2022 CVE Vulnerabilities
27,552 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-2020 | MEDIUM | 4.8 | 0.6% | Jun 9, 2022 | A vulnerability, which was classified as problematic, has been found in SourceCodester Prison Management System 1.0. Aff... |
| CVE-2022-2019 | HIGH | 7.5 | 0.7% | Jun 9, 2022 | A vulnerability classified as critical was found in SourceCodester Prison Management System 1.0. Affected by this vulner... |
| CVE-2022-2018 | HIGH | 7.2 | 0.8% | Jun 9, 2022 | A vulnerability classified as critical has been found in SourceCodester Prison Management System 1.0. Affected is an unk... |
| CVE-2022-2017 | HIGH | 7.2 | 0.7% | Jun 9, 2022 | A vulnerability was found in SourceCodester Prison Management System 1.0. It has been rated as critical. This issue affe... |
| CVE-2022-2016 | MEDIUM | 5.4 | 0.6% | Jun 9, 2022 | Cross-site Scripting (XSS) - Reflected in GitHub repository neorazorx/facturascripts prior to 2022.1. |
| CVE-2022-2000 | HIGH | 7.8 | 1.5% | Jun 9, 2022 | Out-of-bounds Write in GitHub repository vim/vim prior to 8.2. |
| CVE-2022-24969 | MEDIUM | 6.1 | 1.7% | Jun 9, 2022 | bypass CVE-2021-25640 > In Apache Dubbo prior to 2.6.12 and 2.7.15, the usage of parseURL method will lead to the bypass... |
| CVE-2022-0823 | MEDIUM | 6.2 | 0.2% | Jun 9, 2022 | An improper control of interaction frequency vulnerability in Zyxel GS1200 series switches could allow a local attacker ... |
| CVE-2022-32272 | CRITICAL | 9.8 | 8.9% | Jun 9, 2022 | OPSWAT MetaDefender Core before 5.1.2, MetaDefender ICAP before 4.12.1, and MetaDefender Email Gateway Security before 5... |
| CVE-2022-2035 | MEDIUM | 6.1 | 0.7% | Jun 9, 2022 | A reflected cross-site scripting (XSS) vulnerability exists in the playerConfUrl parameter in the /defaultui/player/mode... |
| CVE-2022-23138 | HIGH | 7.5 | 0.9% | Jun 9, 2022 | ZTE's MF297D product has cryptographic issues vulnerability. Due to the use of weak random values, the security of the d... |
| CVE-2022-1998 | HIGH | 7.8 | 0.3% | Jun 9, 2022 | A use after free in the Linux kernel File System notify functionality was found in the way user triggers copy_info_recor... |
| CVE-2022-31830 | CRITICAL | 9.1 | 14.6% | Jun 9, 2022 | Kity Minder v1.3.5 was discovered to contain a Server-Side Request Forgery (SSRF) via the init function at ImageCapture.... |
| CVE-2022-31827 | CRITICAL | 9.1 | 19.1% | Jun 9, 2022 | MonstaFTP v2.10.3 was discovered to contain a Server-Side Request Forgery (SSRF) via the function performFetchRequest at... |
| CVE-2022-31393 | CRITICAL | 9.1 | 1.0% | Jun 9, 2022 | Jizhicms v2.2.5 was discovered to contain a Server-Side Request Forgery (SSRF) vulnerability via the Index function in a... |
| CVE-2022-31390 | CRITICAL | 9.1 | 0.9% | Jun 9, 2022 | Jizhicms v2.2.5 was discovered to contain a Server-Side Request Forgery (SSRF) vulnerability via the Update function in ... |
| CVE-2022-31386 | CRITICAL | 9.1 | 1.0% | Jun 9, 2022 | A Server-Side Request Forgery (SSRF) in the getFileBinary function of nbnbk cms 3 allows attackers to force the applicat... |
| CVE-2022-31030 | MEDIUM | 5.5 | 0.4% | Jun 9, 2022 | containerd is an open source container runtime. A bug was found in the containerd's CRI implementation where programs in... |
| CVE-2022-31027 | MEDIUM | 6.5 | 0.4% | Jun 9, 2022 | OAuthenticator is an OAuth token library for the JupyerHub login handler. CILogonOAuthenticator is provided by the OAuth... |
| CVE-2022-31026 | HIGH | 7.5 | 1.0% | Jun 9, 2022 | Trilogy is a client library for MySQL. When authenticating, a malicious server could return a specially crafted authenti... |
| CVE-2022-31019 | HIGH | 7.5 | 1.5% | Jun 9, 2022 | Vapor is a server-side Swift HTTP web framework. When using automatic content decoding an attacker can craft a request b... |
| CVE-2022-29255 | HIGH | 7.5 | 1.2% | Jun 9, 2022 | Vyper is a Pythonic Smart Contract Language for the ethereum virtual machine. In versions prior to 0.3.4 when a calling ... |
| CVE-2022-29254 | MEDIUM | 6.5 | 0.6% | Jun 9, 2022 | silverstripe-omnipay is a SilverStripe integration with Omnipay PHP payments library. For a subset of Omnipay gateways (... |
| CVE-2022-24896 | MEDIUM | 4.3 | 0.7% | Jun 9, 2022 | Tuleap is a Free & Open Source Suite to manage software developments and collaboration. In versions prior to 13.7.99.239... |
| CVE-2022-32195 | MEDIUM | 6.1 | 2.3% | Jun 9, 2022 | Open edX platform before 2022-06-06 allows XSS via the "next" parameter in the logout URL. |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now