2022 CVE Vulnerabilities
27,525 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-43928 | MEDIUM | 6.5 | 0.6% | Apr 7, 2023 | The IBM Toolbox for Java (Db2 Mirror for i 7.4 and 7.5) could allow a user to obtain sensitive information, caused by ut... |
| CVE-2022-43914 | MEDIUM | 5.4 | 0.4% | Apr 7, 2023 | IBM TRIRIGA Application Platform 4.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arb... |
| CVE-2022-32599 | MEDIUM | 6.7 | 0.1% | Apr 6, 2023 | In rpmb, there is a possible out of bounds write due to a logic error. This could lead to local escalation of privilege ... |
| CVE-2022-31889 | MEDIUM | 6.1 | 0.7% | Apr 5, 2023 | Cross Site Scripting (XSS) vulnerability in audit/templates/auditlogs.tmpl.php in osTicket osTicket-plugins before commi... |
| CVE-2022-3513 | MEDIUM | 6.1 | 0.7% | Apr 5, 2023 | An issue has been discovered in GitLab affecting all versions starting from 12.8 before 15.8.5, all versions starting fr... |
| CVE-2022-4940 | MEDIUM | 6.5 | 1.1% | Apr 5, 2023 | The WCFM Membership plugin for WordPress is vulnerable to unauthorized modification and access of data in versions up to... |
| CVE-2022-48223 | MEDIUM | 6.7 | 0.1% | Apr 4, 2023 | An issue was discovered in Acuant AcuFill SDK before 10.22.02.03. During SDK repair, certutil.exe is called by the Acuan... |
| CVE-2022-48228 | MEDIUM | 5.5 | 0.2% | Apr 4, 2023 | An issue was discovered in Acuant AsureID Sentinel before 5.2.149. It uses the root of the C: drive for the i-Dentify an... |
| CVE-2022-47870 | MEDIUM | 6.1 | 2.2% | Apr 4, 2023 | A Cross Site Scripting (XSS) vulnerability in the web SQL monitor login page in Redgate SQL Monitor 12.1.31.893 allows r... |
| CVE-2022-4771 | MEDIUM | 6.1 | 0.4% | Apr 3, 2023 | Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.1 and 9.3.0.2, including 8.3.x allow a malici... |
| CVE-2022-4770 | MEDIUM | 4.3 | 0.4% | Apr 3, 2023 | Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.0 and 9.3.0.2, including 8.3.x display the fu... |
| CVE-2022-4769 | MEDIUM | 4.3 | 0.4% | Apr 3, 2023 | Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.0 and 9.3.0.2, including 8.3.x display the ta... |
| CVE-2022-43941 | MEDIUM | 6.5 | 0.5% | Apr 3, 2023 | Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.1 and 9.3.0.2, including 8.3.x do not correctly... |
| CVE-2022-43772 | MEDIUM | 6.5 | 0.4% | Apr 3, 2023 | Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.0 and 9.3.0.1, including 8.3.x with the Big Dat... |
| CVE-2022-43771 | MEDIUM | 6.5 | 23.9% | Apr 3, 2023 | Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.0 and 9.3.0.1, including 8.3.x, using the Penta... |
| CVE-2022-3960 | MEDIUM | 6.3 | 0.5% | Apr 3, 2023 | Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.1 and 9.3.0.2, including 8.3.x cannot allow a... |
| CVE-2022-27665 | MEDIUM | 6.1 | 33.1% | Apr 3, 2023 | Reflected XSS (via AngularJS sandbox escape expressions) exists in Progress Ipswitch WS_FTP Server 8.6.0. This can lead ... |
| CVE-2022-42452 | MEDIUM | 5.4 | 0.3% | Apr 2, 2023 | HCL Launch is vulnerable to HTML injection. HTML code is stored and included without being sanitized. This can lead to ... |
| CVE-2022-3192 | MEDIUM | 5.3 | 0.6% | Mar 31, 2023 | Improper Input Validation vulnerability in ABB AC500 V2 PM5xx allows Client-Server Protocol Manipulation.This issue affe... |
| CVE-2022-43473 | MEDIUM | 5.4 | 19.8% | Mar 30, 2023 | A blind XML External Entity (XXE) vulnerability exists in the Add UCS Device functionality of ManageEngine OpManager 12.... |
| CVE-2022-1274 | MEDIUM | 5.4 | 0.7% | Mar 29, 2023 | A flaw was found in Keycloak in the execute-actions-email endpoint. This issue allows arbitrary HTML to be injected into... |
| CVE-2022-47602 | MEDIUM | 5.4 | 0.4% | Mar 29, 2023 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in JoomUnited WP Table Manager plugin <= 3.5.2 vers... |
| CVE-2022-44369 | MEDIUM | 5.5 | 0.3% | Mar 29, 2023 | NASM 2.16 (development) is vulnerable to 476: Null Pointer Dereference via output/outaout.c. |
| CVE-2022-44368 | MEDIUM | 5.5 | 0.3% | Mar 29, 2023 | NASM v2.16 was discovered to contain a null pointer deference in the NASM component |
| CVE-2022-47613 | MEDIUM | 4.8 | 0.4% | Mar 29, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in QuantumCloud AI ChatBot plugin <= 4.3.0 versions. |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now