2022 CVE Vulnerabilities

27,552 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-2037HIGH8Excessive Attack Surface in GitHub repository tooljet/tooljet prior to v1.16.0.
CVE-2022-2036MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository francoisjacquet/rosariosis prior to 9.0.1.
CVE-2022-2029MEDIUM5.4Cross-site Scripting (XSS) - DOM in GitHub repository kromitgmbh/titra prior to 0.77.0.
CVE-2022-2028MEDIUM5.4Cross-site Scripting (XSS) - Generic in GitHub repository kromitgmbh/titra prior to 0.77.0.
CVE-2022-2027HIGH8Improper Neutralization of Formula Elements in a CSV File in GitHub repository kromitgmbh/titra prior to 0.77.0.
CVE-2022-2026MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository kromitgmbh/titra prior to 0.77.0.
CVE-2022-2015MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository jgraph/drawio prior to 19.0.2.
CVE-2022-2014MEDIUM5.4Code Injection in GitHub repository jgraph/drawio prior to 19.0.2.
CVE-2022-29404HIGH7.5In Apache HTTP Server 2.4.53 and earlier, a malicious request to a lua script that calls r:parsebody(0) may cause a deni...
CVE-2022-28615CRITICAL9.1Apache HTTP Server 2.4.53 and earlier may crash or disclose information due to a read beyond bounds in ap_strcmp_match()...
CVE-2022-28614MEDIUM5.3The ap_rwrite() function in Apache HTTP Server 2.4.53 and earlier may read unintended memory if an attacker can cause th...
CVE-2022-28330MEDIUM5.3Apache HTTP Server 2.4.53 and earlier on Windows may read beyond bounds when configured to process requests with the mod...
CVE-2022-26377HIGH7.5Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in mod_proxy_ajp of Apache HTTP Se...
CVE-2022-26364MEDIUM6.7x86 pv: Insufficient care with non-coherent mappings T[his CNA information record relates to multiple CVEs; the text exp...
CVE-2022-26363MEDIUM6.7x86 pv: Insufficient care with non-coherent mappings T[his CNA information record relates to multiple CVEs; the text exp...
CVE-2022-26362MEDIUM6.4x86 pv: Race condition in typeref acquisition Xen maintains a type reference count for pages, in addition to a regular r...
CVE-2022-25153HIGH7.8The ITarian Endpoint Manage Communication Client, prior to version 6.43.41148.21120, is compiled using insecure OpenSSL ...
CVE-2022-25152HIGH8.8The ITarian platform (SAAS / on-premise) offers the possibility to run code on agents via a function called procedures. ...
CVE-2022-25151HIGH7.5Within the Service Desk module of the ITarian platform (SAAS and on-premise), a remote attacker can obtain sensitive inf...
CVE-2022-1993HIGH8.1Path Traversal in GitHub repository gogs/gogs prior to 0.12.9.
CVE-2022-1992CRITICAL9.1Path Traversal in GitHub repository gogs/gogs prior to 0.12.9.
CVE-2022-1986CRITICAL9.8OS Command Injection in GitHub repository gogs/gogs prior to 0.12.9.
CVE-2022-31214HIGH7.8A Privilege Context Switching issue was discovered in join.c in Firejail 0.9.68. By crafting a bogus Firejail container ...
CVE-2022-31031CRITICAL9.8PJSIP is a free and open source multimedia communication library written in C language implementing standard based proto...
CVE-2022-30760MEDIUM4.3An Insecure Direct Object Reference (IDOR) issue in fn2Web in ihb eG FlexNow before 2.04.09.016 allows remote authentica...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now