2022 CVE Vulnerabilities
27,552 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-22426 | LOW | 3.3 | 0.2% | Jun 10, 2022 | IBM Spectrum Copy Data Management Admin 2.2.0.0 through 2.2.15.0 could allow a local attacker to bypass authentication r... |
| CVE-2022-32978 | MEDIUM | 6.5 | 0.8% | Jun 10, 2022 | There is an assertion failure in SingleComponentLSScan::ParseMCU in singlecomponentlsscan.cpp in libjpeg before 1.64 via... |
| CVE-2022-31788 | CRITICAL | 9.8 | 13.9% | Jun 10, 2022 | IdeaLMS 2022 allows SQL injection via the IdeaLMS/ChatRoom/ClassAccessControl/6?isBigBlueButton=0&ClassID= pathname. |
| CVE-2022-27502 | HIGH | 7.8 | 0.7% | Jun 10, 2022 | RealVNC VNC Server 6.9.0 through 5.1.0 for Windows allows local privilege escalation because an installer repair operati... |
| CVE-2022-32563 | CRITICAL | 9.8 | 0.7% | Jun 10, 2022 | An issue was discovered in Couchbase Sync Gateway 3.x before 3.0.2. Admin credentials are not verified when using X.509 ... |
| CVE-2022-31043 | HIGH | 7.5 | 1.8% | Jun 10, 2022 | Guzzle is an open source PHP HTTP client. In affected versions `Authorization` headers on requests are sensitive informa... |
| CVE-2022-31042 | HIGH | 7.5 | 1.8% | Jun 10, 2022 | Guzzle is an open source PHP HTTP client. In affected versions the `Cookie` headers on requests are sensitive informatio... |
| CVE-2022-31045 | CRITICAL | 9.8 | 1.0% | Jun 9, 2022 | Istio is an open platform to connect, manage, and secure microservices. In affected versions ill-formed headers sent to ... |
| CVE-2022-30703 | HIGH | 7.8 | 0.3% | Jun 9, 2022 | Trend Micro Security 2021 and 2022 (Consumer) is vulnerable to an exposed dangerous method vulnerability that could allo... |
| CVE-2022-30702 | MEDIUM | 5.5 | 0.3% | Jun 9, 2022 | Trend Micro Security 2022 and 2021 (Consumer) is vulnerable to an Out-Of-Bounds Read Information Disclosure vulnerabilit... |
| CVE-2022-21499 | MEDIUM | 6.7 | 0.6% | Jun 9, 2022 | KGDB and KDB allow read and write access to kernel memory, and thus should be restricted during lockdown. An attacker wi... |
| CVE-2022-31051 | HIGH | 7.5 | 1.6% | Jun 9, 2022 | semantic-release is an open source npm package for automated version management and package publishing. In affected vers... |
| CVE-2022-31033 | HIGH | 7.5 | 1.4% | Jun 9, 2022 | The Mechanize library is used for automating interaction with websites. Mechanize automatically stores and sends cookies... |
| CVE-2022-29250 | MEDIUM | 6.5 | 0.7% | Jun 9, 2022 | GLPI is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and... |
| CVE-2022-29228 | HIGH | 7.5 | 1.2% | Jun 9, 2022 | Envoy is a cloud-native high-performance proxy. In versions prior to 1.22.1 the OAuth filter would try to invoke the rem... |
| CVE-2022-29227 | HIGH | 7.5 | 1.1% | Jun 9, 2022 | Envoy is a cloud-native high-performance edge/middle/service proxy. In versions prior to 1.22.1 if Envoy attempts to sen... |
| CVE-2022-29226 | CRITICAL | 9.1 | 1.2% | Jun 9, 2022 | Envoy is a cloud-native high-performance proxy. In versions prior to 1.22.1 the OAuth filter implementation does not inc... |
| CVE-2022-29225 | HIGH | 7.5 | 1.4% | Jun 9, 2022 | Envoy is a cloud-native high-performance proxy. In versions prior to 1.22.1 secompressors accumulate decompressed data i... |
| CVE-2022-30898 | MEDIUM | 6.5 | 0.5% | Jun 9, 2022 | A Cross-site request forgery (CSRF) vulnerability in Cscms music portal system v4.2 allows remote attackers to change th... |
| CVE-2022-29224 | MEDIUM | 5.9 | 0.9% | Jun 9, 2022 | Envoy is a cloud-native high-performance proxy. Versions of envoy prior to 1.22.1 are subject to a segmentation fault in... |
| CVE-2022-24876 | MEDIUM | 5.4 | 0.5% | Jun 9, 2022 | GLPI is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and... |
| CVE-2022-31813 | CRITICAL | 9.8 | 3.1% | Jun 9, 2022 | Apache HTTP Server 2.4.53 and earlier may not send the X-Forwarded-* headers to the origin server based on client side C... |
| CVE-2022-31038 | MEDIUM | 5.4 | 0.7% | Jun 9, 2022 | Gogs is an open source self-hosted Git service. In versions of gogs prior to 0.12.9 `DisplayName` does not filter charac... |
| CVE-2022-30556 | HIGH | 7.5 | 4.7% | Jun 9, 2022 | Apache HTTP Server 2.4.53 and earlier may return lengths to applications calling r:wsread() that point past the end of t... |
| CVE-2022-30522 | HIGH | 7.5 | 90.4% | Jun 9, 2022 | If Apache HTTP Server 2.4.53 is configured to do transformations with mod_sed in contexts where the input to mod_sed may... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now