2022 CVE Vulnerabilities

27,543 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-1920HIGH7.8Integer overflow in matroskademux element in gst_matroska_demux_add_wvpk_header function which allows a heap overwrite w...
CVE-2022-36305MEDIUM6.1Vesta v1.0.0-5 was discovered to contain a cross-site scripting (XSS) vulnerability via the body function at /web/api/v1...
CVE-2022-36304MEDIUM6.1Vesta v1.0.0-5 was discovered to contain a cross-site scripting (XSS) vulnerability via the generate_response function a...
CVE-2022-36303MEDIUM6.1Vesta v1.0.0-5 was discovered to contain a cross-site scripting (XSS) vulnerability via the handle_file_upload function ...
CVE-2022-34025MEDIUM6.1Vesta v1.0.0-5 was discovered to contain a cross-site scripting (XSS) vulnerability via the post function at /web/api/v1...
CVE-2022-34169HIGH7.5The Apache Xalan Java XSLT library is vulnerable to an integer truncation issue when processing malicious XSLT styleshee...
CVE-2022-34024HIGH7.2Barangay Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via the resident module...
CVE-2022-30570MEDIUM6.5The Column Based Security component of TIBCO Software Inc.'s TIBCO Data Virtualization and TIBCO Data Virtualization for...
CVE-2022-2394LOW3.5Puppet Bolt prior to version 3.24.0 will print sensitive parameters when planning a run resulting in them potentially be...
CVE-2022-27373HIGH8.8Shanghai Feixun Data Communication Technology Co., Ltd router fir302b A2 was discovered to contain a remote command exec...
CVE-2022-34023CRITICAL9.8Barangay Management System v1.0 was discovered to contain a SQL injection vulnerability via the hidden_id parameter at /...
CVE-2022-34001MEDIUM6.5Unit4 ERP through 7.9 allows XXE via ExecuteServerProcessAsynchronously.
CVE-2022-22417MEDIUM5.4IBM Sterling Partner Engagement Manager 6.1.2, 6.2, and Cloud/SasS 22.2 is vulnerable to cross-site scripting. This vuln...
CVE-2022-22416MEDIUM5.4IBM Sterling Partner Engagement Manager 6.1.2, 6.2, and Cloud/SasS 22.2 is vulnerable to server-side request forgery (SS...
CVE-2022-22360HIGH8.8IBM Sterling Partner Engagement Manager 6.1.2, 6.2, and Cloud/SasS 22.2 could allow a remote authenticated attacker to c...
CVE-2022-22359MEDIUM6.5IBM Sterling Partner Engagement Manager 6.1.2, 6.2, and Cloud/SasS 22.2 is vulnerable to cross-site request forgery whic...
CVE-2022-22358HIGH7.1IBM Sterling Partner Engagement Manager 6.1.2, 6.2, and Cloud/SasS 22.2 is vulnerable to an XML External Entity Injectio...
CVE-2022-35912CRITICAL9.8In grails-databinding in Grails before 3.3.15, 4.x before 4.1.1, 5.x before 5.1.9, and 5.2.x before 5.2.1 (at least when...
CVE-2022-2469HIGH8.1GNU SASL libgsasl server-side read-out-of-bounds with malicious authenticated GSS-API client
CVE-2022-27580HIGH7.8A deserialization vulnerability in a .NET framework class used and not properly checked by Safety Designer all versions ...
CVE-2022-27579HIGH7.8A deserialization vulnerability in a .NET framework class used and not properly checked by Flexi Soft Designer in all ve...
CVE-2022-27545MEDIUM5.4BigFix Web Reports authorized users may perform HTML injection for the email administrative configuration page.
CVE-2022-27544MEDIUM6.5BigFix Web Reports authorized users may see SMTP credentials in clear text.
CVE-2022-35405CRITICAL9.8Zoho ManageEngine Password Manager Pro before 12101 and PAM360 before 5510 are vulnerable to unauthenticated remote code...
CVE-2022-2193HIGH8.8Insecure Direct Object Reference vulnerability in HYPR Server before version 6.14.1 allows remote authenticated attacker...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now