2022 CVE Vulnerabilities
27,525 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-34125 | MEDIUM | 6.5 | 4.6% | Apr 16, 2023 | front/icon.send.php in the CMDB plugin before 3.0.3 for GLPI allows attackers to gain read access to sensitive informati... |
| CVE-2022-30076 | MEDIUM | 5.3 | 3.5% | Apr 16, 2023 | ENTAB ERP 1.0 allows attackers to discover users' full names via a brute force attack with a series of student usernames... |
| CVE-2022-28353 | MEDIUM | 6.1 | 0.6% | Apr 16, 2023 | In the External Redirect Warning Plugin 1.3 for MyBB, the redirect URL (aka external.php?url=) is vulnerable to XSS. |
| CVE-2022-37306 | MEDIUM | 6.1 | 0.6% | Apr 16, 2023 | OX App Suite before 7.10.6-rev30 allows XSS via an upsell trigger. |
| CVE-2022-37186 | MEDIUM | 5.9 | 0.7% | Apr 16, 2023 | In LemonLDAP::NG before 2.0.15. some sessions are not deleted when they are supposed to be deleted according to the time... |
| CVE-2022-37705 | MEDIUM | 6.7 | 1.2% | Apr 16, 2023 | A privilege escalation flaw was found in Amanda 3.5.1 in which the backup user can acquire root privileges. The vulnerab... |
| CVE-2022-37704 | MEDIUM | 6.7 | 0.5% | Apr 16, 2023 | Amanda 3.5.1 allows privilege escalation from the regular user backup to root. The SUID binary located at /lib/amanda/ru... |
| CVE-2022-43699 | MEDIUM | 4.3 | 0.5% | Apr 15, 2023 | OX App Suite before 7.10.6-rev30 allows SSRF because e-mail account discovery disregards the deny-list and thus can be a... |
| CVE-2022-43698 | MEDIUM | 4.3 | 0.5% | Apr 15, 2023 | OX App Suite before 7.10.6-rev30 allows SSRF because changing a POP3 account disregards the deny-list. |
| CVE-2022-43697 | MEDIUM | 6.1 | 0.4% | Apr 15, 2023 | OX App Suite before 7.10.6-rev30 allows XSS via an activity tracking adapter defined by jslob. |
| CVE-2022-43696 | MEDIUM | 6.1 | 0.4% | Apr 15, 2023 | OX App Suite before 7.10.6-rev20 allows XSS via upsell ads. |
| CVE-2022-48178 | MEDIUM | 5.4 | 1.8% | Apr 15, 2023 | X2CRM Open Source Sales CRM 6.6 and 6.9 was discovered to contain a stored cross-site scripting (XSS) vulnerability via ... |
| CVE-2022-48177 | MEDIUM | 5.4 | 1.8% | Apr 15, 2023 | X2CRM Open Source Sales CRM 6.6 and 6.9 was discovered to contain a reflected cross-site scripting (XSS) vulnerability v... |
| CVE-2022-46886 | MEDIUM | 6.1 | 0.3% | Apr 14, 2023 | There exists an open redirect within the response list update functionality of ServiceNow. This allows attackers to redi... |
| CVE-2022-45180 | MEDIUM | 6.5 | 0.7% | Apr 14, 2023 | An issue was discovered in LIVEBOX Collaboration vDesk through v018. Broken Access Control exists under the /api/v1/vdes... |
| CVE-2022-45175 | MEDIUM | 6.5 | 0.7% | Apr 14, 2023 | An issue was discovered in LIVEBOX Collaboration vDesk through v018. An Insecure Direct Object Reference can occur under... |
| CVE-2022-45170 | MEDIUM | 6.5 | 0.4% | Apr 14, 2023 | An issue was discovered in LIVEBOX Collaboration vDesk through v018. A Cryptographic Issue can occur under the /api/v1/v... |
| CVE-2022-48468 | MEDIUM | 5.5 | 0.4% | Apr 13, 2023 | protobuf-c before 1.4.1 has an unsigned integer overflow in parse_required_member. |
| CVE-2022-45358 | MEDIUM | 5.4 | 0.4% | Apr 13, 2023 | Auth. (subscriber+) Reflected Cross-Site Scripting (XSS) vulnerability in Silkalns Activello theme <= 1.4.4 versions. |
| CVE-2022-44625 | MEDIUM | 4.8 | 0.4% | Apr 13, 2023 | Auth. (admin+) Stored Cross-Site Scripting') vulnerability in Zephilou Cyklodev WP Notify plugin <= 1.2.1 versions. |
| CVE-2022-33297 | MEDIUM | 5.5 | 0.1% | Apr 13, 2023 | Information disclosure due to buffer overread in Linux sensors |
| CVE-2022-33289 | MEDIUM | 6.8 | 0.2% | Apr 13, 2023 | Memory corruption occurs in Modem due to improper validation of array index when malformed APDU is sent from card. |
| CVE-2022-33270 | MEDIUM | 5.9 | 0.3% | Apr 13, 2023 | Transient DOS due to time-of-check time-of-use race condition in Modem while processing RRC Reconfiguration message. |
| CVE-2022-47053 | MEDIUM | 5.4 | 0.4% | Apr 12, 2023 | An arbitrary file upload vulnerability in the Digital Assets Manager module of DNN Corp DotNetNuke v7.0.0 to v9.10.2 all... |
| CVE-2022-24350 | MEDIUM | 5.5 | 0.2% | Apr 12, 2023 | An issue was discovered in IhisiSmm in Insyde InsydeH2O with kernel 5.0 through 5.5. IHISI function 0x17 verifies that t... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now