2022 CVE Vulnerabilities
27,552 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-29301 | — | — | — | Jun 23, 2022 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2021-20660. Reason: This candidate is a reservation d... |
| CVE-2022-29299 | — | — | — | Jun 23, 2022 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2021-20660. Reason: This candidate is a reservation d... |
| CVE-2022-22980 | CRITICAL | 9.8 | 16.9% | Jun 23, 2022 | A Spring Data MongoDB application is vulnerable to SpEL Injection when using @Query or @Aggregation-annotated query meth... |
| CVE-2022-22967 | HIGH | 8.8 | 1.9% | Jun 23, 2022 | An issue was discovered in SaltStack Salt in versions before 3002.9, 3003.5, 3004.2. PAM auth fails to reject locked acc... |
| CVE-2022-2175 | HIGH | 7.8 | 1.3% | Jun 23, 2022 | Buffer Over-read in GitHub repository vim/vim prior to 8.2. |
| CVE-2022-34305 | MEDIUM | 6.1 | 6.2% | Jun 23, 2022 | In Apache Tomcat 10.1.0-M1 to 10.1.0-M16, 10.0.0-M1 to 10.0.22, 9.0.30 to 9.0.64 and 8.5.50 to 8.5.81 the Form authentic... |
| CVE-2022-31009 | MEDIUM | 6.5 | 0.6% | Jun 23, 2022 | wire-ios is an iOS client for the Wire secure messaging application. Invalid accent colors of Wire communication partner... |
| CVE-2022-32159 | — | — | 0.8% | Jun 22, 2022 | In openlibrary versions deploy-2016-07-0 through deploy-2021-12-22 are vulnerable to Stored XSS. |
| CVE-2022-23081 | — | — | 0.9% | Jun 22, 2022 | In openlibrary versions deploy-2016-07-0 through deploy-2021-12-22 are vulnerable to Reflected XSS. |
| CVE-2022-23080 | MEDIUM | 5 | 0.8% | Jun 22, 2022 | In directus versions v9.0.0-beta.2 through 9.6.0 are vulnerable to server-side request forgery (SSRF) in the media uploa... |
| CVE-2022-32549 | MEDIUM | 5.3 | 2.2% | Jun 22, 2022 | Apache Sling Commons Log <= 5.4.0 and Apache Sling API <= 2.25.0 are vulnerable to log injection. The ability to forge l... |
| CVE-2022-20651 | MEDIUM | 5.5 | 0.4% | Jun 22, 2022 | A vulnerability in the logging component of Cisco Adaptive Security Device Manager (ASDM) could allow an authenticated, ... |
| CVE-2022-23079 | — | — | 1.3% | Jun 22, 2022 | In motor-admin versions 0.0.1 through 0.2.56 are vulnerable to host header injection in the password reset functionality... |
| CVE-2022-2174 | MEDIUM | 6.1 | 2.8% | Jun 22, 2022 | Cross-site Scripting (XSS) - Reflected in GitHub repository microweber/microweber prior to 1.2.18. |
| CVE-2022-23078 | — | — | 1.1% | Jun 22, 2022 | In habitica versions v4.119.0 through v4.232.2 are vulnerable to open redirect via the login page. |
| CVE-2022-23077 | MEDIUM | 6.1 | 0.7% | Jun 22, 2022 | In habitica versions v4.119.0 through v4.232.2 are vulnerable to DOM XSS via the login page. |
| CVE-2022-31248 | MEDIUM | 5.3 | 1.0% | Jun 22, 2022 | A Observable Response Discrepancy vulnerability in spacewalk-java of SUSE Manager Server 4.1, SUSE Manager Server 4.2 al... |
| CVE-2022-21952 | HIGH | 7.5 | 1.4% | Jun 22, 2022 | A Missing Authentication for Critical Function vulnerability in spacewalk-java of SUSE Manager Server 4.1, SUSE Manager ... |
| CVE-2022-23055 | — | — | 1.1% | Jun 22, 2022 | In ERPNext, versions v11.0.0-beta through v13.0.2 are vulnerable to Missing Authorization, in the chat rooms functionali... |
| CVE-2022-23058 | — | — | 0.8% | Jun 22, 2022 | ERPNext in versions v12.0.9-v13.0.3 are affected by a stored XSS vulnerability that allows low privileged users to store... |
| CVE-2022-23057 | MEDIUM | 5.4 | 0.6% | Jun 22, 2022 | In ERPNext, versions v12.0.9--v13.0.3 are vulnerable to Stored Cross-Site-Scripting (XSS), due to user input not being v... |
| CVE-2022-23056 | — | — | 0.8% | Jun 22, 2022 | In ERPNext, versions v13.0.0-beta.13 through v13.30.0 are vulnerable to Stored XSS at the Patient History page which all... |
| CVE-2022-31095 | MEDIUM | 6.5 | 0.5% | Jun 21, 2022 | discourse-chat is a chat plugin for the Discourse application. Versions prior to 0.4 are vulnerable to an exposure of se... |
| CVE-2022-34008 | HIGH | 7.8 | 0.5% | Jun 21, 2022 | Comodo Antivirus 12.2.2.8012 has a quarantine flaw that allows privilege escalation. To escalate privilege, a low-privil... |
| CVE-2022-33995 | HIGH | 7.5 | 1.6% | Jun 21, 2022 | A path traversal issue in entry attachments in Devolutions Remote Desktop Manager before 2022.2 allows attackers to crea... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now