2022 CVE Vulnerabilities
27,553 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-27126 | CRITICAL | 9.8 | 1.0% | Apr 10, 2022 | zbzcms v1.0 was discovered to contain a SQL injection vulnerability via the art parameter at /include/make.php. |
| CVE-2022-27125 | MEDIUM | 6.1 | 0.6% | Apr 10, 2022 | zbzcms v1.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the neirong parameter at /ph... |
| CVE-2022-1291 | MEDIUM | 5.4 | 0.7% | Apr 10, 2022 | XSS vulnerability with default `onCellHtmlData` function in GitHub repository hhurz/tableexport.jquery.plugin prior to 1... |
| CVE-2022-1290 | MEDIUM | 5.4 | 1.6% | Apr 10, 2022 | Stored XSS in "Name", "Group Name" & "Title" in GitHub repository polonel/trudesk prior to v1.2.0. This allows attackers... |
| CVE-2022-1289 | MEDIUM | 6.5 | 1.1% | Apr 10, 2022 | A denial of service vulnerability was found in tildearrow Furnace. It has been classified as problematic. This is due to... |
| CVE-2022-1286 | CRITICAL | 9.8 | 1.1% | Apr 10, 2022 | heap-buffer-overflow in mrb_vm_exec in mruby/mruby in GitHub repository mruby/mruby prior to 3.2. Possible arbitrary cod... |
| CVE-2022-1276 | CRITICAL | 9.8 | 1.4% | Apr 10, 2022 | Out-of-bounds Read in mrb_get_args in GitHub repository mruby/mruby prior to 3.2. Possible arbitrary code execution if b... |
| CVE-2022-1288 | MEDIUM | 6.1 | 0.5% | Apr 9, 2022 | A vulnerability, which was classified as problematic, has been found in School Club Application System 1.0. This issue a... |
| CVE-2022-1287 | CRITICAL | 9.8 | 0.7% | Apr 9, 2022 | A vulnerability classified as critical was found in School Club Application System 1.0. This vulnerability affects a req... |
| CVE-2022-28365 | MEDIUM | 5.3 | 8.0% | Apr 9, 2022 | Reprise License Manager 14.2 is affected by an Information Disclosure vulnerability via a GET request to /goforms/rlminf... |
| CVE-2022-28364 | MEDIUM | 5.4 | 0.9% | Apr 9, 2022 | Reprise License Manager 14.2 is affected by a reflected cross-site scripting vulnerability (XSS) in the /goform/rlmswitc... |
| CVE-2022-28363 | MEDIUM | 6.1 | 4.2% | Apr 9, 2022 | Reprise License Manager 14.2 is affected by a reflected cross-site scripting vulnerability (XSS) in the /goform/login_pr... |
| CVE-2022-27149 | — | — | — | Apr 9, 2022 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2022-26877 | MEDIUM | 6.5 | 1.1% | Apr 9, 2022 | Asana Desktop before 1.6.0 allows remote attackers to exfiltrate local files if they can trick the Asana desktop app int... |
| CVE-2022-27883 | HIGH | 7.3 | 1.2% | Apr 9, 2022 | A link following vulnerability in Trend Micro Antivirus for Mac 11.5 could allow an attacker to create a specially-craft... |
| CVE-2022-26588 | MEDIUM | 6.5 | 0.6% | Apr 8, 2022 | A Cross-Site Request Forgery (CSRF) in IceHrm 31.0.0.OS allows attackers to delete arbitrary users or achieve account ta... |
| CVE-2022-26180 | HIGH | 8.8 | 3.8% | Apr 8, 2022 | qdPM 9.2 allows Cross-Site Request Forgery (CSRF) via the index.php/myAccount/update URI. |
| CVE-2022-26855 | MEDIUM | 5.5 | 0.2% | Apr 8, 2022 | Dell PowerScale OneFS, versions 8.2.x-9.3.0.x, contains an incorrect default permissions vulnerability. A local maliciou... |
| CVE-2022-26854 | CRITICAL | 9.8 | 0.7% | Apr 8, 2022 | Dell PowerScale OneFS, versions 8.2.x-9.2.x, contain risky cryptographic algorithms. A remote unprivileged malicious att... |
| CVE-2022-26852 | CRITICAL | 9.8 | 1.2% | Apr 8, 2022 | Dell PowerScale OneFS, versions 8.2.x-9.3.x, contain a predictable seed in pseudo-random number generator. A remote unau... |
| CVE-2022-26851 | CRITICAL | 9.1 | 0.9% | Apr 8, 2022 | Dell PowerScale OneFS, 8.2.2-9.3.x, contains a predictable file name from observable state vulnerability. An unprivilege... |
| CVE-2022-24820 | MEDIUM | 5.3 | 1.0% | Apr 8, 2022 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. A guest user wi... |
| CVE-2022-24819 | MEDIUM | 5.3 | 3.3% | Apr 8, 2022 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. A guest user wi... |
| CVE-2022-24428 | HIGH | 8.8 | 0.6% | Apr 8, 2022 | Dell PowerScale OneFS, versions 8.2.x, 9.0.0.x, 9.1.0.x, 9.2.0.x, 9.2.1.x, and 9.3.0.x, contain an improper preservation... |
| CVE-2022-22563 | MEDIUM | 4.4 | 0.2% | Apr 8, 2022 | Dell EMC Powerscale OneFS 8.2.x - 9.2.x omit security-relevant information in /etc/master.passwd. A high-privileged user... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now