2022 CVE Vulnerabilities

27,552 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-23342MEDIUM5.3The Hyland Onbase Application Server releases prior to 20.3.58.1000 and OnBase releases 21.1.1.1000 through 21.1.15.1000...
CVE-2022-33139CRITICAL9.8A vulnerability has been identified in Cerberus DMS (All versions), Desigo CC (All versions), Desigo CC Compact (All ver...
CVE-2022-33119MEDIUM6.1NUUO Network Video Recorder NVRsolo v03.06.02 was discovered to contain a reflected cross-site scripting (XSS) vulnerabi...
CVE-2022-32414MEDIUM5.5Nginx NJS v0.7.2 was discovered to contain a segmentation violation in the function njs_vmcode_interpreter at src/njs_vm...
CVE-2022-31374CRITICAL9.8An arbitrary file upload vulnerability /images/background/1.php in of SolarView Compact 6.0 allows attackers to execute ...
CVE-2022-31373MEDIUM6.1SolarView Compact v6.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component Solar_AiCo...
CVE-2022-31307MEDIUM5.5Nginx NJS v0.7.2 was discovered to contain a segmentation violation in the function njs_string_offset at src/njs_string....
CVE-2022-31306MEDIUM5.5Nginx NJS v0.7.2 was discovered to contain a segmentation violation in the function njs_array_convert_to_slow_array at s...
CVE-2022-31303MEDIUM5.4maccms10 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Server Group text field.
CVE-2022-31302MEDIUM5.4maccms8 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Server Group text field.
CVE-2022-23074In Recipes, versions 0.17.0 through 1.2.5 are vulnerable to Stored Cross-Site Scripting (XSS), in the ‘Name’ field of Ke...
CVE-2022-23073In Recipes, versions 1.0.5 through 1.2.5 are vulnerable to Stored Cross-Site Scripting (XSS), in copy to clipboard funct...
CVE-2022-31801CRITICAL9.8An unauthenticated, remote attacker could upload malicious logic to the devices based on ProConOS/ProConOS eCLR in order...
CVE-2022-31800CRITICAL9.8An unauthenticated, remote attacker could upload malicious logic to devices based on ProConOS/ProConOS eCLR in order to ...
CVE-2022-23072In Recipes, versions 1.0.5 through 1.2.5 are vulnerable to Stored Cross-Site Scripting (XSS), in “Add to Cart” functiona...
CVE-2022-31062MEDIUM5.3### Impact A plugin public script can be used to read content of system files. ### Patches Upgrade to version 1.0.2. ###...
CVE-2022-2128CRITICAL9.8Unrestricted Upload of File with Dangerous Type in GitHub repository polonel/trudesk prior to 1.2.4.
CVE-2022-22414MEDIUM5.5IBM Robotic Process Automation 21.0.2 could allow a local user to obtain sensitive web service configuration credentials...
CVE-2022-22318CRITICAL9.8IBM Curam Social Program Management 8.0.0 and 8.0.1 does not invalidate session after logout which could allow an authen...
CVE-2022-22317CRITICAL9.8IBM Curam Social Program Management 8.0.0 and 8.0.1 does not invalidate session after logout which could allow an authen...
CVE-2022-33913HIGH7.5In Mahara 21.04 before 21.04.6, 21.10 before 21.10.4, and 22.04.2, files can sometimes be downloaded through thumb.php w...
CVE-2022-32983MEDIUM5.3Knot Resolver through 5.5.1 may allow DNS cache poisoning when there is an attempt to limit forwarding actions by filter...
CVE-2022-31795CRITICAL9.8An issue was discovered on Fujitsu ETERNUS CentricStor CS8000 (Control Center) devices before 8.1A SP02 P04. The vulnera...
CVE-2022-31794CRITICAL9.8An issue was discovered on Fujitsu ETERNUS CentricStor CS8000 (Control Center) devices before 8.1A SP02 P04. The vulnera...
CVE-2022-2134MEDIUM6.5Allocation of Resources Without Limits or Throttling in GitHub repository inventree/inventree prior to 0.8.0.

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now