2022 CVE Vulnerabilities
27,553 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-0966 | MEDIUM | 5.4 | 0.5% | Mar 15, 2022 | Stored XSS via File Upload in star7th/showdoc in GitHub repository star7th/showdoc prior to 2.4.10. |
| CVE-2022-0965 | MEDIUM | 5.4 | 0.9% | Mar 15, 2022 | Stored XSS viva .ofd file upload in GitHub repository star7th/showdoc prior to 2.10.4. |
| CVE-2022-0964 | MEDIUM | 5.4 | 0.8% | Mar 15, 2022 | Stored XSS viva .webmv file upload in GitHub repository star7th/showdoc prior to 2.10.4. |
| CVE-2022-0963 | MEDIUM | 5.4 | 1.9% | Mar 15, 2022 | Unrestricted XML Files Leads to Stored XSS in GitHub repository microweber/microweber prior to 1.2.12. |
| CVE-2022-24756 | HIGH | 7.5 | 1.9% | Mar 15, 2022 | Bareos is open source software for backup, archiving, and recovery of data for operating systems. When Bareos Director >... |
| CVE-2022-24755 | CRITICAL | 9.8 | 2.0% | Mar 15, 2022 | Bareos is open source software for backup, archiving, and recovery of data for operating systems. When Bareos Director >... |
| CVE-2022-24752 | CRITICAL | 9.8 | 1.3% | Mar 15, 2022 | SyliusGridBundle is a package of generic data grids for Symfony applications. Prior to versions 1.10.1 and 1.11-rc2, val... |
| CVE-2022-0961 | MEDIUM | 5.5 | 1.0% | Mar 15, 2022 | The microweber application allows large characters to insert in the input field "post title" which can allow attackers t... |
| CVE-2022-0430 | MEDIUM | 5.3 | 1.3% | Mar 15, 2022 | Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository httpie/httpie prior to 3.1.0. |
| CVE-2022-24721 | HIGH | 8.1 | 1.1% | Mar 15, 2022 | CometD is a scalable comet implementation for web messaging. In any version prior to 5.0.11, 6.0.6, and 7.0.6, internal ... |
| CVE-2022-0942 | MEDIUM | 5.4 | 0.7% | Mar 15, 2022 | Stored XSS due to Unrestricted File Upload in GitHub repository star7th/showdoc prior to 2.10.4. |
| CVE-2022-0957 | MEDIUM | 5.4 | 0.8% | Mar 15, 2022 | Stored XSS via File Upload in GitHub repository star7th/showdoc prior to 2.10.4. |
| CVE-2022-0956 | MEDIUM | 5.4 | 0.7% | Mar 15, 2022 | Stored XSS via File Upload in GitHub repository star7th/showdoc prior to v.2.10.4. |
| CVE-2022-0954 | MEDIUM | 5.4 | 3.2% | Mar 15, 2022 | Multiple Stored Cross-site Scripting (XSS) Vulnerabilities in Shop's Other Settings, Shop's Autorespond E-mail Settings ... |
| CVE-2022-0894 | MEDIUM | 5.4 | 0.7% | Mar 15, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.4.0. |
| CVE-2022-0893 | MEDIUM | 5.4 | 0.8% | Mar 15, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.4.0. |
| CVE-2022-0951 | MEDIUM | 6.1 | 0.9% | Mar 15, 2022 | File Upload Restriction Bypass leading to Stored XSS Vulnerability in GitHub repository star7th/showdoc prior to 2.10.4. |
| CVE-2022-0950 | MEDIUM | 5.4 | 0.6% | Mar 15, 2022 | Unrestricted Upload of File with Dangerous Type in GitHub repository star7th/showdoc prior to 2.10.4. |
| CVE-2022-27193 | MEDIUM | 5.5 | 0.7% | Mar 15, 2022 | CVRF-CSAF-Converter before 1.0.0-rc2 resolves XML External Entities (XXE). This leads to the inclusion of arbitrary (loc... |
| CVE-2022-0945 | MEDIUM | 5.4 | 0.8% | Mar 15, 2022 | Stored XSS viva axd and cshtml file upload in star7th/showdoc in GitHub repository star7th/showdoc prior to v2.10.4. |
| CVE-2022-0944 | HIGH | 7.2 | 8.7% | Mar 15, 2022 | Template injection in connection test endpoint leads to RCE in GitHub repository sqlpad/sqlpad prior to 6.10.1. |
| CVE-2022-24762 | MEDIUM | 6.5 | 0.7% | Mar 14, 2022 | sysend.js is a library that allows a user to send messages between pages that are open in the same browser. Users that u... |
| CVE-2022-24740 | HIGH | 7.5 | 0.6% | Mar 14, 2022 | Volto is a ReactJS-based frontend for the Plone Content Management System. Between versions 14.0.0-alpha.5 and 15.0.0-al... |
| CVE-2022-24749 | MEDIUM | 6.1 | 1.1% | Mar 14, 2022 | Sylius is an open source eCommerce platform. In versions prior to 1.9.10, 1.10.11, and 1.11.2, it is possible to upload ... |
| CVE-2022-24743 | HIGH | 8.2 | 1.2% | Mar 14, 2022 | Sylius is an open source eCommerce platform. Prior to versions 1.10.11 and 1.11.2, the reset password token was not set ... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now