2022 CVE Vulnerabilities

27,543 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-29890MEDIUM6.1In affected versions of Octopus Server the help sidebar can be customized to include a Cross-Site Scripting payload in t...
CVE-2022-1881MEDIUM5.3In affected versions of Octopus Server an Insecure Direct Object Reference vulnerability exists where it is possible for...
CVE-2022-2420HIGH8A vulnerability was found in URVE Web Manager. It has been rated as critical. This issue affects some unknown processing...
CVE-2022-2419HIGH8A vulnerability was found in URVE Web Manager. It has been declared as critical. This vulnerability affects unknown code...
CVE-2022-2418HIGH8A vulnerability was found in URVE Web Manager. It has been classified as critical. This affects an unknown part of the f...
CVE-2022-34094MEDIUM6.1Portal do Software Publico Brasileiro i3geo v7.0.5 was discovered to contain a cross-site scripting (XSS) vulnerability ...
CVE-2022-34093MEDIUM6.1Portal do Software Publico Brasileiro i3geo v7.0.5 was discovered to contain a cross-site scripting (XSS) vulnerability ...
CVE-2022-34092MEDIUM6.1Portal do Software Publico Brasileiro i3geo v7.0.5 was discovered to contain a cross-site scripting (XSS) vulnerability ...
CVE-2022-32425MEDIUM5.3The login function of Mealie v1.0.0beta-2 allows attackers to enumerate existing usernames by timing the server's respon...
CVE-2022-32417CRITICAL9.8PbootCMS v3.1.2 was discovered to contain a remote code execution (RCE) vulnerability via the function parserIfLabel at ...
CVE-2022-32416HIGH7.2Product Show Room Site v1.0 is vulnerable to SQL Injection via /psrs/classes/Master.php?f=delete_product.
CVE-2022-32415HIGH8.8Product Show Room Site v1.0 is vulnerable to SQL Injection via /psrs/?p=products/view_product&id=.
CVE-2022-32409CRITICAL9.8A local file inclusion (LFI) vulnerability in the component codemirror.php of Portal do Software Publico Brasileiro i3ge...
CVE-2022-32406MEDIUM5.5GtkRadiant v1.6.6 was discovered to contain a buffer overflow via the component q3map2. This vulnerability can cause a D...
CVE-2022-32389HIGH7.5Isode SWIFT v4.0.2 was discovered to contain hard-coded credentials in the Registry Editor. This allows attackers to acc...
CVE-2022-32323HIGH7.3AutoTrace v0.40.0 was discovered to contain a heap overflow via the ReadImage function at input-bmp.c:660.
CVE-2022-32318MEDIUM5.4Fast Food Ordering System v1.0 was discovered to contain a persistent cross-site scripting (XSS) vulnerability via the c...
CVE-2022-32317MEDIUM5.5The MPlayer Project v1.5 was discovered to contain a heap use-after-free resulting in a double free in the preinit funct...
CVE-2022-32298HIGH7.5Toybox v0.8.7 was discovered to contain a NULL pointer dereference via the component httpd.c. This vulnerability can lea...
CVE-2022-32297HIGH7.5Piwigo v12.2.0 was discovered to contain SQL injection vulnerability via the Search function.
CVE-2022-31156MEDIUM4.4Gradle is a build tool. Dependency verification is a security feature in Gradle Build Tool that was introduced to allow ...
CVE-2022-31147HIGH7.5The jQuery Validation Plugin (jquery-validation) provides drop-in validation for forms. Versions of jquery-validation pr...
CVE-2022-23825MEDIUM6.5Aliases in the branch predictor may cause some AMD processors to predict the wrong branch type potentially leading to in...
CVE-2022-31142HIGH7.5@fastify/bearer-auth is a Fastify plugin to require bearer Authorization headers. @fastify/bearer-auth prior to versions...
CVE-2022-2408MEDIUM4.3The Guest account feature in Mattermost version 6.7.0 and earlier fails to properly restrict the permissions, which allo...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now