2022 CVE Vulnerabilities

27,552 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-22426LOW3.3IBM Spectrum Copy Data Management Admin 2.2.0.0 through 2.2.15.0 could allow a local attacker to bypass authentication r...
CVE-2022-32978MEDIUM6.5There is an assertion failure in SingleComponentLSScan::ParseMCU in singlecomponentlsscan.cpp in libjpeg before 1.64 via...
CVE-2022-31788CRITICAL9.8IdeaLMS 2022 allows SQL injection via the IdeaLMS/ChatRoom/ClassAccessControl/6?isBigBlueButton=0&ClassID= pathname.
CVE-2022-27502HIGH7.8RealVNC VNC Server 6.9.0 through 5.1.0 for Windows allows local privilege escalation because an installer repair operati...
CVE-2022-32563CRITICAL9.8An issue was discovered in Couchbase Sync Gateway 3.x before 3.0.2. Admin credentials are not verified when using X.509 ...
CVE-2022-31043HIGH7.5Guzzle is an open source PHP HTTP client. In affected versions `Authorization` headers on requests are sensitive informa...
CVE-2022-31042HIGH7.5Guzzle is an open source PHP HTTP client. In affected versions the `Cookie` headers on requests are sensitive informatio...
CVE-2022-31045CRITICAL9.8Istio is an open platform to connect, manage, and secure microservices. In affected versions ill-formed headers sent to ...
CVE-2022-30703HIGH7.8Trend Micro Security 2021 and 2022 (Consumer) is vulnerable to an exposed dangerous method vulnerability that could allo...
CVE-2022-30702MEDIUM5.5Trend Micro Security 2022 and 2021 (Consumer) is vulnerable to an Out-Of-Bounds Read Information Disclosure vulnerabilit...
CVE-2022-21499MEDIUM6.7KGDB and KDB allow read and write access to kernel memory, and thus should be restricted during lockdown. An attacker wi...
CVE-2022-31051HIGH7.5semantic-release is an open source npm package for automated version management and package publishing. In affected vers...
CVE-2022-31033HIGH7.5The Mechanize library is used for automating interaction with websites. Mechanize automatically stores and sends cookies...
CVE-2022-29250MEDIUM6.5GLPI is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and...
CVE-2022-29228HIGH7.5Envoy is a cloud-native high-performance proxy. In versions prior to 1.22.1 the OAuth filter would try to invoke the rem...
CVE-2022-29227HIGH7.5Envoy is a cloud-native high-performance edge/middle/service proxy. In versions prior to 1.22.1 if Envoy attempts to sen...
CVE-2022-29226CRITICAL9.1Envoy is a cloud-native high-performance proxy. In versions prior to 1.22.1 the OAuth filter implementation does not inc...
CVE-2022-29225HIGH7.5Envoy is a cloud-native high-performance proxy. In versions prior to 1.22.1 secompressors accumulate decompressed data i...
CVE-2022-30898MEDIUM6.5A Cross-site request forgery (CSRF) vulnerability in Cscms music portal system v4.2 allows remote attackers to change th...
CVE-2022-29224MEDIUM5.9Envoy is a cloud-native high-performance proxy. Versions of envoy prior to 1.22.1 are subject to a segmentation fault in...
CVE-2022-24876MEDIUM5.4GLPI is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and...
CVE-2022-31813CRITICAL9.8Apache HTTP Server 2.4.53 and earlier may not send the X-Forwarded-* headers to the origin server based on client side C...
CVE-2022-31038MEDIUM5.4Gogs is an open source self-hosted Git service. In versions of gogs prior to 0.12.9 `DisplayName` does not filter charac...
CVE-2022-30556HIGH7.5Apache HTTP Server 2.4.53 and earlier may return lengths to applications calling r:wsread() that point past the end of t...
CVE-2022-30522HIGH7.5If Apache HTTP Server 2.4.53 is configured to do transformations with mod_sed in contexts where the input to mod_sed may...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now