2022 CVE Vulnerabilities
27,543 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-2135 | HIGH | 7.5 | 10.1% | Jul 22, 2022 | The affected product is vulnerable to multiple SQL injections, which may allow an unauthorized attacker to disclose info... |
| CVE-2022-1655 | MEDIUM | 6.5 | 0.5% | Jul 22, 2022 | An Incorrect Permission Assignment for Critical Resource flaw was found in Horizon on Red Hat OpenStack. Horizon session... |
| CVE-2022-36131 | MEDIUM | 6.1 | 0.5% | Jul 22, 2022 | The Better PDF Exporter add-on 10.0.0 for Atlassian Jira is prone to stored XSS via a crafted description to the PDF Tem... |
| CVE-2022-31168 | HIGH | 8.8 | 0.6% | Jul 22, 2022 | Zulip is an open source team chat tool. Due to an incorrect authorization check in Zulip Server 5.4 and earlier, a membe... |
| CVE-2022-2209 | — | — | — | Jul 22, 2022 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. Reason: This CVE has been rejected as it was incorrectly assigned. Al... |
| CVE-2022-2327 | HIGH | 7.8 | 0.3% | Jul 22, 2022 | io_uring use work_flags to determine which identity need to grab from the calling process to make sure it is consistent ... |
| CVE-2022-31172 | HIGH | 7.5 | 0.4% | Jul 22, 2022 | OpenZeppelin Contracts is a library for smart contract development. Versions 4.1.0 until 4.7.1 are vulnerable to the Sig... |
| CVE-2022-31170 | HIGH | 7.5 | 0.6% | Jul 22, 2022 | OpenZeppelin Contracts is a library for smart contract development. Versions 4.0.0 until 4.7.1 are vulnerable to ERC165C... |
| CVE-2022-31169 | HIGH | 7.5 | 0.7% | Jul 22, 2022 | Wasmtime is a standalone runtime for WebAssembly. There is a bug in Wasmtime's code generator, Cranelift, for AArch64 ta... |
| CVE-2022-31164 | HIGH | 7.5 | 0.5% | Jul 22, 2022 | Tovy is a a staff management system for Roblox groups. A vulnerability in versions prior to 0.7.51 allows users to log i... |
| CVE-2022-31163 | HIGH | 8.1 | 1.8% | Jul 22, 2022 | TZInfo is a Ruby library that provides access to time zone data and allows times to be converted using time zone rules. ... |
| CVE-2022-31162 | HIGH | 7.5 | 0.7% | Jul 22, 2022 | Slack Morphism is an async client library for Rust. Prior to 0.41.0, it was possible for Slack OAuth client information ... |
| CVE-2022-2495 | MEDIUM | 4.8 | 0.5% | Jul 22, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 1.2.21. |
| CVE-2022-2494 | MEDIUM | 5.4 | 0.5% | Jul 22, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository openemr/openemr prior to 7.0.0. |
| CVE-2022-2493 | HIGH | 8.1 | 0.9% | Jul 22, 2022 | Data Access from Outside Expected Data Manager Component in GitHub repository openemr/openemr prior to 7.0.0. |
| CVE-2022-20916 | MEDIUM | 6.1 | 0.5% | Jul 22, 2022 | A vulnerability in the web-based management interface of Cisco IoT Control Center could allow an unauthenticated, remote... |
| CVE-2022-20913 | MEDIUM | 6.5 | 0.9% | Jul 22, 2022 | A vulnerability in Cisco Nexus Dashboard could allow an authenticated, remote attacker to write arbitrary files on an af... |
| CVE-2022-20912 | HIGH | 7.2 | 0.9% | Jul 22, 2022 | Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W... |
| CVE-2022-20911 | HIGH | 7.2 | 0.9% | Jul 22, 2022 | Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W... |
| CVE-2022-20910 | HIGH | 7.2 | 0.9% | Jul 22, 2022 | Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W... |
| CVE-2022-20909 | MEDIUM | 6.7 | 0.2% | Jul 22, 2022 | Multiple vulnerabilities in Cisco Nexus Dashboard could allow an authenticated, local attacker to elevate privileges on ... |
| CVE-2022-20908 | MEDIUM | 6.7 | 0.2% | Jul 22, 2022 | Multiple vulnerabilities in Cisco Nexus Dashboard could allow an authenticated, local attacker to elevate privileges on ... |
| CVE-2022-20907 | MEDIUM | 6.7 | 0.2% | Jul 22, 2022 | Multiple vulnerabilities in Cisco Nexus Dashboard could allow an authenticated, local attacker to elevate privileges on ... |
| CVE-2022-20906 | MEDIUM | 6.7 | 0.2% | Jul 22, 2022 | Multiple vulnerabilities in Cisco Nexus Dashboard could allow an authenticated, local attacker to elevate privileges on ... |
| CVE-2022-20904 | HIGH | 7.2 | 0.9% | Jul 22, 2022 | Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now