2022 CVE Vulnerabilities
27,525 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-35950 | MEDIUM | 4.8 | 0.4% | Oct 9, 2023 | OroCommerce is an open-source Business to Business Commerce application. In versions 4.1.0 through 4.1.13, 4.2.0 through... |
| CVE-2022-34355 | MEDIUM | 5.5 | 0.2% | Oct 6, 2023 | IBM Jazz Foundation (IBM Engineering Lifecycle Management 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2) could disclose sensitiv... |
| CVE-2022-4145 | MEDIUM | 5.3 | 0.6% | Oct 5, 2023 | A content spoofing flaw was found in OpenShift's OAuth endpoint. This flaw allows a remote, unauthenticated attacker to ... |
| CVE-2022-36277 | MEDIUM | 6.1 | 0.3% | Oct 4, 2023 | The 'sReferencia', 'sDescripcion', 'txtCodigo' and 'txtDescripcion' parameters, in the frmGestionStock.aspx and frmEditS... |
| CVE-2022-43906 | MEDIUM | 5.3 | 0.4% | Oct 4, 2023 | IBM Security Guardium 11.5 could disclose sensitive information due to a missing or insecure SameSite attribute for a se... |
| CVE-2022-4132 | MEDIUM | 5.9 | 0.7% | Oct 4, 2023 | A flaw was found in JSS. A memory leak in JSS requires non-standard configuration but is a low-effort DoS vector if conf... |
| CVE-2022-47187 | MEDIUM | 6.1 | 0.4% | Sep 28, 2023 | There is a file upload XSS vulnerability in Generex CS141 below 2.06 version. The web application allows file uploading,... |
| CVE-2022-4245 | MEDIUM | 4.3 | 0.7% | Sep 25, 2023 | A flaw was found in codehaus-plexus. The org.codehaus.plexus.util.xml.XmlWriterUtil#writeComment fails to sanitize comme... |
| CVE-2022-4137 | MEDIUM | 6.1 | 1.1% | Sep 25, 2023 | A reflected cross-site scripting (XSS) vulnerability was found in the 'oob' OAuth endpoint due to incorrect null-byte ha... |
| CVE-2022-3962 | MEDIUM | 4.3 | 0.7% | Sep 23, 2023 | A content spoofing vulnerability was found in Kiali. It was discovered that Kiali does not implement error handling when... |
| CVE-2022-3916 | MEDIUM | 6.8 | 1.0% | Sep 20, 2023 | A flaw was found in the offline_access scope in Keycloak. This issue would affect users of shared computers more (especi... |
| CVE-2022-1438 | MEDIUM | 4.8 | 0.7% | Sep 20, 2023 | A flaw was found in Keycloak. Under specific circumstances, HTML entities are not sanitized during user impersonation, r... |
| CVE-2022-45448 | MEDIUM | 6.1 | 0.3% | Sep 20, 2023 | M4 PDF plugin for Prestashop sites, in its 3.2.3 version and before, is vulnerable to an arbitrary HTML Document craftin... |
| CVE-2022-45447 | MEDIUM | 6.5 | 0.7% | Sep 20, 2023 | M4 PDF plugin for Prestashop sites, in its 3.2.3 version and before, is vulnerable to a directory traversal vulnerabilit... |
| CVE-2022-47561 | MEDIUM | 5.5 | 0.2% | Sep 20, 2023 | The web application stores credentials in clear text in the "admin.xml" file, which can be accessed without logging into... |
| CVE-2022-47560 | MEDIUM | 6.5 | 0.3% | Sep 20, 2023 | The lack of web request control on ekorCCP and ekorRCI devices allows a potential attacker to create custom requests to ... |
| CVE-2022-47557 | MEDIUM | 6.1 | 0.1% | Sep 19, 2023 | Vulnerability in ekorCCP and ekorRCI that could allow an attacker with access to the network where the device is located... |
| CVE-2022-47556 | MEDIUM | 6.5 | 0.5% | Sep 19, 2023 | Uncontrolled resource consumption in ekorRCI, allowing an attacker with low-privileged access to the web server to send ... |
| CVE-2022-3466 | MEDIUM | 5.3 | 0.2% | Sep 15, 2023 | The version of cri-o as released for Red Hat OpenShift Container Platform 4.9.48, 4.10.31, and 4.11.6 via RHBA-2022:6316... |
| CVE-2022-20917 | MEDIUM | 4.3 | 0.9% | Sep 15, 2023 | A vulnerability in the Extensible Messaging and Presence Protocol (XMPP) message processing feature of Cisco Jabber coul... |
| CVE-2022-47637 | MEDIUM | 6.7 | 0.2% | Sep 12, 2023 | The installer in XAMPP through 8.1.12 allows local users to write to the C:\xampp directory. Common use cases execute fi... |
| CVE-2022-34238 | MEDIUM | 5.5 | 0.3% | Sep 11, 2023 | Acrobat Reader versions 22.001.20142 (and earlier), 20.005.30334 (and earlier) and 20.005.30334 (and earlier) are affect... |
| CVE-2022-22409 | MEDIUM | 5.3 | 0.8% | Sep 8, 2023 | IBM Aspera Faspex 5.0.5 could allow a remote attacker to gather sensitive information about the web application, caused ... |
| CVE-2022-22402 | MEDIUM | 5.4 | 0.4% | Sep 8, 2023 | IBM Aspera Faspex 5.0.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaSc... |
| CVE-2022-22405 | MEDIUM | 5.9 | 0.5% | Sep 8, 2023 | IBM Aspera Faspex 5.0.5 could allow a remote attacker to obtain sensitive information, caused by the failure to properly... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now