2022 CVE Vulnerabilities

27,553 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-0966MEDIUM5.4Stored XSS via File Upload in star7th/showdoc in GitHub repository star7th/showdoc prior to 2.4.10.
CVE-2022-0965MEDIUM5.4Stored XSS viva .ofd file upload in GitHub repository star7th/showdoc prior to 2.10.4.
CVE-2022-0964MEDIUM5.4Stored XSS viva .webmv file upload in GitHub repository star7th/showdoc prior to 2.10.4.
CVE-2022-0963MEDIUM5.4Unrestricted XML Files Leads to Stored XSS in GitHub repository microweber/microweber prior to 1.2.12.
CVE-2022-24756HIGH7.5Bareos is open source software for backup, archiving, and recovery of data for operating systems. When Bareos Director >...
CVE-2022-24755CRITICAL9.8Bareos is open source software for backup, archiving, and recovery of data for operating systems. When Bareos Director >...
CVE-2022-24752CRITICAL9.8SyliusGridBundle is a package of generic data grids for Symfony applications. Prior to versions 1.10.1 and 1.11-rc2, val...
CVE-2022-0961MEDIUM5.5The microweber application allows large characters to insert in the input field "post title" which can allow attackers t...
CVE-2022-0430MEDIUM5.3Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository httpie/httpie prior to 3.1.0.
CVE-2022-24721HIGH8.1CometD is a scalable comet implementation for web messaging. In any version prior to 5.0.11, 6.0.6, and 7.0.6, internal ...
CVE-2022-0942MEDIUM5.4Stored XSS due to Unrestricted File Upload in GitHub repository star7th/showdoc prior to 2.10.4.
CVE-2022-0957MEDIUM5.4Stored XSS via File Upload in GitHub repository star7th/showdoc prior to 2.10.4.
CVE-2022-0956MEDIUM5.4Stored XSS via File Upload in GitHub repository star7th/showdoc prior to v.2.10.4.
CVE-2022-0954MEDIUM5.4Multiple Stored Cross-site Scripting (XSS) Vulnerabilities in Shop's Other Settings, Shop's Autorespond E-mail Settings ...
CVE-2022-0894MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.4.0.
CVE-2022-0893MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.4.0.
CVE-2022-0951MEDIUM6.1File Upload Restriction Bypass leading to Stored XSS Vulnerability in GitHub repository star7th/showdoc prior to 2.10.4.
CVE-2022-0950MEDIUM5.4Unrestricted Upload of File with Dangerous Type in GitHub repository star7th/showdoc prior to 2.10.4.
CVE-2022-27193MEDIUM5.5CVRF-CSAF-Converter before 1.0.0-rc2 resolves XML External Entities (XXE). This leads to the inclusion of arbitrary (loc...
CVE-2022-0945MEDIUM5.4Stored XSS viva axd and cshtml file upload in star7th/showdoc in GitHub repository star7th/showdoc prior to v2.10.4.
CVE-2022-0944HIGH7.2Template injection in connection test endpoint leads to RCE in GitHub repository sqlpad/sqlpad prior to 6.10.1.
CVE-2022-24762MEDIUM6.5sysend.js is a library that allows a user to send messages between pages that are open in the same browser. Users that u...
CVE-2022-24740HIGH7.5Volto is a ReactJS-based frontend for the Plone Content Management System. Between versions 14.0.0-alpha.5 and 15.0.0-al...
CVE-2022-24749MEDIUM6.1Sylius is an open source eCommerce platform. In versions prior to 1.9.10, 1.10.11, and 1.11.2, it is possible to upload ...
CVE-2022-24743HIGH8.2Sylius is an open source eCommerce platform. Prior to versions 1.10.11 and 1.11.2, the reset password token was not set ...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now