2022 CVE Vulnerabilities
27,538 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-2885 | MEDIUM | 4.8 | 0.4% | Aug 21, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0. |
| CVE-2022-30036 | HIGH | 8.8 | 0.8% | Aug 21, 2022 | MA Lighting grandMA2 Light has a password of root for the root account. NOTE: The vendor's position is that the product ... |
| CVE-2022-2921 | HIGH | 8.8 | 1.1% | Aug 21, 2022 | Exposure of Private Personal Information to an Unauthorized Actor in GitHub repository notrinos/notrinoserp prior to v0.... |
| CVE-2022-38493 | HIGH | 7.5 | 0.3% | Aug 20, 2022 | Rhonabwy 0.9.99 through 1.1.x before 1.1.7 doesn't check the RSA private key length before RSA-OAEP decryption. This all... |
| CVE-2022-2909 | HIGH | 8.8 | 0.7% | Aug 20, 2022 | A vulnerability was found in SourceCodester Simple and Nice Shopping Cart Script. It has been declared as critical. Affe... |
| CVE-2022-36030 | CRITICAL | 9.8 | 0.7% | Aug 20, 2022 | Project-nexus is a general-purpose blog website framework. Affected versions are subject to SQL injection due to a lack ... |
| CVE-2022-35692 | MEDIUM | 5.3 | 0.7% | Aug 19, 2022 | Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by an Improp... |
| CVE-2022-35554 | MEDIUM | 6.1 | 0.6% | Aug 19, 2022 | Multiple reflected XSS vulnerabilities occur when handling error message of BPC SmartVista version 3.28.0 allowing an at... |
| CVE-2022-2793 | HIGH | 7.8 | 0.1% | Aug 19, 2022 | Emerson Electric's Proficy Machine Edition Version 9.00 and prior is vulenrable to CWE-353 Missing Support for Integrity... |
| CVE-2022-2792 | HIGH | 7.5 | 0.4% | Aug 19, 2022 | Emerson Electric's Proficy Machine Edition Version 9.00 and prior is vulenrable to CWE-284 Improper Access Control, and ... |
| CVE-2022-2790 | MEDIUM | 5.9 | 0.1% | Aug 19, 2022 | Emerson Electric's Proficy Machine Edition Version 9.00 and prior is vulenrable to CWE-347 Improper Verification of Cryp... |
| CVE-2022-2789 | MEDIUM | 5.5 | 0.1% | Aug 19, 2022 | Emerson Electric's Proficy Machine Edition Version 9.00 and prior is vulnerable to CWE-345 Insufficient Verification of ... |
| CVE-2022-36233 | MEDIUM | 5.5 | 0.3% | Aug 19, 2022 | Tenda AC9 V15.03.2.13 is vulnerable to Buffer Overflow via httpd, form_fast_setting_wifi_set. httpd. |
| CVE-2022-36171 | HIGH | 8.1 | 0.6% | Aug 19, 2022 | MapGIS IGServer 10.5.6.11 is vulnerable to Arbitrary file deletion. |
| CVE-2022-36157 | HIGH | 8.8 | 1.2% | Aug 19, 2022 | XXL-JOB all versions as of 11 July 2022 are vulnerable to Insecure Permissions resulting in the ability to execute admin... |
| CVE-2022-37175 | CRITICAL | 9.8 | 0.9% | Aug 19, 2022 | Tenda ac15 firmware V15.03.05.18 httpd server has stack buffer overflow in /goform/formWifiBasicSet. |
| CVE-2022-36170 | HIGH | 8.8 | 0.8% | Aug 19, 2022 | MapGIS 10.5 Pro IGServer has hardcoded credentials in the front-end and can lead to escalation of privileges and arbitra... |
| CVE-2022-36031 | MEDIUM | 6.5 | 0.8% | Aug 19, 2022 | Directus is a free and open-source data platform for headless content management. The Directus process can be aborted by... |
| CVE-2022-36009 | HIGH | 8.8 | 0.7% | Aug 19, 2022 | gomatrixserverlib is a Go library for matrix protocol federation. Dendrite is a Matrix homeserver written in Go, an alte... |
| CVE-2022-36008 | MEDIUM | 6.5 | 0.9% | Aug 19, 2022 | Frontier is Substrate's Ethereum compatibility layer. A security issue was discovered affecting parsing of the RPC resul... |
| CVE-2022-2788 | HIGH | 7.3 | 0.2% | Aug 19, 2022 | Emerson Electric's Proficy Machine Edition Version 9.80 and prior is vulnerable to CWE-29 Path Traversal: '\..\Filename'... |
| CVE-2022-23460 | HIGH | 7.5 | 0.6% | Aug 19, 2022 | Jsonxx or Json++ is a JSON parser, writer and reader written in C++. In affected versions of jsonxx json parsing may lea... |
| CVE-2022-23459 | CRITICAL | 9.8 | 0.8% | Aug 19, 2022 | Jsonxx or Json++ is a JSON parser, writer and reader written in C++. In affected versions of jsonxx use of the Value cla... |
| CVE-2022-22489 | CRITICAL | 9.1 | 1.4% | Aug 19, 2022 | IBM MQ 8.0, (9.0, 9.1, 9.2 LTS), and (9.1 and 9.2 CD) are vulnerable to an XML External Entity Injection (XXE) attack wh... |
| CVE-2022-0542 | MEDIUM | 6.1 | 0.8% | Aug 19, 2022 | Cross-site Scripting (XSS) - DOM in GitHub repository chatwoot/chatwoot prior to 2.7.0. |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now