2022 CVE Vulnerabilities

27,553 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-22959MEDIUM4.3VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a cross site request forgery vulnerability...
CVE-2022-22958HIGH7.2VMware Workspace ONE Access, Identity Manager and vRealize Automation contain two remote code execution vulnerabilities ...
CVE-2022-22957HIGH7.2VMware Workspace ONE Access, Identity Manager and vRealize Automation contain two remote code execution vulnerabilities ...
CVE-2022-22956CRITICAL9.8VMware Workspace ONE Access has two authentication bypass vulnerabilities (CVE-2022-22955 & CVE-2022-22956) in the OAuth...
CVE-2022-22955CRITICAL9.8VMware Workspace ONE Access has two authentication bypass vulnerabilities (CVE-2022-22955 & CVE-2022-22956) in the OAuth...
CVE-2022-1346CRITICAL9Multiple Stored XSS in GitHub repository causefx/organizr prior to 2.1.1810. This allows attackers to execute malicious ...
CVE-2022-1344CRITICAL9Stored XSS due to no sanitization in the filename in GitHub repository causefx/organizr prior to 2.1.1810. This allows a...
CVE-2022-1337MEDIUM6.5The image proxy component in Mattermost version 6.4.1 and earlier allocates memory for multiple copies of a proxied imag...
CVE-2022-1333MEDIUM6.5Mattermost Playbooks plugin v1.24.0 and earlier fails to properly check the limit on the number of webhooks, which allow...
CVE-2022-1332MEDIUM4.3One of the API in Mattermost version 6.4.1 and earlier fails to properly protect the permissions, which allows the authe...
CVE-2022-1280MEDIUM6.3A use-after-free vulnerability was found in drm_lease_held in drivers/gpu/drm/drm_lease.c in the Linux kernel due to a r...
CVE-2022-1246Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2022-1280. Reason: This candidate is a reservation du...
CVE-2022-0221MEDIUM5.5A CWE-611: Improper Restriction of XML External Entity Reference vulnerability exists that could result in information d...
CVE-2022-28052HIGH8Directory Traversal vulnerability in file cn/roothub/store/FileSystemStorageService in function store in Roothub 2.6.0 a...
CVE-2022-27256MEDIUM6.1A PHP Local File inclusion vulnerability in the Redbasic theme for Hubzilla before version 7.2 allows remote attackers t...
CVE-2022-26643MEDIUM5.3An issue in EasyIO CPT Graphics v0.8 allows attackers to discover valid users in the application.
CVE-2022-26144MEDIUM6.1An XSS issue was discovered in MantisBT before 2.25.3. Improper escaping of a Plugin name allows execution of arbitrary ...
CVE-2022-24308MEDIUM5.5Automox Agent prior to version 37 on Windows and Linux and Version 36 on OSX could allow for a non privileged user to ob...
CVE-2022-27475MEDIUM6.1Cross site scripting (XSS) vulnerability in tramyardg hotel-mgmt-system, allows attackers to execute arbitrary code when...
CVE-2022-1339HIGH7.5SQL injection in ElementController.php in GitHub repository pimcore/pimcore prior to 10.3.5. This vulnerability is capab...
CVE-2022-29156HIGH7.8drivers/infiniband/ulp/rtrs/rtrs-clt.c in the Linux kernel before 5.16.12 has a double free related to rtrs_clt_dev_rele...
CVE-2022-22279MEDIUM4.9A post-authentication arbitrary file read vulnerability impacting end-of-life Secure Remote Access (SRA) products and ol...
CVE-2022-26589MEDIUM6.5A Cross-Site Request Forgery (CSRF) in Pluck CMS v4.7.15 allows attackers to delete arbitrary pages.
CVE-2022-26151HIGH7.2Citrix XenMobile Server 10.12 through RP11, 10.13 through RP7, and 10.14 through RP4 allows Command Injection.
CVE-2022-1330MEDIUM5.4stored xss due to unsantized anchor url in GitHub repository alvarotrigo/fullpage.js prior to 4.0.4. stored xss .

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now