2022 CVE Vulnerabilities

27,553 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-27126CRITICAL9.8zbzcms v1.0 was discovered to contain a SQL injection vulnerability via the art parameter at /include/make.php.
CVE-2022-27125MEDIUM6.1zbzcms v1.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the neirong parameter at /ph...
CVE-2022-1291MEDIUM5.4XSS vulnerability with default `onCellHtmlData` function in GitHub repository hhurz/tableexport.jquery.plugin prior to 1...
CVE-2022-1290MEDIUM5.4Stored XSS in "Name", "Group Name" & "Title" in GitHub repository polonel/trudesk prior to v1.2.0. This allows attackers...
CVE-2022-1289MEDIUM6.5A denial of service vulnerability was found in tildearrow Furnace. It has been classified as problematic. This is due to...
CVE-2022-1286CRITICAL9.8heap-buffer-overflow in mrb_vm_exec in mruby/mruby in GitHub repository mruby/mruby prior to 3.2. Possible arbitrary cod...
CVE-2022-1276CRITICAL9.8Out-of-bounds Read in mrb_get_args in GitHub repository mruby/mruby prior to 3.2. Possible arbitrary code execution if b...
CVE-2022-1288MEDIUM6.1A vulnerability, which was classified as problematic, has been found in School Club Application System 1.0. This issue a...
CVE-2022-1287CRITICAL9.8A vulnerability classified as critical was found in School Club Application System 1.0. This vulnerability affects a req...
CVE-2022-28365MEDIUM5.3Reprise License Manager 14.2 is affected by an Information Disclosure vulnerability via a GET request to /goforms/rlminf...
CVE-2022-28364MEDIUM5.4Reprise License Manager 14.2 is affected by a reflected cross-site scripting vulnerability (XSS) in the /goform/rlmswitc...
CVE-2022-28363MEDIUM6.1Reprise License Manager 14.2 is affected by a reflected cross-site scripting vulnerability (XSS) in the /goform/login_pr...
CVE-2022-27149Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2022-26877MEDIUM6.5Asana Desktop before 1.6.0 allows remote attackers to exfiltrate local files if they can trick the Asana desktop app int...
CVE-2022-27883HIGH7.3A link following vulnerability in Trend Micro Antivirus for Mac 11.5 could allow an attacker to create a specially-craft...
CVE-2022-26588MEDIUM6.5A Cross-Site Request Forgery (CSRF) in IceHrm 31.0.0.OS allows attackers to delete arbitrary users or achieve account ta...
CVE-2022-26180HIGH8.8qdPM 9.2 allows Cross-Site Request Forgery (CSRF) via the index.php/myAccount/update URI.
CVE-2022-26855MEDIUM5.5Dell PowerScale OneFS, versions 8.2.x-9.3.0.x, contains an incorrect default permissions vulnerability. A local maliciou...
CVE-2022-26854CRITICAL9.8Dell PowerScale OneFS, versions 8.2.x-9.2.x, contain risky cryptographic algorithms. A remote unprivileged malicious att...
CVE-2022-26852CRITICAL9.8Dell PowerScale OneFS, versions 8.2.x-9.3.x, contain a predictable seed in pseudo-random number generator. A remote unau...
CVE-2022-26851CRITICAL9.1Dell PowerScale OneFS, 8.2.2-9.3.x, contains a predictable file name from observable state vulnerability. An unprivilege...
CVE-2022-24820MEDIUM5.3XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. A guest user wi...
CVE-2022-24819MEDIUM5.3XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. A guest user wi...
CVE-2022-24428HIGH8.8Dell PowerScale OneFS, versions 8.2.x, 9.0.0.x, 9.1.0.x, 9.2.0.x, 9.2.1.x, and 9.3.0.x, contain an improper preservation...
CVE-2022-22563MEDIUM4.4Dell EMC Powerscale OneFS 8.2.x - 9.2.x omit security-relevant information in /etc/master.passwd. A high-privileged user...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now