2022 CVE Vulnerabilities
27,552 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-2037 | HIGH | 8 | 1.1% | Jun 9, 2022 | Excessive Attack Surface in GitHub repository tooljet/tooljet prior to v1.16.0. |
| CVE-2022-2036 | MEDIUM | 5.4 | 0.8% | Jun 9, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository francoisjacquet/rosariosis prior to 9.0.1. |
| CVE-2022-2029 | MEDIUM | 5.4 | 0.7% | Jun 9, 2022 | Cross-site Scripting (XSS) - DOM in GitHub repository kromitgmbh/titra prior to 0.77.0. |
| CVE-2022-2028 | MEDIUM | 5.4 | 0.7% | Jun 9, 2022 | Cross-site Scripting (XSS) - Generic in GitHub repository kromitgmbh/titra prior to 0.77.0. |
| CVE-2022-2027 | HIGH | 8 | 1.1% | Jun 9, 2022 | Improper Neutralization of Formula Elements in a CSV File in GitHub repository kromitgmbh/titra prior to 0.77.0. |
| CVE-2022-2026 | MEDIUM | 5.4 | 0.7% | Jun 9, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository kromitgmbh/titra prior to 0.77.0. |
| CVE-2022-2015 | MEDIUM | 5.4 | 0.6% | Jun 9, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository jgraph/drawio prior to 19.0.2. |
| CVE-2022-2014 | MEDIUM | 5.4 | 0.7% | Jun 9, 2022 | Code Injection in GitHub repository jgraph/drawio prior to 19.0.2. |
| CVE-2022-29404 | HIGH | 7.5 | 5.7% | Jun 9, 2022 | In Apache HTTP Server 2.4.53 and earlier, a malicious request to a lua script that calls r:parsebody(0) may cause a deni... |
| CVE-2022-28615 | CRITICAL | 9.1 | 5.7% | Jun 9, 2022 | Apache HTTP Server 2.4.53 and earlier may crash or disclose information due to a read beyond bounds in ap_strcmp_match()... |
| CVE-2022-28614 | MEDIUM | 5.3 | 4.4% | Jun 9, 2022 | The ap_rwrite() function in Apache HTTP Server 2.4.53 and earlier may read unintended memory if an attacker can cause th... |
| CVE-2022-28330 | MEDIUM | 5.3 | 3.4% | Jun 9, 2022 | Apache HTTP Server 2.4.53 and earlier on Windows may read beyond bounds when configured to process requests with the mod... |
| CVE-2022-26377 | HIGH | 7.5 | 19.0% | Jun 9, 2022 | Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in mod_proxy_ajp of Apache HTTP Se... |
| CVE-2022-26364 | MEDIUM | 6.7 | 0.5% | Jun 9, 2022 | x86 pv: Insufficient care with non-coherent mappings T[his CNA information record relates to multiple CVEs; the text exp... |
| CVE-2022-26363 | MEDIUM | 6.7 | 0.3% | Jun 9, 2022 | x86 pv: Insufficient care with non-coherent mappings T[his CNA information record relates to multiple CVEs; the text exp... |
| CVE-2022-26362 | MEDIUM | 6.4 | 0.4% | Jun 9, 2022 | x86 pv: Race condition in typeref acquisition Xen maintains a type reference count for pages, in addition to a regular r... |
| CVE-2022-25153 | HIGH | 7.8 | 0.3% | Jun 9, 2022 | The ITarian Endpoint Manage Communication Client, prior to version 6.43.41148.21120, is compiled using insecure OpenSSL ... |
| CVE-2022-25152 | HIGH | 8.8 | 1.6% | Jun 9, 2022 | The ITarian platform (SAAS / on-premise) offers the possibility to run code on agents via a function called procedures. ... |
| CVE-2022-25151 | HIGH | 7.5 | 0.8% | Jun 9, 2022 | Within the Service Desk module of the ITarian platform (SAAS and on-premise), a remote attacker can obtain sensitive inf... |
| CVE-2022-1993 | HIGH | 8.1 | 51.1% | Jun 9, 2022 | Path Traversal in GitHub repository gogs/gogs prior to 0.12.9. |
| CVE-2022-1992 | CRITICAL | 9.1 | 2.3% | Jun 9, 2022 | Path Traversal in GitHub repository gogs/gogs prior to 0.12.9. |
| CVE-2022-1986 | CRITICAL | 9.8 | 4.5% | Jun 9, 2022 | OS Command Injection in GitHub repository gogs/gogs prior to 0.12.9. |
| CVE-2022-31214 | HIGH | 7.8 | 0.4% | Jun 9, 2022 | A Privilege Context Switching issue was discovered in join.c in Firejail 0.9.68. By crafting a bogus Firejail container ... |
| CVE-2022-31031 | CRITICAL | 9.8 | 1.8% | Jun 9, 2022 | PJSIP is a free and open source multimedia communication library written in C language implementing standard based proto... |
| CVE-2022-30760 | MEDIUM | 4.3 | 0.9% | Jun 9, 2022 | An Insecure Direct Object Reference (IDOR) issue in fn2Web in ihb eG FlexNow before 2.04.09.016 allows remote authentica... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now