2022 CVE Vulnerabilities

27,553 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-29529MEDIUM5.4An issue was discovered in MISP before 2.4.158. There is stored XSS via the LinOTP login field.
CVE-2022-29528CRITICAL9.8An issue was discovered in MISP before 2.4.158. PHAR deserialization can occur.
CVE-2022-24874Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2022-28820. Reason: This candidate is a reservation d...
CVE-2022-24872HIGH8.1Shopware is an open commerce platform based on Symfony Framework and Vue. Permissions set to sales channel context by ad...
CVE-2022-24865MEDIUM6.5HumHub is an Open Source Enterprise Social Network. In affected versions users who are forced to change their password b...
CVE-2022-26133CRITICAL9.8SharedSecretClusterAuthenticator in Atlassian Bitbucket Data Center versions 5.14.0 and later before 7.6.14, 7.7.0 and l...
CVE-2022-24871MEDIUM5.5Shopware is an open commerce platform based on Symfony Framework and Vue. In affected versions an attacker can abuse the...
CVE-2022-24864MEDIUM5.4Origin Protocol is a blockchain based project. The Origin Protocol project website allows for malicious users to inject ...
CVE-2022-24862HIGH7.7Databasir is a team-oriented relational database model document management platform. Databasir 1.01 has Server-Side Requ...
CVE-2022-24861HIGH8.8Databasir is a team-oriented relational database model document management platform. Databasir 1.01 has remote code exec...
CVE-2022-0540CRITICAL9.8A vulnerability in Jira Seraph allows a remote, unauthenticated attacker to bypass authentication by sending a specially...
CVE-2022-24799MEDIUM6.1wire-webapp is the web application interface for the wire messaging service. Insufficient escaping in markdown “code hig...
CVE-2022-27179MEDIUM6.5A malicious actor having access to the exported configuration file may obtain the stored credentials and thereby gain ac...
CVE-2022-26519MEDIUM5.5There is no limit to the number of attempts to authenticate for the local configuration pages for the Hills ComNav Versi...
CVE-2022-26516HIGH7.8Authorized users may install a maliciously modified package file when updating the device via the web user interface. Th...
CVE-2022-1318MEDIUM5.5Hills ComNav version 3002-19 suffers from a weak communication channel. Traffic across the local network for the configu...
CVE-2022-1039CRITICAL9.8The weak password on the web user interface can be exploited via HTTP or HTTPS. Once such access has been obtained, the ...
CVE-2022-0567CRITICAL9.1A flaw was found in ovn-kubernetes. This flaw allows a system administrator or privileged attacker to create an egress n...
CVE-2022-25344MEDIUM6.1An XSS issue was discovered on Olivetti d-COLOR MF3555 2XD_S000.002.271 devices. The Web Application doesn't properly ch...
CVE-2022-25343HIGH7.5An issue was discovered on Olivetti d-COLOR MF3555 2XD_S000.002.271 devices. The Web Application is affected by Denial o...
CVE-2022-25342HIGH8.1An issue was discovered on Olivetti d-COLOR MF3555 2XD_S000.002.271 devices. The Web Application is affected by Broken A...
CVE-2022-1254MEDIUM6.1A URL redirection vulnerability in Skyhigh SWG in main releases 10.x prior to 10.2.9, 9.x prior to 9.2.20, 8.x prior to ...
CVE-2022-29527HIGH7Amazon AWS amazon-ssm-agent before 3.1.1208.0 creates a world-writable sudoers file, which allows local attackers to inj...
CVE-2022-28327HIGH7.5The generic P-256 feature in crypto/elliptic in Go before 1.17.9 and 1.18.x before 1.18.1 allows a panic via long scalar...
CVE-2022-27536HIGH7.5Certificate.Verify in crypto/x509 in Go 1.18.x before 1.18.1 can be caused to panic on macOS when presented with certain...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now