2022 CVE Vulnerabilities
27,543 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-2406 | MEDIUM | 6.5 | 0.8% | Jul 14, 2022 | The legacy Slack import feature in Mattermost version 6.7.0 and earlier fails to properly limit the sizes of imported fi... |
| CVE-2022-2401 | MEDIUM | 6.5 | 0.7% | Jul 14, 2022 | Unrestricted information disclosure of all users in Mattermost version 6.7.0 and earlier allows team members to access s... |
| CVE-2022-22460 | HIGH | 7.5 | 0.6% | Jul 14, 2022 | IBM Security Verify Identity Manager 10.0 contains sensitive information in the source code repository that could be use... |
| CVE-2022-22453 | HIGH | 7.5 | 0.3% | Jul 14, 2022 | IBM Security Verify Identity Manager 10.0 uses weaker than expected cryptographic algorithms that could allow an attacke... |
| CVE-2022-22452 | HIGH | 7.5 | 0.8% | Jul 14, 2022 | IBM Security Verify Identity Manager 10.0 uses an inadequate account lockout setting that could allow a remote attacker ... |
| CVE-2022-22450 | LOW | 3.8 | 0.5% | Jul 14, 2022 | IBM Security Verify Identity Manager 10.0 could allow a privileged user to upload a malicious file by bypassing extensio... |
| CVE-2022-35283 | MEDIUM | 6.5 | 1.0% | Jul 14, 2022 | IBM Security Verify Information Queue 10.0.2 could allow an authenticated user to cause a denial of service with a speci... |
| CVE-2022-22477 | MEDIUM | 6.1 | 0.5% | Jul 14, 2022 | IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to e... |
| CVE-2022-22473 | MEDIUM | 5.3 | 0.8% | Jul 14, 2022 | IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to obtain sensitive information ca... |
| CVE-2022-32225 | MEDIUM | 6.1 | 0.5% | Jul 14, 2022 | A reflected DOM-Based XSS vulnerability has been discovered in the Help directory of Veeam Management Pack for Microsoft... |
| CVE-2022-32223 | HIGH | 7.3 | 1.6% | Jul 14, 2022 | Node.js is vulnerable to Hijack Execution Flow: DLL Hijacking under certain conditions on Windows platforms.This vulnera... |
| CVE-2022-32222 | MEDIUM | 5.3 | 1.7% | Jul 14, 2022 | A cryptographic vulnerability exists on Node.js on linux in versions of 18.x prior to 18.40.0 which allowed a default pa... |
| CVE-2022-32215 | MEDIUM | 6.5 | 68.8% | Jul 14, 2022 | The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not correctly handle multi-line T... |
| CVE-2022-32214 | MEDIUM | 6.5 | 77.3% | Jul 14, 2022 | The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not strictly use the CRLF sequenc... |
| CVE-2022-32213 | MEDIUM | 6.5 | 35.1% | Jul 14, 2022 | The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not correctly parse and validate ... |
| CVE-2022-32212 | HIGH | 8.1 | 5.6% | Jul 14, 2022 | A OS Command Injection vulnerability exists in Node.js versions <14.20.0, <16.20.0, <18.5.0 due to an insufficient IsAll... |
| CVE-2022-32210 | MEDIUM | 6.5 | 0.4% | Jul 14, 2022 | `Undici.ProxyAgent` never verifies the remote server's certificate, and always exposes all request & response data to th... |
| CVE-2022-2393 | MEDIUM | 5.7 | 0.2% | Jul 14, 2022 | A flaw was found in pki-core, which could allow a user to get a certificate for another user identity when directory-bas... |
| CVE-2022-29593 | MEDIUM | 5.9 | 10.4% | Jul 14, 2022 | relay_cgi.cgi on Dingtian DT-R002 2CH relay devices with firmware 3.1.276A allows an attacker to replay HTTP post reques... |
| CVE-2022-28876 | HIGH | 7.5 | 0.4% | Jul 14, 2022 | A Denial-of-Service (DoS) vulnerability was discovered in F-Secure Atlant and in certain WithSecure products whereby the... |
| CVE-2022-1662 | MEDIUM | 5.5 | 0.2% | Jul 14, 2022 | In convert2rhel, there's an ansible playbook named ansible/run-convert2rhel.yml which passes the Red Hat Subscription Ma... |
| CVE-2022-30024 | HIGH | 8.8 | 2.2% | Jul 14, 2022 | A buffer overflow in the httpd daemon on TP-Link TL-WR841N V12 (firmware version 3.16.9) devices allows an authenticated... |
| CVE-2022-30113 | CRITICAL | 9.8 | 0.7% | Jul 14, 2022 | Electronic mall system 1.0_build20200203 is affected vulnerable to SQL Injection. |
| CVE-2022-28377 | HIGH | 7.5 | 0.8% | Jul 14, 2022 | On Verizon 5G Home LVSKIHP InDoorUnit (IDU) 3.4.66.162 and OutDoorUnit (ODU) 3.33.101.0 devices, the CRTC and ODU RPC en... |
| CVE-2022-28375 | CRITICAL | 9.8 | 1.8% | Jul 14, 2022 | Verizon 5G Home LVSKIHP OutDoorUnit (ODU) 3.33.101.0 does not property sanitize user-controlled parameters within the cr... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now