2022 CVE Vulnerabilities
27,552 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-25238 | MEDIUM | 5.4 | 0.6% | Jun 28, 2022 | Silverstripe silverstripe/framework through 4.10.0 allows XSS, inside of script tags that can can be added to website co... |
| CVE-2022-24444 | MEDIUM | 6.5 | 0.8% | Jun 28, 2022 | Silverstripe silverstripe/framework through 4.10 allows Session Fixation. |
| CVE-2022-31886 | MEDIUM | 6.5 | 2.1% | Jun 28, 2022 | Marval MSM v14.19.0.12476 is vulnerable to Cross Site Request Forgery (CSRF). An attacker can disable the 2FA by sending... |
| CVE-2022-31885 | CRITICAL | 9.8 | 31.3% | Jun 28, 2022 | Marval MSM v14.19.0.12476 is vulnerable to OS Command Injection due to the insecure handling of VBScripts. |
| CVE-2022-31883 | HIGH | 8.8 | 0.9% | Jun 28, 2022 | Marval MSM v14.19.0.12476 is has an Insecure Direct Object Reference (IDOR) vulnerability. A low privilege user is able ... |
| CVE-2022-2246 | — | — | — | Jun 28, 2022 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. Reason: This CVE has been rejected as it was incorrectly assigned. Al... |
| CVE-2022-2231 | MEDIUM | 5.5 | 1.2% | Jun 28, 2022 | NULL Pointer Dereference in GitHub repository vim/vim prior to 8.2. |
| CVE-2022-31230 | CRITICAL | 9.8 | 0.6% | Jun 28, 2022 | Dell PowerScale OneFS, versions 8.2.x-9.2.x, contain broken or risky cryptographic algorithm. A remote unprivileged mali... |
| CVE-2022-31229 | MEDIUM | 4.9 | 0.7% | Jun 28, 2022 | Dell PowerScale OneFS, 8.2.x through 9.3.0.x, contain an error message with sensitive information. An administrator coul... |
| CVE-2022-31108 | MEDIUM | 6.1 | 0.8% | Jun 28, 2022 | Mermaid is a JavaScript based diagramming and charting tool that uses Markdown-inspired text definitions and a renderer ... |
| CVE-2022-31106 | CRITICAL | 9.8 | 1.0% | Jun 28, 2022 | Underscore.deep is a collection of Underscore mixins that operate on nested objects. Versions of `underscore.deep` prior... |
| CVE-2022-31068 | MEDIUM | 5.3 | 0.9% | Jun 28, 2022 | GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking an... |
| CVE-2022-31061 | CRITICAL | 9.8 | 51.2% | Jun 28, 2022 | GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking an... |
| CVE-2022-31056 | CRITICAL | 9.8 | 8.6% | Jun 28, 2022 | GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking an... |
| CVE-2022-2145 | HIGH | 7.8 | 0.3% | Jun 28, 2022 | Cloudflare WARP client for Windows (up to v. 2022.5.309.0) allowed creation of mount points from its ProgramData folder.... |
| CVE-2022-28621 | HIGH | 7.5 | 1.2% | Jun 28, 2022 | A remote disclosure of sensitive information vulnerability was discovered in HPE NonStop DSM/SCM version: T6031H03^ADP. ... |
| CVE-2022-33108 | HIGH | 7.8 | 1.1% | Jun 28, 2022 | XPDF v4.04 was discovered to contain a stack overflow vulnerability via the Object::Copy class of object.cc files. |
| CVE-2022-31052 | MEDIUM | 6.5 | 1.6% | Jun 28, 2022 | Synapse is an open source home server implementation for the Matrix chat network. In versions prior to 1.61.1 URL previe... |
| CVE-2022-0987 | LOW | 3.3 | 0.3% | Jun 28, 2022 | A flaw was found in PackageKit in the way some of the methods exposed by the Transaction interface examines files. This ... |
| CVE-2022-0085 | MEDIUM | 5.3 | 1.0% | Jun 28, 2022 | Server-Side Request Forgery (SSRF) in GitHub repository dompdf/dompdf prior to 2.0.0. |
| CVE-2022-30563 | HIGH | 7.4 | 0.9% | Jun 28, 2022 | When an attacker uses a man-in-the-middle attack to sniff the request packets with success logging in through ONVIF, he ... |
| CVE-2022-30562 | MEDIUM | 4.7 | 0.7% | Jun 28, 2022 | If the user enables the https function on the device, an attacker can modify the user’s request data packet through a ma... |
| CVE-2022-30561 | MEDIUM | 5.9 | 0.7% | Jun 28, 2022 | When an attacker uses a man-in-the-middle attack to sniff the request packets with success logging in, the attacker coul... |
| CVE-2022-30560 | HIGH | 7.4 | 0.8% | Jun 28, 2022 | When an attacker obtaining the administrative account and password, or through a man-in-the-middle attack, the attacker ... |
| CVE-2022-23763 | HIGH | 8.8 | 0.3% | Jun 28, 2022 | Origin validation error vulnerability in NeoRS’s ActiveX moudle allows attackers to download and execute arbitrary files... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now