2022 CVE Vulnerabilities
27,553 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-1464 | MEDIUM | 5.4 | 0.7% | May 5, 2022 | Stored xss bug in GitHub repository gogs/gogs prior to 0.12.7. As the repo is public , any user can view the report and ... |
| CVE-2022-29340 | HIGH | 7.5 | 1.1% | May 5, 2022 | GPAC 2.1-DEV-rev87-g053aae8-master. has a Null Pointer Dereference vulnerability in gf_isom_parse_movie_boxes_internal d... |
| CVE-2022-29339 | HIGH | 7.5 | 1.1% | May 5, 2022 | In GPAC 2.1-DEV-rev87-g053aae8-master, function BS_ReadByte() in utils/bitstream.c has a failed assertion, which causes ... |
| CVE-2022-28471 | MEDIUM | 6.5 | 0.9% | May 5, 2022 | In ffjpeg (commit hash: caade60), the function bmp_load() in bmp.c contains an integer overflow vulnerability, which eve... |
| CVE-2022-28462 | HIGH | 7.5 | 1.0% | May 5, 2022 | novel-plus 3.6.0 suffers from an Arbitrary file reading vulnerability. |
| CVE-2022-28461 | CRITICAL | 9.8 | 0.9% | May 5, 2022 | mingyuefusu Library Management System all versions as of 03-27-2022 is vulnerable to SQL Injection. |
| CVE-2022-29940 | MEDIUM | 5.4 | 0.8% | May 5, 2022 | In LibreHealth EHR 2.0.0, lack of sanitization of the GET parameters formseq and formid in interface\orders\find_order_p... |
| CVE-2022-29939 | MEDIUM | 5.4 | 0.8% | May 5, 2022 | In LibreHealth EHR 2.0.0, lack of sanitization of the GET parameters debug and InsId in interface\billing\sl_eob_process... |
| CVE-2022-29938 | HIGH | 8.8 | 1.4% | May 5, 2022 | In LibreHealth EHR 2.0.0, lack of sanitization of the GET parameter payment_id in interface\billing\new_payment.php via ... |
| CVE-2022-1575 | CRITICAL | 9.6 | 2.2% | May 5, 2022 | Arbitrary Code Execution through Sanitizer Bypass in GitHub repository jgraph/drawio prior to 18.0.0. - Arbitrary (remot... |
| CVE-2022-1592 | HIGH | 8.2 | 1.1% | May 5, 2022 | Server-Side Request Forgery in scout in GitHub repository clinical-genomics/scout prior to v4.42. An attacker could make... |
| CVE-2022-1411 | MEDIUM | 6.1 | 0.7% | May 5, 2022 | Unrestructed file upload in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0. Attacker can send malicious ... |
| CVE-2022-1590 | MEDIUM | 5.4 | 0.6% | May 5, 2022 | A vulnerability was found in Bludit 3.13.1. It has been declared as problematic. This vulnerability affects the endpoint... |
| CVE-2022-28890 | CRITICAL | 9.8 | 2.3% | May 5, 2022 | A vulnerability in the RDF/XML parser of Apache Jena allows an attacker to cause an external DTD to be retrieved. This i... |
| CVE-2022-1588 | — | — | — | May 5, 2022 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. Reason: This CVE has been rejected as it was incorrectly assigned. Al... |
| CVE-2022-30292 | CRITICAL | 10 | 3.5% | May 4, 2022 | Heap-based buffer overflow in sqbaselib.cpp in SQUIRREL 3.2 due to lack of a certain sq_reservestack call. |
| CVE-2022-30288 | HIGH | 7.5 | 1.5% | May 4, 2022 | Agoo before 2.14.3 does not reject GraphQL fragment spreads that form cycles, leading to an application crash. NOTE: the... |
| CVE-2022-30284 | CRITICAL | 9.8 | 4.6% | May 4, 2022 | In the python-libnmap package through 0.7.2 for Python, remote command execution can occur (if used in a client applicat... |
| CVE-2022-29155 | CRITICAL | 9.8 | 69.9% | May 4, 2022 | In OpenLDAP 2.x before 2.5.12 and 2.6.x before 2.6.2, a SQL injection vulnerability exists in the experimental back-sql ... |
| CVE-2022-30241 | MEDIUM | 6.1 | 0.7% | May 4, 2022 | The jquery.json-viewer library through 1.4.0 for Node.js does not properly escape characters such as < in a JSON object,... |
| CVE-2022-29943 | MEDIUM | 6.5 | 0.8% | May 4, 2022 | Talend Administration Center has a vulnerability that allows an authenticated user to use XML External Entity (XXE) proc... |
| CVE-2022-29942 | MEDIUM | 6.5 | 0.6% | May 4, 2022 | Talend Administration Center has a vulnerability that allows an authenticated user to use the Service Registry 'Add' fun... |
| CVE-2022-25786 | MEDIUM | 4.9 | 0.7% | May 4, 2022 | Unprotected Alternate Channel vulnerability in debug console of GateManager allows system administrator to obtain sensit... |
| CVE-2022-1584 | MEDIUM | 6.1 | 0.8% | May 4, 2022 | Reflected XSS in GitHub repository microweber/microweber prior to 1.2.16. Executing JavaScript as the victim |
| CVE-2022-23724 | HIGH | 8.1 | 0.4% | May 4, 2022 | Use of static encryption key material allows forging an authentication token to other users within a tenant organization... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now