2022 CVE Vulnerabilities
27,552 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-23342 | MEDIUM | 5.3 | 1.2% | Jun 21, 2022 | The Hyland Onbase Application Server releases prior to 20.3.58.1000 and OnBase releases 21.1.1.1000 through 21.1.15.1000... |
| CVE-2022-33139 | CRITICAL | 9.8 | 1.2% | Jun 21, 2022 | A vulnerability has been identified in Cerberus DMS (All versions), Desigo CC (All versions), Desigo CC Compact (All ver... |
| CVE-2022-33119 | MEDIUM | 6.1 | 1.5% | Jun 21, 2022 | NUUO Network Video Recorder NVRsolo v03.06.02 was discovered to contain a reflected cross-site scripting (XSS) vulnerabi... |
| CVE-2022-32414 | MEDIUM | 5.5 | 0.6% | Jun 21, 2022 | Nginx NJS v0.7.2 was discovered to contain a segmentation violation in the function njs_vmcode_interpreter at src/njs_vm... |
| CVE-2022-31374 | CRITICAL | 9.8 | 2.5% | Jun 21, 2022 | An arbitrary file upload vulnerability /images/background/1.php in of SolarView Compact 6.0 allows attackers to execute ... |
| CVE-2022-31373 | MEDIUM | 6.1 | 5.1% | Jun 21, 2022 | SolarView Compact v6.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component Solar_AiCo... |
| CVE-2022-31307 | MEDIUM | 5.5 | 0.6% | Jun 21, 2022 | Nginx NJS v0.7.2 was discovered to contain a segmentation violation in the function njs_string_offset at src/njs_string.... |
| CVE-2022-31306 | MEDIUM | 5.5 | 0.6% | Jun 21, 2022 | Nginx NJS v0.7.2 was discovered to contain a segmentation violation in the function njs_array_convert_to_slow_array at s... |
| CVE-2022-31303 | MEDIUM | 5.4 | 0.4% | Jun 21, 2022 | maccms10 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Server Group text field. |
| CVE-2022-31302 | MEDIUM | 5.4 | 0.4% | Jun 21, 2022 | maccms8 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Server Group text field. |
| CVE-2022-23074 | — | — | 0.8% | Jun 21, 2022 | In Recipes, versions 0.17.0 through 1.2.5 are vulnerable to Stored Cross-Site Scripting (XSS), in the ‘Name’ field of Ke... |
| CVE-2022-23073 | — | — | 0.8% | Jun 21, 2022 | In Recipes, versions 1.0.5 through 1.2.5 are vulnerable to Stored Cross-Site Scripting (XSS), in copy to clipboard funct... |
| CVE-2022-31801 | CRITICAL | 9.8 | 1.0% | Jun 21, 2022 | An unauthenticated, remote attacker could upload malicious logic to the devices based on ProConOS/ProConOS eCLR in order... |
| CVE-2022-31800 | CRITICAL | 9.8 | 1.5% | Jun 21, 2022 | An unauthenticated, remote attacker could upload malicious logic to devices based on ProConOS/ProConOS eCLR in order to ... |
| CVE-2022-23072 | — | — | 0.8% | Jun 21, 2022 | In Recipes, versions 1.0.5 through 1.2.5 are vulnerable to Stored Cross-Site Scripting (XSS), in “Add to Cart” functiona... |
| CVE-2022-31062 | MEDIUM | 5.3 | 5.5% | Jun 20, 2022 | ### Impact A plugin public script can be used to read content of system files. ### Patches Upgrade to version 1.0.2. ###... |
| CVE-2022-2128 | CRITICAL | 9.8 | 2.6% | Jun 20, 2022 | Unrestricted Upload of File with Dangerous Type in GitHub repository polonel/trudesk prior to 1.2.4. |
| CVE-2022-22414 | MEDIUM | 5.5 | 0.2% | Jun 20, 2022 | IBM Robotic Process Automation 21.0.2 could allow a local user to obtain sensitive web service configuration credentials... |
| CVE-2022-22318 | CRITICAL | 9.8 | 0.4% | Jun 20, 2022 | IBM Curam Social Program Management 8.0.0 and 8.0.1 does not invalidate session after logout which could allow an authen... |
| CVE-2022-22317 | CRITICAL | 9.8 | 0.5% | Jun 20, 2022 | IBM Curam Social Program Management 8.0.0 and 8.0.1 does not invalidate session after logout which could allow an authen... |
| CVE-2022-33913 | HIGH | 7.5 | 1.0% | Jun 20, 2022 | In Mahara 21.04 before 21.04.6, 21.10 before 21.10.4, and 22.04.2, files can sometimes be downloaded through thumb.php w... |
| CVE-2022-32983 | MEDIUM | 5.3 | 0.8% | Jun 20, 2022 | Knot Resolver through 5.5.1 may allow DNS cache poisoning when there is an attempt to limit forwarding actions by filter... |
| CVE-2022-31795 | CRITICAL | 9.8 | 2.8% | Jun 20, 2022 | An issue was discovered on Fujitsu ETERNUS CentricStor CS8000 (Control Center) devices before 8.1A SP02 P04. The vulnera... |
| CVE-2022-31794 | CRITICAL | 9.8 | 2.8% | Jun 20, 2022 | An issue was discovered on Fujitsu ETERNUS CentricStor CS8000 (Control Center) devices before 8.1A SP02 P04. The vulnera... |
| CVE-2022-2134 | MEDIUM | 6.5 | 0.8% | Jun 20, 2022 | Allocation of Resources Without Limits or Throttling in GitHub repository inventree/inventree prior to 0.8.0. |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now