sep 8, 2022 | A vulnerability in the IPSec VPN Server authentication functionality of Cisco Small Business RV110W, RV130, RV130W, and ... |
| CVE-2022-20863 | MEDIUM | 5.3 | 0.8% | Sep 8, 2022 | A vulnerability in the messaging interface of Cisco Webex App, formerly Webex Teams, could allow an unauthenticated, rem... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now