2022 CVE Vulnerabilities
27,543 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-1920 | HIGH | 7.8 | 0.5% | Jul 19, 2022 | Integer overflow in matroskademux element in gst_matroska_demux_add_wvpk_header function which allows a heap overwrite w... |
| CVE-2022-36305 | MEDIUM | 6.1 | 0.4% | Jul 19, 2022 | Vesta v1.0.0-5 was discovered to contain a cross-site scripting (XSS) vulnerability via the body function at /web/api/v1... |
| CVE-2022-36304 | MEDIUM | 6.1 | 0.4% | Jul 19, 2022 | Vesta v1.0.0-5 was discovered to contain a cross-site scripting (XSS) vulnerability via the generate_response function a... |
| CVE-2022-36303 | MEDIUM | 6.1 | 0.4% | Jul 19, 2022 | Vesta v1.0.0-5 was discovered to contain a cross-site scripting (XSS) vulnerability via the handle_file_upload function ... |
| CVE-2022-34025 | MEDIUM | 6.1 | 0.4% | Jul 19, 2022 | Vesta v1.0.0-5 was discovered to contain a cross-site scripting (XSS) vulnerability via the post function at /web/api/v1... |
| CVE-2022-34169 | HIGH | 7.5 | 17.7% | Jul 19, 2022 | The Apache Xalan Java XSLT library is vulnerable to an integer truncation issue when processing malicious XSLT styleshee... |
| CVE-2022-34024 | HIGH | 7.2 | 1.1% | Jul 19, 2022 | Barangay Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via the resident module... |
| CVE-2022-30570 | MEDIUM | 6.5 | 0.6% | Jul 19, 2022 | The Column Based Security component of TIBCO Software Inc.'s TIBCO Data Virtualization and TIBCO Data Virtualization for... |
| CVE-2022-2394 | LOW | 3.5 | 0.4% | Jul 19, 2022 | Puppet Bolt prior to version 3.24.0 will print sensitive parameters when planning a run resulting in them potentially be... |
| CVE-2022-27373 | HIGH | 8.8 | 2.7% | Jul 19, 2022 | Shanghai Feixun Data Communication Technology Co., Ltd router fir302b A2 was discovered to contain a remote command exec... |
| CVE-2022-34023 | CRITICAL | 9.8 | 0.7% | Jul 19, 2022 | Barangay Management System v1.0 was discovered to contain a SQL injection vulnerability via the hidden_id parameter at /... |
| CVE-2022-34001 | MEDIUM | 6.5 | 0.7% | Jul 19, 2022 | Unit4 ERP through 7.9 allows XXE via ExecuteServerProcessAsynchronously. |
| CVE-2022-22417 | MEDIUM | 5.4 | 0.4% | Jul 19, 2022 | IBM Sterling Partner Engagement Manager 6.1.2, 6.2, and Cloud/SasS 22.2 is vulnerable to cross-site scripting. This vuln... |
| CVE-2022-22416 | MEDIUM | 5.4 | 0.4% | Jul 19, 2022 | IBM Sterling Partner Engagement Manager 6.1.2, 6.2, and Cloud/SasS 22.2 is vulnerable to server-side request forgery (SS... |
| CVE-2022-22360 | HIGH | 8.8 | 1.4% | Jul 19, 2022 | IBM Sterling Partner Engagement Manager 6.1.2, 6.2, and Cloud/SasS 22.2 could allow a remote authenticated attacker to c... |
| CVE-2022-22359 | MEDIUM | 6.5 | 0.3% | Jul 19, 2022 | IBM Sterling Partner Engagement Manager 6.1.2, 6.2, and Cloud/SasS 22.2 is vulnerable to cross-site request forgery whic... |
| CVE-2022-22358 | HIGH | 7.1 | 1.0% | Jul 19, 2022 | IBM Sterling Partner Engagement Manager 6.1.2, 6.2, and Cloud/SasS 22.2 is vulnerable to an XML External Entity Injectio... |
| CVE-2022-35912 | CRITICAL | 9.8 | 1.7% | Jul 19, 2022 | In grails-databinding in Grails before 3.3.15, 4.x before 4.1.1, 5.x before 5.1.9, and 5.2.x before 5.2.1 (at least when... |
| CVE-2022-2469 | HIGH | 8.1 | 1.1% | Jul 19, 2022 | GNU SASL libgsasl server-side read-out-of-bounds with malicious authenticated GSS-API client |
| CVE-2022-27580 | HIGH | 7.8 | 0.3% | Jul 19, 2022 | A deserialization vulnerability in a .NET framework class used and not properly checked by Safety Designer all versions ... |
| CVE-2022-27579 | HIGH | 7.8 | 0.3% | Jul 19, 2022 | A deserialization vulnerability in a .NET framework class used and not properly checked by Flexi Soft Designer in all ve... |
| CVE-2022-27545 | MEDIUM | 5.4 | 0.3% | Jul 19, 2022 | BigFix Web Reports authorized users may perform HTML injection for the email administrative configuration page. |
| CVE-2022-27544 | MEDIUM | 6.5 | 0.4% | Jul 19, 2022 | BigFix Web Reports authorized users may see SMTP credentials in clear text. |
| CVE-2022-35405 | CRITICAL | 9.8 | 99.9% | Jul 19, 2022 | Zoho ManageEngine Password Manager Pro before 12101 and PAM360 before 5510 are vulnerable to unauthenticated remote code... |
| CVE-2022-2193 | HIGH | 8.8 | 0.7% | Jul 19, 2022 | Insecure Direct Object Reference vulnerability in HYPR Server before version 6.14.1 allows remote authenticated attacker... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now