2022 CVE Vulnerabilities
27,552 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-1708 | HIGH | 7.5 | 2.8% | Jun 7, 2022 | A vulnerability was found in CRI-O that causes memory or disk space exhaustion on the node for anyone with access to the... |
| CVE-2022-31279 | — | — | — | Jun 7, 2022 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2022-31028 | HIGH | 7.5 | 2.8% | Jun 7, 2022 | MinIO is a multi-cloud object storage solution. Starting with version RELEASE.2019-09-25T18-25-51Z and ending with versi... |
| CVE-2022-31495 | MEDIUM | 6.1 | 0.9% | Jun 7, 2022 | LibreHealth EHR Base 2.0.0 allows gacl/admin/acl_admin.php return_page XSS. |
| CVE-2022-31025 | MEDIUM | 5.3 | 0.9% | Jun 7, 2022 | Discourse is an open source platform for community discussion. Prior to version 2.8.4 on the `stable` branch and 2.9.0be... |
| CVE-2022-29564 | HIGH | 7.5 | 0.9% | Jun 7, 2022 | Jamf Private Access before 2022-05-16 has Incorrect Access Control, in which an unauthorized user can reach a system in ... |
| CVE-2022-25361 | CRITICAL | 9.1 | 1.2% | Jun 7, 2022 | WatchGuard Firebox and XTM appliances allow an unauthenticated remote attacker to delete arbitrary files from a limited ... |
| CVE-2022-1991 | MEDIUM | 4.8 | 0.6% | Jun 7, 2022 | A vulnerability classified as problematic has been found in Fast Food Ordering System 1.0. Affected is the file Master.p... |
| CVE-2022-31494 | MEDIUM | 6.1 | 1.0% | Jun 6, 2022 | LibreHealth EHR Base 2.0.0 allows gacl/admin/acl_admin.php action XSS. |
| CVE-2022-30927 | CRITICAL | 9.8 | 1.4% | Jun 6, 2022 | A SQL injection vulnerability exists in Simple Task Scheduling System 1.0 when MySQL is being used as the application da... |
| CVE-2022-29296 | MEDIUM | 6.1 | 2.4% | Jun 6, 2022 | A reflected cross-site scripting (XSS) vulnerability in the login portal of Avantune Genialcloud ProJ - 10 allows attack... |
| CVE-2022-28479 | MEDIUM | 4.8 | 0.6% | Jun 6, 2022 | SeedDMS versions 6.0.18 and 5.1.25 and below are vulnerable to stored XSS. An attacker with admin privileges can inject ... |
| CVE-2022-28478 | MEDIUM | 6.5 | 1.4% | Jun 6, 2022 | SeedDMS 6.0.17 and 5.1.24 are vulnerable to Directory Traversal. The "Remove file" functionality inside the "Log files m... |
| CVE-2022-28051 | MEDIUM | 5.4 | 0.9% | Jun 6, 2022 | The "Add category" functionality inside the "Global Keywords" menu in "SeedDMS" version 6.0.18 and 5.1.25, is prone to s... |
| CVE-2022-27438 | HIGH | 8.1 | 2.4% | Jun 6, 2022 | Caphyon Ltd Advanced Installer 19.3 and earlier and many products that use the updater from Advanced Installer (Advanced... |
| CVE-2022-32511 | CRITICAL | 9.8 | 2.1% | Jun 6, 2022 | jmespath.rb (aka JMESPath for Ruby) before 1.6.1 uses JSON.load in a situation where JSON.parse is preferable. |
| CVE-2022-31498 | MEDIUM | 6.1 | 0.9% | Jun 6, 2022 | LibreHealth EHR Base 2.0.0 allows interface/orders/patient_match_dialog.php key XSS. |
| CVE-2022-30469 | HIGH | 8.8 | 1.4% | Jun 6, 2022 | In Afian Filerun 20220202, lack of sanitization of the POST parameter "metadata[]" in `/?module=fileman§ion=get&page... |
| CVE-2022-29631 | HIGH | 7.5 | 0.9% | Jun 6, 2022 | Jodd HTTP v6.0.9 was discovered to contain multiple CLRF injection vulnerabilities via the components jodd.http.HttpRequ... |
| CVE-2022-31492 | MEDIUM | 6.1 | 0.9% | Jun 6, 2022 | Cross Site scripting (XSS) vulnerability inLibreHealth EHR Base 2.0.0 via interface/usergroup/usergroup_admin_add.php Us... |
| CVE-2022-30587 | HIGH | 7.5 | 0.8% | Jun 6, 2022 | Gradle Enterprise through 2022.2.2 has Incorrect Access Control that leads to information disclosure. |
| CVE-2022-29617 | MEDIUM | 6.5 | 0.8% | Jun 6, 2022 | Due to improper error handling an authenticated user can crash CLA assistant instance. This could impact the availabilit... |
| CVE-2022-32275 | HIGH | 7.5 | 8.5% | Jun 6, 2022 | Grafana 8.4.3 allows reading files via (for example) a /dashboard/snapshot/%7B%7Bconstructor.constructor'/.. /.. /.. /..... |
| CVE-2022-31768 | CRITICAL | 9.8 | 1.3% | Jun 6, 2022 | IBM InfoSphere Information Server 11.7 is vulnerable to SQL injection. A remote attacker could send specially crafted SQ... |
| CVE-2022-31493 | MEDIUM | 6.1 | 0.9% | Jun 6, 2022 | LibreHealth EHR Base 2.0.0 allows gacl/admin/acl_admin.php acl_id XSS. |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now