2022 CVE Vulnerabilities

27,543 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-2135HIGH7.5The affected product is vulnerable to multiple SQL injections, which may allow an unauthorized attacker to disclose info...
CVE-2022-1655MEDIUM6.5An Incorrect Permission Assignment for Critical Resource flaw was found in Horizon on Red Hat OpenStack. Horizon session...
CVE-2022-36131MEDIUM6.1The Better PDF Exporter add-on 10.0.0 for Atlassian Jira is prone to stored XSS via a crafted description to the PDF Tem...
CVE-2022-31168HIGH8.8Zulip is an open source team chat tool. Due to an incorrect authorization check in Zulip Server 5.4 and earlier, a membe...
CVE-2022-2209Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. Reason: This CVE has been rejected as it was incorrectly assigned. Al...
CVE-2022-2327HIGH7.8io_uring use work_flags to determine which identity need to grab from the calling process to make sure it is consistent ...
CVE-2022-31172HIGH7.5OpenZeppelin Contracts is a library for smart contract development. Versions 4.1.0 until 4.7.1 are vulnerable to the Sig...
CVE-2022-31170HIGH7.5OpenZeppelin Contracts is a library for smart contract development. Versions 4.0.0 until 4.7.1 are vulnerable to ERC165C...
CVE-2022-31169HIGH7.5Wasmtime is a standalone runtime for WebAssembly. There is a bug in Wasmtime's code generator, Cranelift, for AArch64 ta...
CVE-2022-31164HIGH7.5Tovy is a a staff management system for Roblox groups. A vulnerability in versions prior to 0.7.51 allows users to log i...
CVE-2022-31163HIGH8.1TZInfo is a Ruby library that provides access to time zone data and allows times to be converted using time zone rules. ...
CVE-2022-31162HIGH7.5Slack Morphism is an async client library for Rust. Prior to 0.41.0, it was possible for Slack OAuth client information ...
CVE-2022-2495MEDIUM4.8Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 1.2.21.
CVE-2022-2494MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository openemr/openemr prior to 7.0.0.
CVE-2022-2493HIGH8.1Data Access from Outside Expected Data Manager Component in GitHub repository openemr/openemr prior to 7.0.0.
CVE-2022-20916MEDIUM6.1A vulnerability in the web-based management interface of Cisco IoT Control Center could allow an unauthenticated, remote...
CVE-2022-20913MEDIUM6.5A vulnerability in Cisco Nexus Dashboard could allow an authenticated, remote attacker to write arbitrary files on an af...
CVE-2022-20912HIGH7.2Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W...
CVE-2022-20911HIGH7.2Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W...
CVE-2022-20910HIGH7.2Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W...
CVE-2022-20909MEDIUM6.7Multiple vulnerabilities in Cisco Nexus Dashboard could allow an authenticated, local attacker to elevate privileges on ...
CVE-2022-20908MEDIUM6.7Multiple vulnerabilities in Cisco Nexus Dashboard could allow an authenticated, local attacker to elevate privileges on ...
CVE-2022-20907MEDIUM6.7Multiple vulnerabilities in Cisco Nexus Dashboard could allow an authenticated, local attacker to elevate privileges on ...
CVE-2022-20906MEDIUM6.7Multiple vulnerabilities in Cisco Nexus Dashboard could allow an authenticated, local attacker to elevate privileges on ...
CVE-2022-20904HIGH7.2Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now