2022 CVE Vulnerabilities

27,552 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-31501CRITICAL9.3The ChaoticOnyx/OnyxForum repository before 2022-05-04 on GitHub allows absolute path traversal because the Flask send_f...
CVE-2022-31472MEDIUM4.3Browse restriction bypass vulnerability in Cabinet of Cybozu Garoon 4.0.0 to 5.5.1 allows a remote authenticated attacke...
CVE-2022-30943MEDIUM4.3Browsing restriction bypass vulnerability in Bulletin of Cybozu Garoon 4.0.0 to 5.9.1 allows a remote authenticated atta...
CVE-2022-30602HIGH8.1Operation restriction bypass in multiple applications of Cybozu Garoon 4.0.0 to 5.9.1 allows a remote authenticated atta...
CVE-2022-29512MEDIUM6.5Exposure of sensitive information to an unauthorized actor issue in multiple applications of Cybozu Garoon 4.0.0 to 5.9....
CVE-2022-27168MEDIUM6.1Cross-site scripting vulnerability in LiteCart versions prior to 2.4.2 allows a remote attacker to inject an arbitrary s...
CVE-2022-2365MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository zadam/trilium prior to 0.53.3.
CVE-2022-27910MEDIUM6.1In Joomla component 'Joomlatools - DOCman 3.5.13 (and likely most versions below)' are affected to an reflected Cross-Si...
CVE-2022-2353MEDIUM6.1Prior to microweber/microweber v1.2.20, due to improper neutralization of input, an attacker can steal tokens to perform...
CVE-2022-2345HIGH7.8Use After Free in GitHub repository vim/vim prior to 9.0.0046.
CVE-2022-35412MEDIUM5.1Digital Guardian Agent 7.7.4.0042 allows an administrator (who ordinarily does not have a supported way to uninstall the...
CVE-2022-31137CRITICAL9.8Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Versions prior to 6.1.1.0 are sub...
CVE-2022-35411CRITICAL9.8rpc.py through 0.6.0 allows Remote Code Execution because an unpickle occurs when the "serializer: pickle" HTTP header i...
CVE-2022-34914CRITICAL9.8Webswing before 22.1.3 allows X-Forwarded-For header injection. The client IP address is associated with a variable in t...
CVE-2022-2344HIGH7.8Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0045.
CVE-2022-35410HIGH7.5mat2 (aka metadata anonymisation toolkit) before 0.13.0 allows ../ directory traversal during the ZIP archive cleaning p...
CVE-2022-2343HIGH7.8Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0044.
CVE-2022-22476HIGH8.8IBM WebSphere Application Server Liberty 17.0.0.3 through 22.0.0.7 and Open Liberty are vulnerable to identity spoofing ...
CVE-2022-22465HIGH7.8IBM Security Access Manager Appliance 10.0.0.0, 10.0.1.0, 10.0.2.0, and 10.0.3.0 could allow a local user to obtain elev...
CVE-2022-22464HIGH7.5IBM Security Access Manager Appliance 10.0.0.0, 10.0.1.0, 10.0.2.0, and 10.0.3.0 uses weaker than expected cryptographic...
CVE-2022-22463MEDIUM6.5IBM Security Access Manager Appliance 10.0.0.0, 10.0.1.0, 10.0.2.0, and 10.0.3.0 is vulnerable to SQL injection. A remot...
CVE-2022-22370MEDIUM5.4IBM Security Verify Access 10.0.0.0, 10.0.1.0, 10.0.2.0, and 10.0.3.0 is vulnerable to cross-site scripting. This vulner...
CVE-2022-34306MEDIUM5.4IBM CICS TX Standard and Advanced 11.1 is vulnerable to HTTP header injection, caused by improper validation of input by...
CVE-2022-34167MEDIUM5.4IBM CICS TX Standard and Advanced 11.1 is vulnerable to stored cross-site scripting. This vulnerability allows users to ...
CVE-2022-34166MEDIUM5.4IBM CICS TX Standard and Advanced 11.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed a...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now