2022 CVE Vulnerabilities
27,525 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-4955 | MEDIUM | 6.5 | 0.3% | Aug 4, 2023 | Inappropriate implementation in DevTools in Google Chrome prior to 108.0.5359.71 allowed an attacker who convinced a use... |
| CVE-2022-41401 | MEDIUM | 6.5 | 1.2% | Aug 4, 2023 | OpenRefine <= v3.5.2 contains a Server-Side Request Forgery (SSRF) vulnerability, which permits unauthorized users to ex... |
| CVE-2022-26838 | MEDIUM | 6.5 | 1.0% | Aug 3, 2023 | Path traversal vulnerability in Importing Mobile Device Data of Cybozu Remote Service 3.1.2 allows a remote authenticate... |
| CVE-2022-2416 | MEDIUM | 4.3 | 0.3% | Aug 2, 2023 | In affected versions of Octopus Deploy it is possible for a low privileged guest user to craft a request that allows enu... |
| CVE-2022-2346 | MEDIUM | 4.3 | 0.3% | Aug 2, 2023 | In affected versions of Octopus Deploy it is possible for a low privileged guest user to interact with extension endpoin... |
| CVE-2022-42182 | MEDIUM | 5.3 | 0.9% | Jul 31, 2023 | Precisely Spectrum Spatial Analyst 20.01 is vulnerable to Directory Traversal. |
| CVE-2022-4888 | MEDIUM | 6.5 | 0.3% | Jul 31, 2023 | The Checkout Fields Manager WordPress plugin before 1.0.2, Abandoned Cart Recovery WordPress plugin before 1.2.5, Custom... |
| CVE-2022-4926 | MEDIUM | 6.5 | 0.5% | Jul 29, 2023 | Insufficient policy enforcement in Intents in Google Chrome on Android prior to 109.0.5414.119 allowed a remote attacker... |
| CVE-2022-4925 | MEDIUM | 6.5 | 0.5% | Jul 29, 2023 | Insufficient validation of untrusted input in QUIC in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to p... |
| CVE-2022-4922 | MEDIUM | 6.5 | 0.5% | Jul 29, 2023 | Inappropriate implementation in Blink in Google Chrome prior to 99.0.4844.51 allowed a remote attacker to perform UI spo... |
| CVE-2022-4917 | MEDIUM | 4.3 | 0.3% | Jul 29, 2023 | Incorrect security UI in Notifications in Google Chrome on Android prior to 103.0.5060.53 allowed a remote attacker to o... |
| CVE-2022-4915 | MEDIUM | 6.5 | 0.5% | Jul 29, 2023 | Inappropriate implementation in URL Formatting in Google Chrome prior to 103.0.5060.134 allowed a remote attacker to per... |
| CVE-2022-4913 | MEDIUM | 6.5 | 0.5% | Jul 29, 2023 | Inappropriate implementation in Extensions in Google Chrome prior to 105.0.5195.52 allowed a remote attacker who had com... |
| CVE-2022-4911 | MEDIUM | 6.5 | 0.5% | Jul 29, 2023 | Insufficient data validation in DevTools in Google Chrome prior to 106.0.5249.62 allowed a remote attacker to bypass con... |
| CVE-2022-4910 | MEDIUM | 5.4 | 0.4% | Jul 29, 2023 | Inappropriate implementation in Autofill in Google Chrome prior to 107.0.5304.62 allowed a remote attacker to bypass nav... |
| CVE-2022-4909 | MEDIUM | 6.3 | 0.4% | Jul 29, 2023 | Inappropriate implementation in XML in Google Chrome prior to 107.0.5304.62 allowed a remote attacker to potentially per... |
| CVE-2022-4908 | MEDIUM | 4.3 | 0.5% | Jul 29, 2023 | Inappropriate implementation in iFrame Sandbox in Google Chrome prior to 107.0.5304.62 allowed a remote attacker to leak... |
| CVE-2022-31454 | MEDIUM | 6.1 | 0.4% | Jul 28, 2023 | Yii 2 v2.0.45 was discovered to contain a cross-site scripting (XSS) vulnerability via the endpoint /books. NOTE: this i... |
| CVE-2022-31200 | MEDIUM | 6.1 | 0.4% | Jul 27, 2023 | Atmail 5.62 allows XSS via the mail/parse.php?file=html/$this-%3ELanguage/help/filexp.html&FirstLoad=1&HelpFile=file.htm... |
| CVE-2022-31455 | MEDIUM | 6.1 | 0.4% | Jul 26, 2023 | * A cross-site scripting (XSS) vulnerability in Truedesk v1.2.2 allows attackers to execute arbitrary web scripts or HTM... |
| CVE-2022-31456 | MEDIUM | 6.1 | 0.4% | Jul 26, 2023 | A cross-site scripting (XSS) vulnerability in Truedesk v1.2.2 allows attackers to execute arbitrary web scripts or HTML ... |
| CVE-2022-43712 | MEDIUM | 6.5 | 0.4% | Jul 26, 2023 | POST requests to /web/mvc in GX Software XperienCentral version 10.36.0 and earlier were not blocked for uses that are n... |
| CVE-2022-43711 | MEDIUM | 6.1 | 0.3% | Jul 26, 2023 | Interactive Forms (IAF) in GX Software XperienCentral versions 10.29.1 until 10.33.0 was vulnerable to cross site script... |
| CVE-2022-46900 | MEDIUM | 6.5 | 0.5% | Jul 25, 2023 | An issue was discovered in Vocera Report Server and Voice Server 5.x through 5.8. There is Path Traversal in the Task Ex... |
| CVE-2022-31458 | MEDIUM | 6.1 | 0.4% | Jul 25, 2023 | RTX TRAP v1.0 was discovered to be vulnerable to host header poisoning. |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now