2022 CVE Vulnerabilities
27,553 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-20741 | MEDIUM | 5.4 | 0.6% | Apr 6, 2022 | A vulnerability in the web-based management interface of the Network Diagrams application for Cisco Secure Network Analy... |
| CVE-2022-20675 | MEDIUM | 5.3 | 1.2% | Apr 6, 2022 | A vulnerability in the TCP/IP stack of Cisco Email Security Appliance (ESA), Cisco Web Security Appliance (WSA), and Cis... |
| CVE-2022-20665 | MEDIUM | 6.7 | 0.3% | Apr 6, 2022 | A vulnerability in the CLI of Cisco StarOS could allow an authenticated, local attacker to elevate privileges on an affe... |
| CVE-2022-26850 | MEDIUM | 4.3 | 1.4% | Apr 6, 2022 | When creating or updating credentials for single-user access, Apache NiFi wrote a copy of the Login Identity Providers c... |
| CVE-2022-24822 | HIGH | 7.5 | 1.6% | Apr 6, 2022 | Podium is a library for building micro frontends. @podium/layout is a module for building a Podium layout server, and @p... |
| CVE-2022-20784 | MEDIUM | 5.3 | 0.9% | Apr 6, 2022 | A vulnerability in the Web-Based Reputation Score (WBRS) engine of Cisco AsyncOS Software for Cisco Web Security Applian... |
| CVE-2022-22410 | HIGH | 7.2 | 0.7% | Apr 6, 2022 | IBM Watson Query with Cloud Pak for Data as a Service could allow an authenticated user to obtain sensitive information ... |
| CVE-2022-27110 | MEDIUM | 5.4 | 0.5% | Apr 6, 2022 | OrangeHRM 4.10 is vulnerable to a Host header injection redirect via viewPersonalDetails endpoint. |
| CVE-2022-27109 | MEDIUM | 5.4 | 0.5% | Apr 6, 2022 | OrangeHRM 4.10 suffers from a Referer header injection redirect vulnerability. |
| CVE-2022-27108 | MEDIUM | 4.3 | 0.6% | Apr 6, 2022 | OrangeHRM 4.10 is vulnerable to Insecure Direct Object Reference (IDOR) via the end point symfony/web/index.php/time/cre... |
| CVE-2022-27107 | MEDIUM | 5.4 | 0.5% | Apr 6, 2022 | OrangeHRM 4.10 is vulnerable to Stored XSS in the "Share Video" section under "OrangeBuzz" via the GET/POST "createVideo... |
| CVE-2022-24793 | HIGH | 7.5 | 2.1% | Apr 6, 2022 | PJSIP is a free and open source multimedia communication library written in C. A buffer overflow vulnerability in versio... |
| CVE-2022-24786 | CRITICAL | 9.8 | 1.9% | Apr 6, 2022 | PJSIP is a free and open source multimedia communication library written in C. PJSIP versions 2.12 and prior do not pars... |
| CVE-2022-1253 | CRITICAL | 9.8 | 2.0% | Apr 6, 2022 | Heap-based Buffer Overflow in GitHub repository strukturag/libde265 prior to and including 1.0.8. The fix is established... |
| CVE-2022-1240 | HIGH | 7.8 | 0.7% | Apr 6, 2022 | Heap buffer overflow in libr/bin/format/mach0/mach0.c in GitHub repository radareorg/radare2 prior to 5.8.6. If address ... |
| CVE-2022-23440 | HIGH | 7.8 | 0.2% | Apr 6, 2022 | A use of hard-coded cryptographic key vulnerability [CWE-321] in the registration mechanism of FortiEDR collectors versi... |
| CVE-2022-1238 | HIGH | 7.8 | 0.8% | Apr 6, 2022 | Out-of-bounds Write in libr/bin/format/ne/ne.c in GitHub repository radareorg/radare2 prior to 5.6.8. This vulnerability... |
| CVE-2022-1237 | HIGH | 7.8 | 0.8% | Apr 6, 2022 | Improper Validation of Array Index in GitHub repository radareorg/radare2 prior to 5.6.8. This vulnerability is heap ove... |
| CVE-2022-23446 | MEDIUM | 4.4 | 0.2% | Apr 6, 2022 | A improper control of a resource through its lifetime in Fortinet FortiEDR version 5.0.3 and earlier allows attacker to ... |
| CVE-2022-23441 | CRITICAL | 9.1 | 0.9% | Apr 6, 2022 | A use of hard-coded cryptographic key vulnerability [CWE-321] in FortiEDR versions 5.0.2, 5.0.1, 5.0.0, 4.0.0 may allow ... |
| CVE-2022-1234 | MEDIUM | 6.1 | 0.7% | Apr 6, 2022 | XSS in livehelperchat in GitHub repository livehelperchat/livehelperchat prior to 3.97. This vulnerability has the poten... |
| CVE-2022-1248 | HIGH | 7.3 | 1.3% | Apr 6, 2022 | A vulnerability was found in SAP Information System 1.0 which has been rated as critical. Affected by this issue is the ... |
| CVE-2022-26110 | HIGH | 8.8 | 1.5% | Apr 6, 2022 | An issue was discovered in HTCondor 8.8.x before 8.8.16, 9.0.x before 9.0.10, and 9.1.x before 9.6.0. When a user authen... |
| CVE-2022-26953 | HIGH | 7.5 | 1.8% | Apr 6, 2022 | Digi Passport Firmware through 1.5.1,1 is affected by a buffer overflow. An attacker can supply a string in the page par... |
| CVE-2022-26952 | HIGH | 7.5 | 2.0% | Apr 6, 2022 | Digi Passport Firmware through 1.5.1,1 is affected by a buffer overflow in the function for building the Location header... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now