2022 CVE Vulnerabilities

27,552 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-31090HIGH7.7Guzzle, an extensible PHP HTTP client. `Authorization` headers on requests are sensitive information. In affected versio...
CVE-2022-33116MEDIUM6.5An issue in the jmpath variable in /modules/mindmap/index.php of GUnet Open eClass Platform (aka openeclass) v3.12.4 and...
CVE-2022-33005MEDIUM6.1A cross-site scripting (XSS) vulnerability in the System Settings/IOT Settings module of Delta Electronics DIAEnergie v1...
CVE-2022-31094MEDIUM6.1ScratchTools is a web extension designed to make interacting with the Scratch programming language community (Scratching...
CVE-2022-31089HIGH7.5Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. In affected vers...
CVE-2022-31088MEDIUM5.3LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP d...
CVE-2022-31087HIGH7.8LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP d...
CVE-2022-31086HIGH8.8LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP d...
CVE-2022-31085MEDIUM6.1LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP d...
CVE-2022-31084HIGH8.1LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP d...
CVE-2022-31082CRITICAL9.8GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking an...
CVE-2022-31081MEDIUM6.5HTTP::Daemon is a simple http server class written in perl. Versions prior to 6.15 are subject to a vulnerability which ...
CVE-2022-31077MEDIUM5.7KubeEdge is built upon Kubernetes and extends native containerized application orchestration and device management to ho...
CVE-2022-31076MEDIUM5.7KubeEdge is built upon Kubernetes and extends native containerized application orchestration and device management to ho...
CVE-2022-31065MEDIUM6.1BigBlueButton is an open source web conferencing system. In affected versions an attacker can embed malicious JS in thei...
CVE-2022-31064MEDIUM5.4BigBlueButton is an open source web conferencing system. Users in meetings with private chat enabled are vulnerable to a...
CVE-2022-31057MEDIUM5.4Shopware is an open source e-commerce software made in Germany. Versions of Shopware 5 prior to version 5.7.12 are subje...
CVE-2022-31039MEDIUM5.3Greenlight is a simple front-end interface for your BigBlueButton server. In affected versions an attacker can view any ...
CVE-2022-31036MEDIUM4.3Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. All versions of Argo CD starting with v1.3.0 a...
CVE-2022-31035MEDIUM5.4Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. All versions of Argo CD starting with v1.0.0 a...
CVE-2022-31034HIGH8.1Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. All versions of Argo CD starting with v0.11.0 ...
CVE-2022-2221MEDIUM6.5Information Exposure vulnerability in My Account Settings of Devolutions Remote Desktop Manager before 2022.1.8 allows a...
CVE-2022-28622HIGH7.5A potential security vulnerability has been identified in HPE StoreOnce Software. The SSH server supports weak key excha...
CVE-2022-28172MEDIUM6.1The web module in some Hikvision Hybrid SAN/Cluster Storage products have the following security vulnerability. Due to t...
CVE-2022-28171CRITICAL9.8The web module in some Hikvision Hybrid SAN/Cluster Storage products have the following security vulnerability. Due to t...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now