2022 CVE Vulnerabilities

27,552 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-28889MEDIUM4.3In Apache Druid 0.22.1 and earlier, the server did not set appropriate headers to prevent clickjacking. Druid 0.23.0 and...
CVE-2022-31136MEDIUM6.1Bookwyrm is an open source social reading and reviewing program. Versions of Bookwyrm prior to 0.4.1 did not properly sa...
CVE-2022-31135HIGH7.5Akashi is an open source server implementation of the Attorney Online video game based on the Ace Attorney universe. Aff...
CVE-2022-31133MEDIUM4.8HumHub is an Open Source Enterprise Social Network. Affected versions of HumHub are vulnerable to a stored Cross-Site Sc...
CVE-2022-31121HIGH7.5Hyperledger Fabric is a permissioned distributed ledger framework. In affected versions if a consensus client sends a ma...
CVE-2022-23744LOW2.3Check Point Endpoint before version E86.50 failed to protect against specific registry change which allowed to disable e...
CVE-2022-32441MEDIUM5.5A memory corruption in Hex Rays Ida Pro v6.6 allows attackers to cause a Denial of Service (DoS) via a crafted file. Rel...
CVE-2022-32208MEDIUM5.9When curl < 7.84.0 does FTP transfers secured by krb5, it handles message verification failures wrongly. This flaw makes...
CVE-2022-32207CRITICAL9.8When curl < 7.84.0 saves cookies, alt-svc and hsts data to local files, it makes the operation atomic by finalizing the ...
CVE-2022-32206MEDIUM6.5curl < 7.84.0 supports "chained" HTTP compression algorithms, meaning that a serverresponse can be compressed multiple t...
CVE-2022-32205MEDIUM4.3A malicious server can serve excessive amounts of `Set-Cookie:` headers in a HTTP response to curl and curl < 7.84.0 sto...
CVE-2022-31854HIGH7.2Codoforum v5.1 was discovered to contain an arbitrary file upload vulnerability via the logo change option in the admin ...
CVE-2022-34007MEDIUM6.1EQS Integrity Line Professional through 2022-07-01 allows a stored XSS via a crafted whistleblower entry.
CVE-2022-33996HIGH8.8Incorrect permission management in Devolutions Server before 2022.2 allows a new user with a preexisting username to inh...
CVE-2022-25048HIGH8.8Command injection vulnerability in CWP v0.9.8.1126 that allows normal users to run commands as the root user.
CVE-2022-25047MEDIUM5.9The password reset token in CWP v0.9.8.1126 is generated using known or predictable values.
CVE-2022-25046CRITICAL9.8A path traversal vulnerability in loader.php of CWP v0.9.8.1122 allows attackers to execute arbitrary code via a crafted...
CVE-2022-32567MEDIUM5.4The Appfire Jira Misc Custom Fields (JMCF) app 2.4.6 for Atlassian Jira allows XSS via a crafted project name to the Add...
CVE-2022-2342MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository outline/outline prior to v0.64.4.
CVE-2022-2339HIGH7.5With this SSRF vulnerability, an attacker can reach internal addresses to make a request as the server and read it's con...
CVE-2022-27549MEDIUM5.5HCL Launch may store certain data for recurring activities in a plain text format.
CVE-2022-27548MEDIUM5.5HCL Launch stores user credentials in plain clear text which can be read by a local user.
CVE-2022-20862MEDIUM4.3A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) and Cisco Uni...
CVE-2022-20859HIGH8.8A vulnerability in the Disaster Recovery framework of Cisco Unified Communications Manager (Unified CM), Cisco Unified C...
CVE-2022-20815MEDIUM6.1A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM), Cisco Unifie...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now