2022 CVE Vulnerabilities
27,543 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-29890 | MEDIUM | 6.1 | 0.4% | Jul 15, 2022 | In affected versions of Octopus Server the help sidebar can be customized to include a Cross-Site Scripting payload in t... |
| CVE-2022-1881 | MEDIUM | 5.3 | 0.5% | Jul 15, 2022 | In affected versions of Octopus Server an Insecure Direct Object Reference vulnerability exists where it is possible for... |
| CVE-2022-2420 | HIGH | 8 | 1.0% | Jul 15, 2022 | A vulnerability was found in URVE Web Manager. It has been rated as critical. This issue affects some unknown processing... |
| CVE-2022-2419 | HIGH | 8 | 12.8% | Jul 15, 2022 | A vulnerability was found in URVE Web Manager. It has been declared as critical. This vulnerability affects unknown code... |
| CVE-2022-2418 | HIGH | 8 | 1.1% | Jul 15, 2022 | A vulnerability was found in URVE Web Manager. It has been classified as critical. This affects an unknown part of the f... |
| CVE-2022-34094 | MEDIUM | 6.1 | 2.3% | Jul 14, 2022 | Portal do Software Publico Brasileiro i3geo v7.0.5 was discovered to contain a cross-site scripting (XSS) vulnerability ... |
| CVE-2022-34093 | MEDIUM | 6.1 | 2.3% | Jul 14, 2022 | Portal do Software Publico Brasileiro i3geo v7.0.5 was discovered to contain a cross-site scripting (XSS) vulnerability ... |
| CVE-2022-34092 | MEDIUM | 6.1 | 1.1% | Jul 14, 2022 | Portal do Software Publico Brasileiro i3geo v7.0.5 was discovered to contain a cross-site scripting (XSS) vulnerability ... |
| CVE-2022-32425 | MEDIUM | 5.3 | 0.5% | Jul 14, 2022 | The login function of Mealie v1.0.0beta-2 allows attackers to enumerate existing usernames by timing the server's respon... |
| CVE-2022-32417 | CRITICAL | 9.8 | 32.7% | Jul 14, 2022 | PbootCMS v3.1.2 was discovered to contain a remote code execution (RCE) vulnerability via the function parserIfLabel at ... |
| CVE-2022-32416 | HIGH | 7.2 | 0.8% | Jul 14, 2022 | Product Show Room Site v1.0 is vulnerable to SQL Injection via /psrs/classes/Master.php?f=delete_product. |
| CVE-2022-32415 | HIGH | 8.8 | 0.8% | Jul 14, 2022 | Product Show Room Site v1.0 is vulnerable to SQL Injection via /psrs/?p=products/view_product&id=. |
| CVE-2022-32409 | CRITICAL | 9.8 | 9.5% | Jul 14, 2022 | A local file inclusion (LFI) vulnerability in the component codemirror.php of Portal do Software Publico Brasileiro i3ge... |
| CVE-2022-32406 | MEDIUM | 5.5 | 0.5% | Jul 14, 2022 | GtkRadiant v1.6.6 was discovered to contain a buffer overflow via the component q3map2. This vulnerability can cause a D... |
| CVE-2022-32389 | HIGH | 7.5 | 0.5% | Jul 14, 2022 | Isode SWIFT v4.0.2 was discovered to contain hard-coded credentials in the Registry Editor. This allows attackers to acc... |
| CVE-2022-32323 | HIGH | 7.3 | 0.8% | Jul 14, 2022 | AutoTrace v0.40.0 was discovered to contain a heap overflow via the ReadImage function at input-bmp.c:660. |
| CVE-2022-32318 | MEDIUM | 5.4 | 0.5% | Jul 14, 2022 | Fast Food Ordering System v1.0 was discovered to contain a persistent cross-site scripting (XSS) vulnerability via the c... |
| CVE-2022-32317 | MEDIUM | 5.5 | 0.8% | Jul 14, 2022 | The MPlayer Project v1.5 was discovered to contain a heap use-after-free resulting in a double free in the preinit funct... |
| CVE-2022-32298 | HIGH | 7.5 | 0.9% | Jul 14, 2022 | Toybox v0.8.7 was discovered to contain a NULL pointer dereference via the component httpd.c. This vulnerability can lea... |
| CVE-2022-32297 | HIGH | 7.5 | 1.0% | Jul 14, 2022 | Piwigo v12.2.0 was discovered to contain SQL injection vulnerability via the Search function. |
| CVE-2022-31156 | MEDIUM | 4.4 | 0.5% | Jul 14, 2022 | Gradle is a build tool. Dependency verification is a security feature in Gradle Build Tool that was introduced to allow ... |
| CVE-2022-31147 | HIGH | 7.5 | 1.6% | Jul 14, 2022 | The jQuery Validation Plugin (jquery-validation) provides drop-in validation for forms. Versions of jquery-validation pr... |
| CVE-2022-23825 | MEDIUM | 6.5 | 0.8% | Jul 14, 2022 | Aliases in the branch predictor may cause some AMD processors to predict the wrong branch type potentially leading to in... |
| CVE-2022-31142 | HIGH | 7.5 | 1.2% | Jul 14, 2022 | @fastify/bearer-auth is a Fastify plugin to require bearer Authorization headers. @fastify/bearer-auth prior to versions... |
| CVE-2022-2408 | MEDIUM | 4.3 | 0.5% | Jul 14, 2022 | The Guest account feature in Mattermost version 6.7.0 and earlier fails to properly restrict the permissions, which allo... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now