2022 CVE Vulnerabilities

27,552 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-25238MEDIUM5.4Silverstripe silverstripe/framework through 4.10.0 allows XSS, inside of script tags that can can be added to website co...
CVE-2022-24444MEDIUM6.5Silverstripe silverstripe/framework through 4.10 allows Session Fixation.
CVE-2022-31886MEDIUM6.5Marval MSM v14.19.0.12476 is vulnerable to Cross Site Request Forgery (CSRF). An attacker can disable the 2FA by sending...
CVE-2022-31885CRITICAL9.8Marval MSM v14.19.0.12476 is vulnerable to OS Command Injection due to the insecure handling of VBScripts.
CVE-2022-31883HIGH8.8Marval MSM v14.19.0.12476 is has an Insecure Direct Object Reference (IDOR) vulnerability. A low privilege user is able ...
CVE-2022-2246Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. Reason: This CVE has been rejected as it was incorrectly assigned. Al...
CVE-2022-2231MEDIUM5.5NULL Pointer Dereference in GitHub repository vim/vim prior to 8.2.
CVE-2022-31230CRITICAL9.8Dell PowerScale OneFS, versions 8.2.x-9.2.x, contain broken or risky cryptographic algorithm. A remote unprivileged mali...
CVE-2022-31229MEDIUM4.9Dell PowerScale OneFS, 8.2.x through 9.3.0.x, contain an error message with sensitive information. An administrator coul...
CVE-2022-31108MEDIUM6.1Mermaid is a JavaScript based diagramming and charting tool that uses Markdown-inspired text definitions and a renderer ...
CVE-2022-31106CRITICAL9.8Underscore.deep is a collection of Underscore mixins that operate on nested objects. Versions of `underscore.deep` prior...
CVE-2022-31068MEDIUM5.3GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking an...
CVE-2022-31061CRITICAL9.8GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking an...
CVE-2022-31056CRITICAL9.8GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking an...
CVE-2022-2145HIGH7.8Cloudflare WARP client for Windows (up to v. 2022.5.309.0) allowed creation of mount points from its ProgramData folder....
CVE-2022-28621HIGH7.5A remote disclosure of sensitive information vulnerability was discovered in HPE NonStop DSM/SCM version: T6031H03^ADP. ...
CVE-2022-33108HIGH7.8XPDF v4.04 was discovered to contain a stack overflow vulnerability via the Object::Copy class of object.cc files.
CVE-2022-31052MEDIUM6.5Synapse is an open source home server implementation for the Matrix chat network. In versions prior to 1.61.1 URL previe...
CVE-2022-0987LOW3.3A flaw was found in PackageKit in the way some of the methods exposed by the Transaction interface examines files. This ...
CVE-2022-0085MEDIUM5.3Server-Side Request Forgery (SSRF) in GitHub repository dompdf/dompdf prior to 2.0.0.
CVE-2022-30563HIGH7.4When an attacker uses a man-in-the-middle attack to sniff the request packets with success logging in through ONVIF, he ...
CVE-2022-30562MEDIUM4.7If the user enables the https function on the device, an attacker can modify the user’s request data packet through a ma...
CVE-2022-30561MEDIUM5.9When an attacker uses a man-in-the-middle attack to sniff the request packets with success logging in, the attacker coul...
CVE-2022-30560HIGH7.4When an attacker obtaining the administrative account and password, or through a man-in-the-middle attack, the attacker ...
CVE-2022-23763HIGH8.8Origin validation error vulnerability in NeoRS’s ActiveX moudle allows attackers to download and execute arbitrary files...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now