2022 CVE Vulnerabilities

27,525 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-45139MEDIUM5.3A CORS Misconfiguration in the web-based management allows a malicious third party webserver to misuse all basic informa...
CVE-2022-45137MEDIUM6.1The configuration backend of the web-based management is vulnerable to reflected XSS (Cross-Site Scripting) attacks that...
CVE-2022-34910MEDIUM5.5An issue was discovered in the A4N (Aremis 4 Nomad) application 1.5.0 for Android. It uses a local database to store dat...
CVE-2022-31405MEDIUM6.5MV iDigital Clinic Enterprise (iDCE) 1.0 stores passwords in cleartext.
CVE-2022-4203MEDIUM4.9A read buffer overrun can be triggered in X.509 certificate verification, specifically in name constraint checking. Note...
CVE-2022-43923MEDIUM5.5IBM Maximo Application Suite 8.8.0 and 8.9.0 stores potentially sensitive information that could be read by a local user...
CVE-2022-48345MEDIUM6.1sanitize-url (aka @braintree/sanitize-url) before 6.0.2 allows XSS via HTML entities.
CVE-2022-46440MEDIUM5.5ttftool v0.9.2 was discovered to contain a segmentation violation via the readU16 function at ttf.c.
CVE-2022-46785MEDIUM6.1SquaredUp Dashboard Server SCOM edition before 5.7.1 GA allows XSS (issue 1 of 2).
CVE-2022-46784MEDIUM6.1SquaredUp Dashboard Server SCOM edition before 5.7.1 GA allows open redirection. (The issue was originally found in 5.5....
CVE-2022-46786MEDIUM5.4SquaredUp Dashboard Server SCOM edition before 5.7.1 GA allows XSS (issue 2 of 2).
CVE-2022-48344MEDIUM6.1In JetBrains TeamCity before 2022.10.2 there was an XSS vulnerability in the group creation process.
CVE-2022-48343MEDIUM6.1In JetBrains TeamCity before 2022.10.2 there was an XSS vulnerability in the user creation process.
CVE-2022-29273MEDIUM6.1pfSense CE through 2.6.0 and pfSense Plus before 22.05 allow XSS in the WebGUI via URL Table Alias URL parameters.
CVE-2022-43870MEDIUM6.5IBM Spectrum Virtualize 8.3, 8.4, and 8.5 could disclose SNMPv3 server credentials to an authenticated user in log files...
CVE-2022-43578MEDIUM5.4IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.7 and 6.1.0.0 through 6.1.2.0 is vulnerable to cross-...
CVE-2022-41567MEDIUM5.4The BusinessConnect UI component of TIBCO Software Inc.'s TIBCO BusinessConnect contains an easily exploitable vulnerabi...
CVE-2022-41566MEDIUM5.4The server component of TIBCO Software Inc.'s TIBCO EBX Add-ons contains an easily exploitable vulnerability that allows...
CVE-2022-41565MEDIUM5.4The Web Application component of TIBCO Software Inc.'s TIBCO EBX and TIBCO Product and Service Catalog powered by TIBCO ...
CVE-2022-41216MEDIUM6.5Local File Inclusion vulnerability within Cloudflow allows attackers to retrieve confidential information from the syste...
CVE-2022-38779MEDIUM6.1An open redirect issue was discovered in Kibana that could lead to a user being redirected to an arbitrary website if th...
CVE-2022-4897MEDIUM6.1The BackupBuddy WordPress plugin before 8.8.3 does not sanitise and escape some parameters before outputting them back i...
CVE-2022-4791MEDIUM5.4The Product Slider and Carousel with Category for WooCommerce WordPress plugin before 2.8 does not validate and escape o...
CVE-2022-4786MEDIUM5.4The Video.js WordPress plugin through 4.5.0 does not validate and escape some of its shortcode attributes before outputt...
CVE-2022-4785MEDIUM5.4The Video Sidebar Widgets WordPress plugin through 6.1 does not validate and escape some of its shortcode attributes bef...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now