2022 CVE Vulnerabilities

27,553 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-24875HIGH7.5The CVEProject/cve-services is an open source project used to operate the CVE services api. In versions up to and includ...
CVE-2022-24870MEDIUM5.4Combodo iTop is a web based IT Service Management tool. In 3.0.0 beta releases prior to 3.0.0 beta3 a malicious script c...
CVE-2022-24869MEDIUM5.4GLPI is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and...
CVE-2022-24868MEDIUM5.4GLPI is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and...
CVE-2022-24867HIGH7.5GLPI is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and...
CVE-2022-22436MEDIUM5.4IBM Maximo Asset Management 7.6.1.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbi...
CVE-2022-22435MEDIUM5.4IBM Maximo Asset Management 7.6.1.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbi...
CVE-2022-0272CRITICAL9.8Improper Restriction of XML External Entity Reference in GitHub repository detekt/detekt prior to 1.20.0.
CVE-2022-1022MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository chatwoot/chatwoot prior to 2.5.0.
CVE-2022-24272MEDIUM6.5An authenticated user may trigger an invariant assertion during command dispatch due to incorrect validation on the $ext...
CVE-2022-1420MEDIUM5.5Use of Out-of-range Pointer Offset in GitHub repository vim/vim prior to 8.2.4774.
CVE-2022-29498HIGH7.5Blazer before 2.6.0 allows SQL Injection. In certain circumstances, an attacker could get a user to run a query they wou...
CVE-2022-27237MEDIUM6.1There is a cross-site scripting (XSS) vulnerability in an NI Web Server component installed with several NI products. De...
CVE-2022-29548MEDIUM6.1A reflected XSS issue exists in the Management Console of several WSO2 products. This affects API Manager 2.2.0, 2.5.0, ...
CVE-2022-29547HIGH7.5The CreateRedirect extension before 2022-04-14 for MediaWiki does not properly check whether the user has permissions to...
CVE-2022-27926MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability in the /public/launchNewWindow.jsp component of Zimbra Collaboratio...
CVE-2022-27925HIGH7.2Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts file...
CVE-2022-27924HIGH7.5Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 allows an unauthenticated attacker to inject arbitrary memcache commands i...
CVE-2022-29537MEDIUM5.5gp_rtp_builder_do_hevc in ietf/rtp_pck_mpeg4.c in GPAC 2.0.0 has a heap-based buffer over-read, as demonstrated by MP4Bo...
CVE-2022-29536HIGH7.5In GNOME Epiphany before 41.4 and 42.x before 42.2, an HTML document can trigger a client buffer overflow (in ephy_strin...
CVE-2022-29534HIGH7.5An issue was discovered in MISP before 2.4.158. In UsersController.php, password confirmation can be bypassed via vector...
CVE-2022-29533MEDIUM6.1An issue was discovered in MISP before 2.4.158. There is XSS in app/Controller/OrganisationsController.php in a situatio...
CVE-2022-29532MEDIUM4.8An issue was discovered in MISP before 2.4.158. There is XSS in the cerebrate view if one administrator puts a javascrip...
CVE-2022-29531MEDIUM5.4An issue was discovered in MISP before 2.4.158. There is stored XSS in the event graph via a tag name.
CVE-2022-29530MEDIUM5.4An issue was discovered in MISP before 2.4.158. There is stored XSS in the galaxy clusters.

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now