2022 CVE Vulnerabilities
27,553 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-22973 | HIGH | 7.8 | 2.3% | May 20, 2022 | VMware Workspace ONE Access and Identity Manager contain a privilege escalation vulnerability. A malicious actor with lo... |
| CVE-2022-22972 | CRITICAL | 9.8 | 52.8% | May 20, 2022 | VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an authentication bypass vulnerability aff... |
| CVE-2022-29448 | MEDIUM | 4.9 | 1.0% | May 20, 2022 | Authenticated (admin or higher user role) Local File Inclusion (LFI) vulnerability in Wow-Company's Herd Effects plugin ... |
| CVE-2022-29425 | MEDIUM | 6.1 | 0.7% | May 20, 2022 | Cross-Site Scripting (XSS) vulnerability in WP Wham's Checkout Files Upload for WooCommerce plugin <= 2.1.2 at WordPress... |
| CVE-2022-29424 | MEDIUM | 4.8 | 0.5% | May 20, 2022 | Authenticated (admin or higher user role) Reflected Cross-Site Scripting (XSS) vulnerability in Biplob Adhikari's Image ... |
| CVE-2022-29185 | MEDIUM | 4.4 | 0.8% | May 20, 2022 | totp-rs is a Rust library that permits the creation of 2FA authentification tokens per time-based one-time password (TOT... |
| CVE-2022-29184 | HIGH | 8.8 | 3.6% | May 20, 2022 | GoCD is a continuous delivery server. In GoCD versions prior to 22.1.0, it is possible for existing authenticated users ... |
| CVE-2022-24434 | HIGH | 7.5 | 3.0% | May 20, 2022 | This affects all versions of package dicer. A malicious attacker can send a modified form to server, and crash the nodej... |
| CVE-2022-21195 | HIGH | 7.5 | 1.3% | May 20, 2022 | All versions of package url-regex are vulnerable to Regular Expression Denial of Service (ReDoS) which can cause the CPU... |
| CVE-2022-29183 | MEDIUM | 6.1 | 0.8% | May 20, 2022 | GoCD is a continuous delivery server. GoCD versions 20.2.0 until 21.4.0 are vulnerable to reflected cross-site scripting... |
| CVE-2022-29182 | MEDIUM | 5.4 | 0.8% | May 20, 2022 | GoCD is a continuous delivery server. GoCD versions 19.11.0 through 21.4.0 (inclusive) are vulnerable to a Document Obje... |
| CVE-2022-29181 | HIGH | 8.2 | 2.9% | May 20, 2022 | Nokogiri is an open source XML and HTML library for Ruby. Nokogiri prior to version 1.13.6 does not type-check all input... |
| CVE-2022-29179 | HIGH | 8.2 | 0.4% | May 20, 2022 | Cilium is open source software for providing and securing network connectivity and loadbalancing between application wor... |
| CVE-2022-29178 | HIGH | 8.2 | 0.3% | May 20, 2022 | Cilium is open source software for providing and securing network connectivity and loadbalancing between application wor... |
| CVE-2022-28995 | CRITICAL | 9.8 | 2.2% | May 20, 2022 | Rengine v1.0.2 was discovered to contain a remote code execution (RCE) vulnerability via the yaml configuration function... |
| CVE-2022-28990 | HIGH | 7.8 | 0.4% | May 20, 2022 | WASM3 v0.5.0 was discovered to contain a heap overflow via the component /wabt/bin/poc.wasm. |
| CVE-2022-28531 | CRITICAL | 9.8 | 14.2% | May 20, 2022 | Sourcecodester Covid-19 Directory on Vaccination System1.0 is vulnerable to SQL Injection via the admin/login.php txtuse... |
| CVE-2022-1770 | HIGH | 8.8 | 2.4% | May 20, 2022 | Improper Privilege Management in GitHub repository polonel/trudesk prior to 1.2.2. |
| CVE-2022-29177 | MEDIUM | 5.9 | 0.9% | May 20, 2022 | Go Ethereum is the official Golang implementation of the Ethereum protocol. Prior to version 1.10.17, a vulnerable node,... |
| CVE-2022-22365 | MEDIUM | 5.9 | 0.6% | May 20, 2022 | IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0, with the Ajax Proxy Web Application (AjaxProxy.war) deployed, i... |
| CVE-2022-29170 | HIGH | 8.5 | 1.1% | May 20, 2022 | Grafana is an open-source platform for monitoring and observability. In Grafana Enterprise, the Request security feature... |
| CVE-2022-29163 | MEDIUM | 4.3 | 1.0% | May 20, 2022 | Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform. Prior to versions 22.2.... |
| CVE-2022-29160 | LOW | 3.3 | 0.4% | May 20, 2022 | Nextcloud Android is the Android client for Nextcloud, a self-hosted productivity platform. Prior to version 3.19.0, sen... |
| CVE-2022-29159 | MEDIUM | 4.3 | 0.9% | May 20, 2022 | Nextcloud Deck is a Kanban-style project & personal management tool for Nextcloud. In versions prior to 1.4.8, 1.5.6, an... |
| CVE-2022-24906 | MEDIUM | 4.3 | 1.0% | May 20, 2022 | Nextcloud Deck is a Kanban-style project & personal management tool for Nextcloud, similar to Trello. The full path of t... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now