2022 CVE Vulnerabilities

27,553 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-1784HIGH7.5Server-Side Request Forgery (SSRF) in GitHub repository jgraph/drawio prior to 18.0.8.
CVE-2022-31215MEDIUM6.5In certain Goverlan products, the Windows Firewall is temporarily turned off upon a Goverlan agent update operation. Thi...
CVE-2022-30551HIGH7.5OPC UA Legacy Java Stack 2022-04-01 allows a remote attacker to cause a server to stop processing messages by sending cr...
CVE-2022-25227HIGH8.8Thinfinity VNC v4.0.0.1 contains a Cross-Origin Resource Sharing (CORS) vulnerability which can allow an unprivileged re...
CVE-2022-25224MEDIUM5.4Proton v0.2.0 allows an attacker to create a malicious link inside a markdown file. When the victim clicks the link, the...
CVE-2022-25229MEDIUM5.4Popcorn Time 0.4.7 has a Stored XSS in the 'Movies API Server(s)' field via the 'settings' page. The 'nodeIntegration' c...
CVE-2022-1806MEDIUM6.1Cross-site Scripting (XSS) - Reflected in GitHub repository rtxteam/rtx prior to checkpoint_2022-05-18.
CVE-2022-1754MEDIUM6.5Integer Overflow or Wraparound in GitHub repository polonel/trudesk prior to 1.2.2.
CVE-2022-28987MEDIUM5.3Zoho ManageEngine ADSelfService Plus before 6202 allows attackers to perform username enumeration via a crafted POST req...
CVE-2022-28985MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in the addNewPost component of OrangeHRM v4.10.1 allows attackers to e...
CVE-2022-28965MEDIUM6.5Multiple DLL hijacking vulnerabilities via the components instup.exe and wsc_proxy.exe in Avast Premium Security before ...
CVE-2022-28964HIGH7.1An arbitrary file write vulnerability in Avast Premium Security before v21.11.2500 (build 21.11.6809.528) allows attacke...
CVE-2022-21500HIGH7.5Vulnerability in Oracle E-Business Suite (component: Manage Proxies). The supported version that is affected is 12.2. Ea...
CVE-2022-29652MEDIUM6.1Online Sports Complex Booking System 1.0 is vulnerable to SQL Injection via /scbs/classes/Users.php?f=save_client.
CVE-2022-29304HIGH8.8Online Sports Complex Booking System 1.0 is vulnerable to SQL Injection via /classes/master.php?f=delete_ Facility.
CVE-2022-28962CRITICAL9.8Online Sports Complex Booking System 1.0 is vulnerable to SQL Injection via /scbs/classes/Users.php?f=delete_client.
CVE-2022-28961HIGH8.8Spip Web Framework v3.1.13 and below was discovered to contain multiple SQL injection vulnerabilities at /ecrire via the...
CVE-2022-28960HIGH8.8A PHP injection vulnerability in Spip before v3.2.8 allows attackers to execute arbitrary PHP code via the _oups paramet...
CVE-2022-28959MEDIUM6.1Multiple cross-site scripting (XSS) vulnerabilities in the component /spip.php of Spip Web Framework v3.1.13 and below a...
CVE-2022-28948HIGH7.5An issue in the Unmarshal function in Go-Yaml v3 causes the program to crash when attempting to deserialize invalid inpu...
CVE-2022-28946HIGH7.5An issue in the component ast/parser.go of Open Policy Agent v0.39.0 causes the application to incorrectly interpret eve...
CVE-2022-30618HIGH7.5An authenticated user with access to the Strapi admin panel can view private and sensitive data, such as email and passw...
CVE-2022-30617HIGH8.8An authenticated user with access to the Strapi admin panel can view private and sensitive data, such as email and passw...
CVE-2022-1423HIGH8.8Improper access control in the CI/CD cache mechanism in GitLab CE/EE affecting all versions starting from 1.0.2 before 1...
CVE-2022-1416MEDIUM5.4Missing sanitization of data in Pipeline error messages in GitLab CE/EE affecting all versions starting from 1.0.2 befor...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now