2022 CVE Vulnerabilities
27,553 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-24875 | HIGH | 7.5 | 0.9% | Apr 21, 2022 | The CVEProject/cve-services is an open source project used to operate the CVE services api. In versions up to and includ... |
| CVE-2022-24870 | MEDIUM | 5.4 | 0.9% | Apr 21, 2022 | Combodo iTop is a web based IT Service Management tool. In 3.0.0 beta releases prior to 3.0.0 beta3 a malicious script c... |
| CVE-2022-24869 | MEDIUM | 5.4 | 0.7% | Apr 21, 2022 | GLPI is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and... |
| CVE-2022-24868 | MEDIUM | 5.4 | 0.6% | Apr 21, 2022 | GLPI is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and... |
| CVE-2022-24867 | HIGH | 7.5 | 1.2% | Apr 21, 2022 | GLPI is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and... |
| CVE-2022-22436 | MEDIUM | 5.4 | 0.4% | Apr 21, 2022 | IBM Maximo Asset Management 7.6.1.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbi... |
| CVE-2022-22435 | MEDIUM | 5.4 | 0.4% | Apr 21, 2022 | IBM Maximo Asset Management 7.6.1.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbi... |
| CVE-2022-0272 | CRITICAL | 9.8 | 1.4% | Apr 21, 2022 | Improper Restriction of XML External Entity Reference in GitHub repository detekt/detekt prior to 1.20.0. |
| CVE-2022-1022 | MEDIUM | 5.4 | 4.5% | Apr 21, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository chatwoot/chatwoot prior to 2.5.0. |
| CVE-2022-24272 | MEDIUM | 6.5 | 0.8% | Apr 21, 2022 | An authenticated user may trigger an invariant assertion during command dispatch due to incorrect validation on the $ext... |
| CVE-2022-1420 | MEDIUM | 5.5 | 1.4% | Apr 21, 2022 | Use of Out-of-range Pointer Offset in GitHub repository vim/vim prior to 8.2.4774. |
| CVE-2022-29498 | HIGH | 7.5 | 0.8% | Apr 21, 2022 | Blazer before 2.6.0 allows SQL Injection. In certain circumstances, an attacker could get a user to run a query they wou... |
| CVE-2022-27237 | MEDIUM | 6.1 | 0.5% | Apr 21, 2022 | There is a cross-site scripting (XSS) vulnerability in an NI Web Server component installed with several NI products. De... |
| CVE-2022-29548 | MEDIUM | 6.1 | 40.5% | Apr 21, 2022 | A reflected XSS issue exists in the Management Console of several WSO2 products. This affects API Manager 2.2.0, 2.5.0, ... |
| CVE-2022-29547 | HIGH | 7.5 | 0.9% | Apr 21, 2022 | The CreateRedirect extension before 2022-04-14 for MediaWiki does not properly check whether the user has permissions to... |
| CVE-2022-27926 | MEDIUM | 6.1 | 17.3% | Apr 21, 2022 | A reflected cross-site scripting (XSS) vulnerability in the /public/launchNewWindow.jsp component of Zimbra Collaboratio... |
| CVE-2022-27925 | HIGH | 7.2 | 98.6% | Apr 21, 2022 | Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts file... |
| CVE-2022-27924 | HIGH | 7.5 | 85.4% | Apr 21, 2022 | Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 allows an unauthenticated attacker to inject arbitrary memcache commands i... |
| CVE-2022-29537 | MEDIUM | 5.5 | 0.6% | Apr 20, 2022 | gp_rtp_builder_do_hevc in ietf/rtp_pck_mpeg4.c in GPAC 2.0.0 has a heap-based buffer over-read, as demonstrated by MP4Bo... |
| CVE-2022-29536 | HIGH | 7.5 | 1.9% | Apr 20, 2022 | In GNOME Epiphany before 41.4 and 42.x before 42.2, an HTML document can trigger a client buffer overflow (in ephy_strin... |
| CVE-2022-29534 | HIGH | 7.5 | 1.5% | Apr 20, 2022 | An issue was discovered in MISP before 2.4.158. In UsersController.php, password confirmation can be bypassed via vector... |
| CVE-2022-29533 | MEDIUM | 6.1 | 0.8% | Apr 20, 2022 | An issue was discovered in MISP before 2.4.158. There is XSS in app/Controller/OrganisationsController.php in a situatio... |
| CVE-2022-29532 | MEDIUM | 4.8 | 0.8% | Apr 20, 2022 | An issue was discovered in MISP before 2.4.158. There is XSS in the cerebrate view if one administrator puts a javascrip... |
| CVE-2022-29531 | MEDIUM | 5.4 | 0.8% | Apr 20, 2022 | An issue was discovered in MISP before 2.4.158. There is stored XSS in the event graph via a tag name. |
| CVE-2022-29530 | MEDIUM | 5.4 | 0.8% | Apr 20, 2022 | An issue was discovered in MISP before 2.4.158. There is stored XSS in the galaxy clusters. |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now