2022 CVE Vulnerabilities
27,553 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-24780 | HIGH | 8.8 | 5.3% | Apr 5, 2022 | Combodo iTop is a web based IT Service Management tool. In versions prior to 2.7.6 and 3.0.0, users of the iTop user por... |
| CVE-2022-1244 | MEDIUM | 5.5 | 0.8% | Apr 5, 2022 | heap-buffer-overflow in GitHub repository radareorg/radare2 prior to 5.6.8. This vulnerability is capable of inducing de... |
| CVE-2022-28651 | MEDIUM | 5.5 | 0.3% | Apr 5, 2022 | In JetBrains IntelliJ IDEA before 2021.3.3 it was possible to get passwords from protected fields |
| CVE-2022-28650 | MEDIUM | 5.4 | 0.6% | Apr 5, 2022 | In JetBrains YouTrack before 2022.1.43700 it was possible to inject JavaScript into Markdown in the YouTrack Classic UI |
| CVE-2022-28649 | MEDIUM | 5.4 | 0.4% | Apr 5, 2022 | In JetBrains YouTrack before 2022.1.43563 it was possible to include an iframe from a third-party domain in the issue de... |
| CVE-2022-28648 | MEDIUM | 5.4 | 1.3% | Apr 5, 2022 | In JetBrains YouTrack before 2022.1.43563 HTML code from the issue description was being rendered |
| CVE-2022-26630 | HIGH | 8.8 | 0.9% | Apr 5, 2022 | Jellycms v3.8.1 and below was discovered to contain an arbitrary file upload vulnerability via \app.\admin\Controllers\d... |
| CVE-2022-26635 | CRITICAL | 9.8 | 21.4% | Apr 5, 2022 | PHP-Memcached v2.2.0 and below contains an improper NULL termination which allows attackers to execute CLRF injection. N... |
| CVE-2022-22356 | MEDIUM | 6.5 | 0.8% | Apr 5, 2022 | IBM MQ Appliance 9.2 CD and 9.2 LTS could allow an attacker to enumerate account credentials due to an observable discre... |
| CVE-2022-22355 | MEDIUM | 5.3 | 1.1% | Apr 5, 2022 | IBM MQ Appliance 9.2 CD and 9.2 LTS are vulnerable to a denial of service in the Login component of the application whic... |
| CVE-2022-27463 | MEDIUM | 6.1 | 0.6% | Apr 5, 2022 | Open redirect vulnerability in objects/login.json.php in WWBN AVideo through 11.6, allows attackers to arbitrarily redir... |
| CVE-2022-27462 | MEDIUM | 6.1 | 0.6% | Apr 5, 2022 | Cross Site Scripting (XSS) vulnerability in objects/function.php in function getDeviceID in WWBN AVideo through 11.6, vi... |
| CVE-2022-24795 | HIGH | 7.5 | 3.5% | Apr 5, 2022 | yajl-ruby is a C binding to the YAJL JSON parsing and generation library. The 1.x branch and the 2.x branch of `yajl` co... |
| CVE-2022-0602 | MEDIUM | 5.4 | 0.7% | Apr 5, 2022 | Cross-site Scripting (XSS) - DOM in GitHub repository tastyigniter/tastyigniter prior to 3.3.0. |
| CVE-2022-26986 | HIGH | 7.2 | 4.1% | Apr 5, 2022 | SQL Injection in ImpressCMS 1.4.3 and earlier allows remote attackers to inject into the code in unintended way, this al... |
| CVE-2022-26982 | HIGH | 7.2 | 9.2% | Apr 5, 2022 | SimpleMachinesForum 2.1.1 and earlier allows remote authenticated administrators to execute arbitrary code by inserting ... |
| CVE-2022-1243 | MEDIUM | 6.1 | 0.7% | Apr 5, 2022 | CRHTLF can lead to invalid protocol extraction potentially leading to XSS in GitHub repository medialize/uri.js prior to... |
| CVE-2022-26361 | HIGH | 7.8 | 0.3% | Apr 5, 2022 | IOMMU: RMRR (VT-d) and unity map (AMD-Vi) handling issues T[his CNA information record relates to multiple CVEs; the tex... |
| CVE-2022-26360 | HIGH | 7.8 | 0.3% | Apr 5, 2022 | IOMMU: RMRR (VT-d) and unity map (AMD-Vi) handling issues T[his CNA information record relates to multiple CVEs; the tex... |
| CVE-2022-26359 | HIGH | 7.8 | 0.3% | Apr 5, 2022 | IOMMU: RMRR (VT-d) and unity map (AMD-Vi) handling issues T[his CNA information record relates to multiple CVEs; the tex... |
| CVE-2022-26358 | HIGH | 7.8 | 0.3% | Apr 5, 2022 | IOMMU: RMRR (VT-d) and unity map (AMD-Vi) handling issues T[his CNA information record relates to multiple CVEs; the tex... |
| CVE-2022-26357 | HIGH | 7 | 0.2% | Apr 5, 2022 | race in VT-d domain ID cleanup Xen domain IDs are up to 15 bits wide. VT-d hardware may allow for only less than 15 bits... |
| CVE-2022-26356 | MEDIUM | 5.6 | 0.2% | Apr 5, 2022 | Racy interactions between dirty vram tracking and paging log dirty hypercalls Activation of log dirty mode done by XEN_D... |
| CVE-2022-1236 | MEDIUM | 6.5 | 0.5% | Apr 5, 2022 | Weak Password Requirements in GitHub repository weseek/growi prior to v5.0.0. |
| CVE-2022-1235 | HIGH | 8.2 | 0.5% | Apr 5, 2022 | Weak secrethash can be brute-forced in GitHub repository livehelperchat/livehelperchat prior to 3.96. |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now