2022 CVE Vulnerabilities
27,553 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-1784 | HIGH | 7.5 | 1.7% | May 20, 2022 | Server-Side Request Forgery (SSRF) in GitHub repository jgraph/drawio prior to 18.0.8. |
| CVE-2022-31215 | MEDIUM | 6.5 | 1.1% | May 20, 2022 | In certain Goverlan products, the Windows Firewall is temporarily turned off upon a Goverlan agent update operation. Thi... |
| CVE-2022-30551 | HIGH | 7.5 | 2.2% | May 20, 2022 | OPC UA Legacy Java Stack 2022-04-01 allows a remote attacker to cause a server to stop processing messages by sending cr... |
| CVE-2022-25227 | HIGH | 8.8 | 0.6% | May 20, 2022 | Thinfinity VNC v4.0.0.1 contains a Cross-Origin Resource Sharing (CORS) vulnerability which can allow an unprivileged re... |
| CVE-2022-25224 | MEDIUM | 5.4 | 0.7% | May 20, 2022 | Proton v0.2.0 allows an attacker to create a malicious link inside a markdown file. When the victim clicks the link, the... |
| CVE-2022-25229 | MEDIUM | 5.4 | 0.5% | May 20, 2022 | Popcorn Time 0.4.7 has a Stored XSS in the 'Movies API Server(s)' field via the 'settings' page. The 'nodeIntegration' c... |
| CVE-2022-1806 | MEDIUM | 6.1 | 0.7% | May 20, 2022 | Cross-site Scripting (XSS) - Reflected in GitHub repository rtxteam/rtx prior to checkpoint_2022-05-18. |
| CVE-2022-1754 | MEDIUM | 6.5 | 1.0% | May 20, 2022 | Integer Overflow or Wraparound in GitHub repository polonel/trudesk prior to 1.2.2. |
| CVE-2022-28987 | MEDIUM | 5.3 | 9.7% | May 20, 2022 | Zoho ManageEngine ADSelfService Plus before 6202 allows attackers to perform username enumeration via a crafted POST req... |
| CVE-2022-28985 | MEDIUM | 5.4 | 0.5% | May 20, 2022 | A stored cross-site scripting (XSS) vulnerability in the addNewPost component of OrangeHRM v4.10.1 allows attackers to e... |
| CVE-2022-28965 | MEDIUM | 6.5 | 0.3% | May 20, 2022 | Multiple DLL hijacking vulnerabilities via the components instup.exe and wsc_proxy.exe in Avast Premium Security before ... |
| CVE-2022-28964 | HIGH | 7.1 | 0.2% | May 20, 2022 | An arbitrary file write vulnerability in Avast Premium Security before v21.11.2500 (build 21.11.6809.528) allows attacke... |
| CVE-2022-21500 | HIGH | 7.5 | 70.6% | May 20, 2022 | Vulnerability in Oracle E-Business Suite (component: Manage Proxies). The supported version that is affected is 12.2. Ea... |
| CVE-2022-29652 | MEDIUM | 6.1 | 0.8% | May 19, 2022 | Online Sports Complex Booking System 1.0 is vulnerable to SQL Injection via /scbs/classes/Users.php?f=save_client. |
| CVE-2022-29304 | HIGH | 8.8 | 0.8% | May 19, 2022 | Online Sports Complex Booking System 1.0 is vulnerable to SQL Injection via /classes/master.php?f=delete_ Facility. |
| CVE-2022-28962 | CRITICAL | 9.8 | 1.6% | May 19, 2022 | Online Sports Complex Booking System 1.0 is vulnerable to SQL Injection via /scbs/classes/Users.php?f=delete_client. |
| CVE-2022-28961 | HIGH | 8.8 | 1.5% | May 19, 2022 | Spip Web Framework v3.1.13 and below was discovered to contain multiple SQL injection vulnerabilities at /ecrire via the... |
| CVE-2022-28960 | HIGH | 8.8 | 1.8% | May 19, 2022 | A PHP injection vulnerability in Spip before v3.2.8 allows attackers to execute arbitrary PHP code via the _oups paramet... |
| CVE-2022-28959 | MEDIUM | 6.1 | 1.5% | May 19, 2022 | Multiple cross-site scripting (XSS) vulnerabilities in the component /spip.php of Spip Web Framework v3.1.13 and below a... |
| CVE-2022-28948 | HIGH | 7.5 | 3.5% | May 19, 2022 | An issue in the Unmarshal function in Go-Yaml v3 causes the program to crash when attempting to deserialize invalid inpu... |
| CVE-2022-28946 | HIGH | 7.5 | 0.9% | May 19, 2022 | An issue in the component ast/parser.go of Open Policy Agent v0.39.0 causes the application to incorrectly interpret eve... |
| CVE-2022-30618 | HIGH | 7.5 | 0.9% | May 19, 2022 | An authenticated user with access to the Strapi admin panel can view private and sensitive data, such as email and passw... |
| CVE-2022-30617 | HIGH | 8.8 | 1.3% | May 19, 2022 | An authenticated user with access to the Strapi admin panel can view private and sensitive data, such as email and passw... |
| CVE-2022-1423 | HIGH | 8.8 | 1.4% | May 19, 2022 | Improper access control in the CI/CD cache mechanism in GitLab CE/EE affecting all versions starting from 1.0.2 before 1... |
| CVE-2022-1416 | MEDIUM | 5.4 | 0.7% | May 19, 2022 | Missing sanitization of data in Pipeline error messages in GitLab CE/EE affecting all versions starting from 1.0.2 befor... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now