2022 CVE Vulnerabilities
27,553 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-22959 | MEDIUM | 4.3 | 0.5% | Apr 13, 2022 | VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a cross site request forgery vulnerability... |
| CVE-2022-22958 | HIGH | 7.2 | 2.9% | Apr 13, 2022 | VMware Workspace ONE Access, Identity Manager and vRealize Automation contain two remote code execution vulnerabilities ... |
| CVE-2022-22957 | HIGH | 7.2 | 21.9% | Apr 13, 2022 | VMware Workspace ONE Access, Identity Manager and vRealize Automation contain two remote code execution vulnerabilities ... |
| CVE-2022-22956 | CRITICAL | 9.8 | 49.9% | Apr 13, 2022 | VMware Workspace ONE Access has two authentication bypass vulnerabilities (CVE-2022-22955 & CVE-2022-22956) in the OAuth... |
| CVE-2022-22955 | CRITICAL | 9.8 | 7.6% | Apr 13, 2022 | VMware Workspace ONE Access has two authentication bypass vulnerabilities (CVE-2022-22955 & CVE-2022-22956) in the OAuth... |
| CVE-2022-1346 | CRITICAL | 9 | 1.0% | Apr 13, 2022 | Multiple Stored XSS in GitHub repository causefx/organizr prior to 2.1.1810. This allows attackers to execute malicious ... |
| CVE-2022-1344 | CRITICAL | 9 | 1.0% | Apr 13, 2022 | Stored XSS due to no sanitization in the filename in GitHub repository causefx/organizr prior to 2.1.1810. This allows a... |
| CVE-2022-1337 | MEDIUM | 6.5 | 0.9% | Apr 13, 2022 | The image proxy component in Mattermost version 6.4.1 and earlier allocates memory for multiple copies of a proxied imag... |
| CVE-2022-1333 | MEDIUM | 6.5 | 0.7% | Apr 13, 2022 | Mattermost Playbooks plugin v1.24.0 and earlier fails to properly check the limit on the number of webhooks, which allow... |
| CVE-2022-1332 | MEDIUM | 4.3 | 0.6% | Apr 13, 2022 | One of the API in Mattermost version 6.4.1 and earlier fails to properly protect the permissions, which allows the authe... |
| CVE-2022-1280 | MEDIUM | 6.3 | 0.3% | Apr 13, 2022 | A use-after-free vulnerability was found in drm_lease_held in drivers/gpu/drm/drm_lease.c in the Linux kernel due to a r... |
| CVE-2022-1246 | — | — | — | Apr 13, 2022 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2022-1280. Reason: This candidate is a reservation du... |
| CVE-2022-0221 | MEDIUM | 5.5 | 0.9% | Apr 13, 2022 | A CWE-611: Improper Restriction of XML External Entity Reference vulnerability exists that could result in information d... |
| CVE-2022-28052 | HIGH | 8 | 2.3% | Apr 13, 2022 | Directory Traversal vulnerability in file cn/roothub/store/FileSystemStorageService in function store in Roothub 2.6.0 a... |
| CVE-2022-27256 | MEDIUM | 6.1 | 1.4% | Apr 13, 2022 | A PHP Local File inclusion vulnerability in the Redbasic theme for Hubzilla before version 7.2 allows remote attackers t... |
| CVE-2022-26643 | MEDIUM | 5.3 | 1.2% | Apr 13, 2022 | An issue in EasyIO CPT Graphics v0.8 allows attackers to discover valid users in the application. |
| CVE-2022-26144 | MEDIUM | 6.1 | 0.8% | Apr 13, 2022 | An XSS issue was discovered in MantisBT before 2.25.3. Improper escaping of a Plugin name allows execution of arbitrary ... |
| CVE-2022-24308 | MEDIUM | 5.5 | 0.2% | Apr 13, 2022 | Automox Agent prior to version 37 on Windows and Linux and Version 36 on OSX could allow for a non privileged user to ob... |
| CVE-2022-27475 | MEDIUM | 6.1 | 0.7% | Apr 13, 2022 | Cross site scripting (XSS) vulnerability in tramyardg hotel-mgmt-system, allows attackers to execute arbitrary code when... |
| CVE-2022-1339 | HIGH | 7.5 | 5.6% | Apr 13, 2022 | SQL injection in ElementController.php in GitHub repository pimcore/pimcore prior to 10.3.5. This vulnerability is capab... |
| CVE-2022-29156 | HIGH | 7.8 | 0.4% | Apr 13, 2022 | drivers/infiniband/ulp/rtrs/rtrs-clt.c in the Linux kernel before 5.16.12 has a double free related to rtrs_clt_dev_rele... |
| CVE-2022-22279 | MEDIUM | 4.9 | 1.0% | Apr 13, 2022 | A post-authentication arbitrary file read vulnerability impacting end-of-life Secure Remote Access (SRA) products and ol... |
| CVE-2022-26589 | MEDIUM | 6.5 | 0.5% | Apr 13, 2022 | A Cross-Site Request Forgery (CSRF) in Pluck CMS v4.7.15 allows attackers to delete arbitrary pages. |
| CVE-2022-26151 | HIGH | 7.2 | 7.4% | Apr 13, 2022 | Citrix XenMobile Server 10.12 through RP11, 10.13 through RP7, and 10.14 through RP4 allows Command Injection. |
| CVE-2022-1330 | MEDIUM | 5.4 | 0.8% | Apr 12, 2022 | stored xss due to unsantized anchor url in GitHub repository alvarotrigo/fullpage.js prior to 4.0.4. stored xss . |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now