2022 CVE Vulnerabilities
27,552 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-31501 | CRITICAL | 9.3 | 1.2% | Jul 11, 2022 | The ChaoticOnyx/OnyxForum repository before 2022-05-04 on GitHub allows absolute path traversal because the Flask send_f... |
| CVE-2022-31472 | MEDIUM | 4.3 | 0.7% | Jul 11, 2022 | Browse restriction bypass vulnerability in Cabinet of Cybozu Garoon 4.0.0 to 5.5.1 allows a remote authenticated attacke... |
| CVE-2022-30943 | MEDIUM | 4.3 | 0.7% | Jul 11, 2022 | Browsing restriction bypass vulnerability in Bulletin of Cybozu Garoon 4.0.0 to 5.9.1 allows a remote authenticated atta... |
| CVE-2022-30602 | HIGH | 8.1 | 1.0% | Jul 11, 2022 | Operation restriction bypass in multiple applications of Cybozu Garoon 4.0.0 to 5.9.1 allows a remote authenticated atta... |
| CVE-2022-29512 | MEDIUM | 6.5 | 0.9% | Jul 11, 2022 | Exposure of sensitive information to an unauthorized actor issue in multiple applications of Cybozu Garoon 4.0.0 to 5.9.... |
| CVE-2022-27168 | MEDIUM | 6.1 | 0.9% | Jul 11, 2022 | Cross-site scripting vulnerability in LiteCart versions prior to 2.4.2 allows a remote attacker to inject an arbitrary s... |
| CVE-2022-2365 | MEDIUM | 5.4 | 0.4% | Jul 10, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository zadam/trilium prior to 0.53.3. |
| CVE-2022-27910 | MEDIUM | 6.1 | 0.5% | Jul 10, 2022 | In Joomla component 'Joomlatools - DOCman 3.5.13 (and likely most versions below)' are affected to an reflected Cross-Si... |
| CVE-2022-2353 | MEDIUM | 6.1 | 0.5% | Jul 9, 2022 | Prior to microweber/microweber v1.2.20, due to improper neutralization of input, an attacker can steal tokens to perform... |
| CVE-2022-2345 | HIGH | 7.8 | 1.0% | Jul 8, 2022 | Use After Free in GitHub repository vim/vim prior to 9.0.0046. |
| CVE-2022-35412 | MEDIUM | 5.1 | 0.2% | Jul 8, 2022 | Digital Guardian Agent 7.7.4.0042 allows an administrator (who ordinarily does not have a supported way to uninstall the... |
| CVE-2022-31137 | CRITICAL | 9.8 | 90.4% | Jul 8, 2022 | Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Versions prior to 6.1.1.0 are sub... |
| CVE-2022-35411 | CRITICAL | 9.8 | 45.9% | Jul 8, 2022 | rpc.py through 0.6.0 allows Remote Code Execution because an unpickle occurs when the "serializer: pickle" HTTP header i... |
| CVE-2022-34914 | CRITICAL | 9.8 | 0.9% | Jul 8, 2022 | Webswing before 22.1.3 allows X-Forwarded-For header injection. The client IP address is associated with a variable in t... |
| CVE-2022-2344 | HIGH | 7.8 | 1.0% | Jul 8, 2022 | Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0045. |
| CVE-2022-35410 | HIGH | 7.5 | 1.8% | Jul 8, 2022 | mat2 (aka metadata anonymisation toolkit) before 0.13.0 allows ../ directory traversal during the ZIP archive cleaning p... |
| CVE-2022-2343 | HIGH | 7.8 | 1.1% | Jul 8, 2022 | Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0044. |
| CVE-2022-22476 | HIGH | 8.8 | 0.6% | Jul 8, 2022 | IBM WebSphere Application Server Liberty 17.0.0.3 through 22.0.0.7 and Open Liberty are vulnerable to identity spoofing ... |
| CVE-2022-22465 | HIGH | 7.8 | 0.2% | Jul 8, 2022 | IBM Security Access Manager Appliance 10.0.0.0, 10.0.1.0, 10.0.2.0, and 10.0.3.0 could allow a local user to obtain elev... |
| CVE-2022-22464 | HIGH | 7.5 | 0.6% | Jul 8, 2022 | IBM Security Access Manager Appliance 10.0.0.0, 10.0.1.0, 10.0.2.0, and 10.0.3.0 uses weaker than expected cryptographic... |
| CVE-2022-22463 | MEDIUM | 6.5 | 0.8% | Jul 8, 2022 | IBM Security Access Manager Appliance 10.0.0.0, 10.0.1.0, 10.0.2.0, and 10.0.3.0 is vulnerable to SQL injection. A remot... |
| CVE-2022-22370 | MEDIUM | 5.4 | 0.4% | Jul 8, 2022 | IBM Security Verify Access 10.0.0.0, 10.0.1.0, 10.0.2.0, and 10.0.3.0 is vulnerable to cross-site scripting. This vulner... |
| CVE-2022-34306 | MEDIUM | 5.4 | 0.6% | Jul 8, 2022 | IBM CICS TX Standard and Advanced 11.1 is vulnerable to HTTP header injection, caused by improper validation of input by... |
| CVE-2022-34167 | MEDIUM | 5.4 | 0.5% | Jul 8, 2022 | IBM CICS TX Standard and Advanced 11.1 is vulnerable to stored cross-site scripting. This vulnerability allows users to ... |
| CVE-2022-34166 | MEDIUM | 5.4 | 0.5% | Jul 8, 2022 | IBM CICS TX Standard and Advanced 11.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed a... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now