2022 CVE Vulnerabilities

27,554 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-25020MEDIUM5.4A cross-site scripting (XSS) vulnerability in Pluxml v5.8.7 allows attackers to execute arbitrary web scripts or HTML vi...
CVE-2022-25018HIGH8.8Pluxml v5.8.7 was discovered to allow attackers to execute arbitrary code via crafted PHP code inserted into static page...
CVE-2022-24446MEDIUM4.3An issue was discovered in Zoho ManageEngine Key Manager Plus 6.1.6. A user, with the level Operator, can see all SSH se...
CVE-2022-22262HIGH7.7ROG Live Service’s function for deleting temp files created by installation has an improper link resolution before file ...
CVE-2022-26332MEDIUM5.4Cipi 3.1.15 allows Add Server stored XSS via the /api/servers name field.
CVE-2022-25413MEDIUM5.4Maxsite CMS v108 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the parameter f_tags at...
CVE-2022-25412HIGH8.1Maxsite CMS v180 was discovered to contain multiple arbitrary file deletion vulnerabilities in /admin_page/all-files-upd...
CVE-2022-25411CRITICAL9.8A Remote Code Execution (RCE) vulnerability at /admin/options in Maxsite CMS v180 allows attackers to execute arbitrary ...
CVE-2022-25410MEDIUM5.4Maxsite CMS v180 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the parameter f_file_de...
CVE-2022-25409MEDIUM5.4Hospital Management System v1.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the dema...
CVE-2022-25408MEDIUM5.4Hospital Management System v1.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the dpas...
CVE-2022-25407MEDIUM5.4Hospital Management System v1.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Doct...
CVE-2022-25029Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2022-25096. Reason: This candidate is a duplicate of ...
CVE-2022-25028MEDIUM6.1Home Owners Collection Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via t...
CVE-2022-23907MEDIUM6.1CMS Made Simple v2.2.15 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the parameter...
CVE-2022-23906HIGH7.2CMS Made Simple v2.2.15 was discovered to contain a Remote Command Execution (RCE) vulnerability via the upload avatar f...
CVE-2022-0743MEDIUM4.6Cross-site Scripting (XSS) - Stored in GitHub repository getgrav/grav prior to 1.7.31.
CVE-2022-26315MEDIUM5.3qrcp through 0.8.4, in receive mode, allows ../ Directory Traversal via the file name specified by the uploader.
CVE-2022-26181HIGH7.8Dropbox Lepton v1.2.1-185-g2a08b77 was discovered to contain a heap-buffer-overflow in the function aligned_dealloc():sr...
CVE-2022-25023HIGH8.8Audio File commit 004065d was discovered to contain a heap-buffer overflow in the function fouBytesToInt():AudioFile.h.
CVE-2022-25015MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in Ice Hrm 30.0.0.OS allows attackers to steal cookies via a crafted p...
CVE-2022-25014MEDIUM6.1Ice Hrm 30.0.0.OS was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the "m" parameter i...
CVE-2022-25013MEDIUM6.1Ice Hrm 30.0.0.OS was discovered to contain multiple reflected cross-site scripting (XSS) vulnerabilities via the "key" ...
CVE-2022-26158MEDIUM6.1An issue was discovered in the web application in Cherwell Service Management (CSM) 10.2.3. It accepts and reflects arbi...
CVE-2022-26157MEDIUM5.3An issue was discovered in the web application in Cherwell Service Management (CSM) 10.2.3. The ASP.NET_Sessionid cookie...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now