2022 CVE Vulnerabilities
27,553 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-29529 | MEDIUM | 5.4 | 0.8% | Apr 20, 2022 | An issue was discovered in MISP before 2.4.158. There is stored XSS via the LinOTP login field. |
| CVE-2022-29528 | CRITICAL | 9.8 | 2.1% | Apr 20, 2022 | An issue was discovered in MISP before 2.4.158. PHAR deserialization can occur. |
| CVE-2022-24874 | — | — | — | Apr 20, 2022 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2022-28820. Reason: This candidate is a reservation d... |
| CVE-2022-24872 | HIGH | 8.1 | 1.0% | Apr 20, 2022 | Shopware is an open commerce platform based on Symfony Framework and Vue. Permissions set to sales channel context by ad... |
| CVE-2022-24865 | MEDIUM | 6.5 | 1.2% | Apr 20, 2022 | HumHub is an Open Source Enterprise Social Network. In affected versions users who are forced to change their password b... |
| CVE-2022-26133 | CRITICAL | 9.8 | 71.4% | Apr 20, 2022 | SharedSecretClusterAuthenticator in Atlassian Bitbucket Data Center versions 5.14.0 and later before 7.6.14, 7.7.0 and l... |
| CVE-2022-24871 | MEDIUM | 5.5 | 1.0% | Apr 20, 2022 | Shopware is an open commerce platform based on Symfony Framework and Vue. In affected versions an attacker can abuse the... |
| CVE-2022-24864 | MEDIUM | 5.4 | 0.6% | Apr 20, 2022 | Origin Protocol is a blockchain based project. The Origin Protocol project website allows for malicious users to inject ... |
| CVE-2022-24862 | HIGH | 7.7 | 1.0% | Apr 20, 2022 | Databasir is a team-oriented relational database model document management platform. Databasir 1.01 has Server-Side Requ... |
| CVE-2022-24861 | HIGH | 8.8 | 2.8% | Apr 20, 2022 | Databasir is a team-oriented relational database model document management platform. Databasir 1.01 has remote code exec... |
| CVE-2022-0540 | CRITICAL | 9.8 | 88.3% | Apr 20, 2022 | A vulnerability in Jira Seraph allows a remote, unauthenticated attacker to bypass authentication by sending a specially... |
| CVE-2022-24799 | MEDIUM | 6.1 | 0.9% | Apr 20, 2022 | wire-webapp is the web application interface for the wire messaging service. Insufficient escaping in markdown “code hig... |
| CVE-2022-27179 | MEDIUM | 6.5 | 0.5% | Apr 20, 2022 | A malicious actor having access to the exported configuration file may obtain the stored credentials and thereby gain ac... |
| CVE-2022-26519 | MEDIUM | 5.5 | 0.2% | Apr 20, 2022 | There is no limit to the number of attempts to authenticate for the local configuration pages for the Hills ComNav Versi... |
| CVE-2022-26516 | HIGH | 7.8 | 0.3% | Apr 20, 2022 | Authorized users may install a maliciously modified package file when updating the device via the web user interface. Th... |
| CVE-2022-1318 | MEDIUM | 5.5 | 0.1% | Apr 20, 2022 | Hills ComNav version 3002-19 suffers from a weak communication channel. Traffic across the local network for the configu... |
| CVE-2022-1039 | CRITICAL | 9.8 | 1.1% | Apr 20, 2022 | The weak password on the web user interface can be exploited via HTTP or HTTPS. Once such access has been obtained, the ... |
| CVE-2022-0567 | CRITICAL | 9.1 | 1.0% | Apr 20, 2022 | A flaw was found in ovn-kubernetes. This flaw allows a system administrator or privileged attacker to create an egress n... |
| CVE-2022-25344 | MEDIUM | 6.1 | 0.7% | Apr 20, 2022 | An XSS issue was discovered on Olivetti d-COLOR MF3555 2XD_S000.002.271 devices. The Web Application doesn't properly ch... |
| CVE-2022-25343 | HIGH | 7.5 | 1.3% | Apr 20, 2022 | An issue was discovered on Olivetti d-COLOR MF3555 2XD_S000.002.271 devices. The Web Application is affected by Denial o... |
| CVE-2022-25342 | HIGH | 8.1 | 1.0% | Apr 20, 2022 | An issue was discovered on Olivetti d-COLOR MF3555 2XD_S000.002.271 devices. The Web Application is affected by Broken A... |
| CVE-2022-1254 | MEDIUM | 6.1 | 0.8% | Apr 20, 2022 | A URL redirection vulnerability in Skyhigh SWG in main releases 10.x prior to 10.2.9, 9.x prior to 9.2.20, 8.x prior to ... |
| CVE-2022-29527 | HIGH | 7 | 0.3% | Apr 20, 2022 | Amazon AWS amazon-ssm-agent before 3.1.1208.0 creates a world-writable sudoers file, which allows local attackers to inj... |
| CVE-2022-28327 | HIGH | 7.5 | 3.9% | Apr 20, 2022 | The generic P-256 feature in crypto/elliptic in Go before 1.17.9 and 1.18.x before 1.18.1 allows a panic via long scalar... |
| CVE-2022-27536 | HIGH | 7.5 | 1.3% | Apr 20, 2022 | Certificate.Verify in crypto/x509 in Go 1.18.x before 1.18.1 can be caused to panic on macOS when presented with certain... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now