2022 CVE Vulnerabilities
27,553 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-23675 | MEDIUM | 4.8 | 0.5% | May 17, 2022 | A remote authenticated stored cross-site scripting (xss) vulnerability was discovered in Aruba ClearPass Policy Manager ... |
| CVE-2022-23673 | HIGH | 7.2 | 2.1% | May 17, 2022 | A authenticated remote command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10... |
| CVE-2022-23672 | HIGH | 7.2 | 2.1% | May 17, 2022 | A authenticated remote command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10... |
| CVE-2022-23671 | HIGH | 7.5 | 1.2% | May 17, 2022 | A remote authenticated information disclosure vulnerability was discovered in Aruba ClearPass Policy Manager version(s):... |
| CVE-2022-23669 | HIGH | 8.8 | 1.0% | May 17, 2022 | A remote authorization bypass vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and belo... |
| CVE-2022-22775 | MEDIUM | 5.4 | 0.5% | May 17, 2022 | The Workspace client component of TIBCO Software Inc.'s TIBCO BPM Enterprise and TIBCO BPM Enterprise Distribution for T... |
| CVE-2022-22773 | MEDIUM | 5.4 | 0.5% | May 17, 2022 | The REST API component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server - Community Editi... |
| CVE-2022-1706 | MEDIUM | 6.5 | 1.1% | May 17, 2022 | A vulnerability was found in Ignition where ignition configs are accessible from unprivileged containers in VMs running ... |
| CVE-2022-30072 | MEDIUM | 5.4 | 0.8% | May 17, 2022 | WBCE CMS 1.5.2 is vulnerable to Cross Site Scripting (XSS) via \admin\pages\sections_save.php namesection2 parameters. |
| CVE-2022-30067 | MEDIUM | 5.5 | 0.7% | May 17, 2022 | GIMP 2.10.30 and 2.99.10 are vulnerable to Buffer Overflow. Through a crafted XCF file, the program will allocate for a ... |
| CVE-2022-29581 | HIGH | 7.8 | 1.0% | May 17, 2022 | Improper Update of Reference Count vulnerability in net/sched of Linux Kernel allows local attacker to cause privilege e... |
| CVE-2022-22482 | MEDIUM | 6.5 | 0.9% | May 17, 2022 | IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.5 and 6.1.0.0 through 6.1.1.0 could allow an authenti... |
| CVE-2022-22475 | MEDIUM | 6.5 | 0.6% | May 17, 2022 | IBM WebSphere Application Server Liberty and Open Liberty 17.0.0.3 through 22.0.0.5 are vulnerable to identity spoofing ... |
| CVE-2022-1769 | HIGH | 7.8 | 0.4% | May 17, 2022 | Buffer Over-read in GitHub repository vim/vim prior to 8.2.4974. |
| CVE-2022-1733 | HIGH | 7.8 | 0.6% | May 17, 2022 | Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.4968. |
| CVE-2022-1116 | HIGH | 7.8 | 0.5% | May 17, 2022 | Integer Overflow or Wraparound vulnerability in io_uring of Linux Kernel allows local attacker to cause memory corruptio... |
| CVE-2022-30073 | MEDIUM | 5.4 | 1.5% | May 17, 2022 | WBCE CMS 1.5.2 is vulnerable to Cross Site Scripting (XSS) via /admin/users/save.php. |
| CVE-2022-30007 | HIGH | 7.2 | 0.9% | May 17, 2022 | GXCMS V1.5 has a file upload vulnerability in the background. The vulnerability is the template management page. You can... |
| CVE-2022-24856 | HIGH | 7.5 | 9.7% | May 17, 2022 | FlyteConsole is the web user interface for the Flyte platform. FlyteConsole prior to version 0.52.0 is vulnerable to ser... |
| CVE-2022-24108 | CRITICAL | 9.8 | 33.0% | May 17, 2022 | The Skyoftech So Listing Tabs module 2.2.0 for OpenCart allows a remote attacker to inject a serialized PHP object via t... |
| CVE-2022-22484 | MEDIUM | 5.5 | 0.2% | May 17, 2022 | IBM Spectrum Protect Operations Center 8.1.12 and 8.1.13 could allow a local attacker to obtain sensitive information, c... |
| CVE-2022-30972 | HIGH | 8.8 | 0.6% | May 17, 2022 | A cross-site request forgery (CSRF) vulnerability in Jenkins Storable Configs Plugin 1.0 and earlier allows attackers to... |
| CVE-2022-30971 | HIGH | 8.8 | 1.1% | May 17, 2022 | Jenkins Storable Configs Plugin 1.0 and earlier does not configure its XML parser to prevent XML external entity (XXE) a... |
| CVE-2022-30970 | MEDIUM | 5.4 | 0.7% | May 17, 2022 | Jenkins Autocomplete Parameter Plugin 1.1 and earlier references Dropdown Autocomplete parameter and Auto Complete Strin... |
| CVE-2022-30969 | HIGH | 8.8 | 0.8% | May 17, 2022 | A cross-site request forgery (CSRF) vulnerability in Jenkins Autocomplete Parameter Plugin 1.1 and earlier allows attack... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now