2022 CVE Vulnerabilities

27,552 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-1708HIGH7.5A vulnerability was found in CRI-O that causes memory or disk space exhaustion on the node for anyone with access to the...
CVE-2022-31279Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2022-31028HIGH7.5MinIO is a multi-cloud object storage solution. Starting with version RELEASE.2019-09-25T18-25-51Z and ending with versi...
CVE-2022-31495MEDIUM6.1LibreHealth EHR Base 2.0.0 allows gacl/admin/acl_admin.php return_page XSS.
CVE-2022-31025MEDIUM5.3Discourse is an open source platform for community discussion. Prior to version 2.8.4 on the `stable` branch and 2.9.0be...
CVE-2022-29564HIGH7.5Jamf Private Access before 2022-05-16 has Incorrect Access Control, in which an unauthorized user can reach a system in ...
CVE-2022-25361CRITICAL9.1WatchGuard Firebox and XTM appliances allow an unauthenticated remote attacker to delete arbitrary files from a limited ...
CVE-2022-1991MEDIUM4.8A vulnerability classified as problematic has been found in Fast Food Ordering System 1.0. Affected is the file Master.p...
CVE-2022-31494MEDIUM6.1LibreHealth EHR Base 2.0.0 allows gacl/admin/acl_admin.php action XSS.
CVE-2022-30927CRITICAL9.8A SQL injection vulnerability exists in Simple Task Scheduling System 1.0 when MySQL is being used as the application da...
CVE-2022-29296MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability in the login portal of Avantune Genialcloud ProJ - 10 allows attack...
CVE-2022-28479MEDIUM4.8SeedDMS versions 6.0.18 and 5.1.25 and below are vulnerable to stored XSS. An attacker with admin privileges can inject ...
CVE-2022-28478MEDIUM6.5SeedDMS 6.0.17 and 5.1.24 are vulnerable to Directory Traversal. The "Remove file" functionality inside the "Log files m...
CVE-2022-28051MEDIUM5.4The "Add category" functionality inside the "Global Keywords" menu in "SeedDMS" version 6.0.18 and 5.1.25, is prone to s...
CVE-2022-27438HIGH8.1Caphyon Ltd Advanced Installer 19.3 and earlier and many products that use the updater from Advanced Installer (Advanced...
CVE-2022-32511CRITICAL9.8jmespath.rb (aka JMESPath for Ruby) before 1.6.1 uses JSON.load in a situation where JSON.parse is preferable.
CVE-2022-31498MEDIUM6.1LibreHealth EHR Base 2.0.0 allows interface/orders/patient_match_dialog.php key XSS.
CVE-2022-30469HIGH8.8In Afian Filerun 20220202, lack of sanitization of the POST parameter "metadata[]" in `/?module=fileman&section=get&page...
CVE-2022-29631HIGH7.5Jodd HTTP v6.0.9 was discovered to contain multiple CLRF injection vulnerabilities via the components jodd.http.HttpRequ...
CVE-2022-31492MEDIUM6.1Cross Site scripting (XSS) vulnerability inLibreHealth EHR Base 2.0.0 via interface/usergroup/usergroup_admin_add.php Us...
CVE-2022-30587HIGH7.5Gradle Enterprise through 2022.2.2 has Incorrect Access Control that leads to information disclosure.
CVE-2022-29617MEDIUM6.5Due to improper error handling an authenticated user can crash CLA assistant instance. This could impact the availabilit...
CVE-2022-32275HIGH7.5Grafana 8.4.3 allows reading files via (for example) a /dashboard/snapshot/%7B%7Bconstructor.constructor'/.. /.. /.. /.....
CVE-2022-31768CRITICAL9.8IBM InfoSphere Information Server 11.7 is vulnerable to SQL injection. A remote attacker could send specially crafted SQ...
CVE-2022-31493MEDIUM6.1LibreHealth EHR Base 2.0.0 allows gacl/admin/acl_admin.php acl_id XSS.

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now