2022 CVE Vulnerabilities

27,554 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-21805MEDIUM6.1Reflected cross-site scripting vulnerability in the attached file name of php_mailform versions prior to Version 1.40 al...
CVE-2022-21799MEDIUM5.2Cross-site scripting vulnerability in ELECOM LAN router WRC-300FEBK-R firmware v1.13 and earlier allows an attacker on t...
CVE-2022-21241CRITICAL9.6Cross-site scripting vulnerability in CSV+ prior to 0.8.1 allows a remote unauthenticated attacker to inject an arbitrar...
CVE-2022-21193HIGH7.5Directory traversal vulnerability in TransmitMail 2.5.0 to 2.6.1 allows a remote unauthenticated attacker to obtain an a...
CVE-2022-21173HIGH8.8Hidden functionality vulnerability in ELECOM LAN routers (WRH-300BK3 firmware v1.05 and earlier, WRH-300WH3 firmware v1....
CVE-2022-0508MEDIUM5.3Server-Side Request Forgery (SSRF) in GitHub repository chocobozzz/peertube prior to f33e515991a32885622b217bf2ed1d1b0d9...
CVE-2022-0506MEDIUM5.4Cross-site Scripting (XSS) - Stored in Packagist microweber/microweber prior to 1.2.11.
CVE-2022-0505MEDIUM6.5Cross-Site Request Forgery (CSRF) in Packagist microweber/microweber prior to 1.2.11.
CVE-2022-0504MEDIUM6.5Generation of Error Message Containing Sensitive Information in Packagist microweber/microweber prior to 1.2.11.
CVE-2022-24450HIGH8.8NATS nats-server before 2.7.2 has Incorrect Access Control. Any authenticated user can obtain the privileges of the Syst...
CVE-2022-23624HIGH8.8Frourio-express is a minimal full stack framework, for TypeScript. Frourio-express users who uses frourio-express versio...
CVE-2022-23623HIGH8.8Frourio is a full stack framework, for TypeScript. Frourio users who uses frourio version prior to v0.26.0 and integrati...
CVE-2022-23613HIGH7.8xrdp is an open source remote desktop protocol (RDP) server. In affected versions an integer underflow leading to a heap...
CVE-2022-21712HIGH7.5twisted is an event-driven networking engine written in Python. In affected versions twisted exposes cookies and authori...
CVE-2022-21816MEDIUM5.5NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (nvidia.ko), where a user in the guest OS can c...
CVE-2022-21815MEDIUM5.5NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for priva...
CVE-2022-21814MEDIUM6.1NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel driver package, where improper handling of in...
CVE-2022-21813MEDIUM6.1NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel driver, where improper handling of insufficie...
CVE-2022-22931MEDIUM4.3Fix of CVE-2021-40525 do not prepend delimiters upon valid directory validations. Affected implementations include: - ma...
CVE-2022-23263HIGH7.7Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
CVE-2022-23262MEDIUM6.3Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
CVE-2022-23261MEDIUM5.3Microsoft Edge (Chromium-based) Tampering Vulnerability
CVE-2022-0149MEDIUM6.1The WooCommerce Stored Exporter WordPress plugin before 2.7.1 was affected by a Reflected Cross-Site Scripting (XSS) vul...
CVE-2022-0148MEDIUM5.4The All-in-one Floating Contact Form, Call, Chat, and 50+ Social Icon Tabs WordPress plugin before 2.0.4 was vulnerable ...
CVE-2022-23320HIGH7.5XMPie uStore 12.3.7244.0 allows for administrators to generate reports based on raw SQL queries. Since the application s...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now