2022 CVE Vulnerabilities

27,552 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-29301Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2021-20660. Reason: This candidate is a reservation d...
CVE-2022-29299Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2021-20660. Reason: This candidate is a reservation d...
CVE-2022-22980CRITICAL9.8A Spring Data MongoDB application is vulnerable to SpEL Injection when using @Query or @Aggregation-annotated query meth...
CVE-2022-22967HIGH8.8An issue was discovered in SaltStack Salt in versions before 3002.9, 3003.5, 3004.2. PAM auth fails to reject locked acc...
CVE-2022-2175HIGH7.8Buffer Over-read in GitHub repository vim/vim prior to 8.2.
CVE-2022-34305MEDIUM6.1In Apache Tomcat 10.1.0-M1 to 10.1.0-M16, 10.0.0-M1 to 10.0.22, 9.0.30 to 9.0.64 and 8.5.50 to 8.5.81 the Form authentic...
CVE-2022-31009MEDIUM6.5wire-ios is an iOS client for the Wire secure messaging application. Invalid accent colors of Wire communication partner...
CVE-2022-32159In openlibrary versions deploy-2016-07-0 through deploy-2021-12-22 are vulnerable to Stored XSS.
CVE-2022-23081In openlibrary versions deploy-2016-07-0 through deploy-2021-12-22 are vulnerable to Reflected XSS.
CVE-2022-23080MEDIUM5In directus versions v9.0.0-beta.2 through 9.6.0 are vulnerable to server-side request forgery (SSRF) in the media uploa...
CVE-2022-32549MEDIUM5.3Apache Sling Commons Log <= 5.4.0 and Apache Sling API <= 2.25.0 are vulnerable to log injection. The ability to forge l...
CVE-2022-20651MEDIUM5.5A vulnerability in the logging component of Cisco Adaptive Security Device Manager (ASDM) could allow an authenticated, ...
CVE-2022-23079In motor-admin versions 0.0.1 through 0.2.56 are vulnerable to host header injection in the password reset functionality...
CVE-2022-2174MEDIUM6.1Cross-site Scripting (XSS) - Reflected in GitHub repository microweber/microweber prior to 1.2.18.
CVE-2022-23078In habitica versions v4.119.0 through v4.232.2 are vulnerable to open redirect via the login page.
CVE-2022-23077MEDIUM6.1In habitica versions v4.119.0 through v4.232.2 are vulnerable to DOM XSS via the login page.
CVE-2022-31248MEDIUM5.3A Observable Response Discrepancy vulnerability in spacewalk-java of SUSE Manager Server 4.1, SUSE Manager Server 4.2 al...
CVE-2022-21952HIGH7.5A Missing Authentication for Critical Function vulnerability in spacewalk-java of SUSE Manager Server 4.1, SUSE Manager ...
CVE-2022-23055In ERPNext, versions v11.0.0-beta through v13.0.2 are vulnerable to Missing Authorization, in the chat rooms functionali...
CVE-2022-23058ERPNext in versions v12.0.9-v13.0.3 are affected by a stored XSS vulnerability that allows low privileged users to store...
CVE-2022-23057MEDIUM5.4In ERPNext, versions v12.0.9--v13.0.3 are vulnerable to Stored Cross-Site-Scripting (XSS), due to user input not being v...
CVE-2022-23056In ERPNext, versions v13.0.0-beta.13 through v13.30.0 are vulnerable to Stored XSS at the Patient History page which all...
CVE-2022-31095MEDIUM6.5discourse-chat is a chat plugin for the Discourse application. Versions prior to 0.4 are vulnerable to an exposure of se...
CVE-2022-34008HIGH7.8Comodo Antivirus 12.2.2.8012 has a quarantine flaw that allows privilege escalation. To escalate privilege, a low-privil...
CVE-2022-33995HIGH7.5A path traversal issue in entry attachments in Devolutions Remote Desktop Manager before 2022.2 allows attackers to crea...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now