2022 CVE Vulnerabilities
27,553 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-23136 | MEDIUM | 5.4 | 0.4% | Mar 30, 2022 | There is a stored XSS vulnerability in ZTE home gateway product. An attacker could modify the gateway name by inserting ... |
| CVE-2022-22996 | HIGH | 7.8 | 0.3% | Mar 30, 2022 | The G-RAID 4/8 Software Utility setups for Windows were affected by a DLL hijacking vulnerability. Successful exploitati... |
| CVE-2022-20002 | HIGH | 7.8 | 0.1% | Mar 30, 2022 | In incfs, there is a possible way of mounting on arbitrary paths due to a missing permission check. This could lead to l... |
| CVE-2022-0998 | HIGH | 7.8 | 0.4% | Mar 30, 2022 | An integer overflow flaw was found in the Linux kernel’s virtio device driver code in the way a user triggers the vhost_... |
| CVE-2022-25620 | CRITICAL | 9 | 0.4% | Mar 30, 2022 | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Group Functionality of Pr... |
| CVE-2022-25619 | MEDIUM | 6.7 | 0.3% | Mar 30, 2022 | Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in ping tool of Profel... |
| CVE-2022-1155 | HIGH | 7.4 | 1.0% | Mar 30, 2022 | Old sessions are not blocked by the login enable function. in GitHub repository snipe/snipe-it prior to 5.3.10. |
| CVE-2022-24131 | MEDIUM | 6.1 | 0.8% | Mar 30, 2022 | DouPHP v1.6 Release 20220121 is affected by Cross Site Scripting (XSS) through /admin/login.php in the background, which... |
| CVE-2022-1181 | MEDIUM | 5.4 | 51.5% | Mar 30, 2022 | Stored Cross Site Scripting in GitHub repository openemr/openemr prior to 6.0.0.2. |
| CVE-2022-1180 | LOW | 3.5 | 0.6% | Mar 30, 2022 | Reflected Cross Site Scripting in GitHub repository openemr/openemr prior to 6.0.0.4. |
| CVE-2022-1179 | MEDIUM | 5.4 | 76.9% | Mar 30, 2022 | Non-Privilege User Can Created New Rule and Lead to Stored Cross Site Scripting in GitHub repository openemr/openemr pri... |
| CVE-2022-1178 | MEDIUM | 5.4 | 51.6% | Mar 30, 2022 | Stored Cross Site Scripting in GitHub repository openemr/openemr prior to 6.0.0.4. |
| CVE-2022-1154 | HIGH | 7.8 | 1.5% | Mar 30, 2022 | Use after free in utf_ptr2char in GitHub repository vim/vim prior to 8.2.4646. |
| CVE-2022-23869 | MEDIUM | 6.5 | 0.7% | Mar 30, 2022 | In RuoYi v4.7.2 through the WebUI, user test1 does not have permission to reset the password of user test3, but the pass... |
| CVE-2022-23868 | HIGH | 7.8 | 0.7% | Mar 30, 2022 | RuoYi v4.7.2 contains a CSV injection vulnerability through ruoyi-admin when a victim opens .xlsx log file. |
| CVE-2022-1177 | MEDIUM | 4.3 | 0.9% | Mar 30, 2022 | Accounting User Can Download Patient Reports in openemr in GitHub repository openemr/openemr prior to 6.1.0. |
| CVE-2022-25598 | HIGH | 7.5 | 1.9% | Mar 30, 2022 | Apache DolphinScheduler user registration is vulnerable to Regular express Denial of Service (ReDoS) attacks, Apache Dol... |
| CVE-2022-1172 | MEDIUM | 5 | 0.7% | Mar 30, 2022 | Null Pointer Dereference Caused Segmentation Fault in GitHub repository gpac/gpac prior to 2.1.0-DEV. |
| CVE-2022-28209 | CRITICAL | 9.8 | 1.3% | Mar 30, 2022 | An issue was discovered in Mediawiki through 1.37.1. The check for the override-antispoof permission in the AntiSpoof ex... |
| CVE-2022-28206 | CRITICAL | 9.8 | 1.4% | Mar 30, 2022 | An issue was discovered in MediaWiki through 1.37.1. ImportPlanValidator.php in the FileImporter extension mishandles th... |
| CVE-2022-28205 | CRITICAL | 9.8 | 1.4% | Mar 30, 2022 | An issue was discovered in MediaWiki through 1.37.1. The CentralAuth extension mishandles a ttl issue for groups expirin... |
| CVE-2022-1163 | MEDIUM | 4.8 | 3.5% | Mar 30, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository mineweb/minewebcms prior to next. |
| CVE-2022-28202 | MEDIUM | 6.1 | 1.2% | Mar 30, 2022 | An XSS issue was discovered in MediaWiki before 1.35.6, 1.36.x before 1.36.4, and 1.37.x before 1.37.2. The widthheight,... |
| CVE-2022-27816 | HIGH | 7.1 | 0.5% | Mar 30, 2022 | SWHKD 1.1.5 unsafely uses the /tmp/swhks.pid pathname. There can be data loss or a denial of service. |
| CVE-2022-24693 | CRITICAL | 9.8 | 3.3% | Mar 30, 2022 | Baicells Nova436Q and Neutrino 430 devices with firmware through QRTB 2.7.8 have hardcoded credentials that are easily d... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now