2022 CVE Vulnerabilities

27,525 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-32595MEDIUM4.4In widevine, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local informati...
CVE-2022-4902MEDIUM6.1A vulnerability classified as problematic has been found in eXo Chat Application. Affected is an unknown function of the...
CVE-2022-2933MEDIUM5.4The 0mk Shortener plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 0.2...
CVE-2022-48085MEDIUM5.4Softr v2.0 was discovered to contain a HTML injection vulnerability via the Work Space Name parameter.
CVE-2022-45722MEDIUM6.1ezEIP v5.3.0(0649) was discovered to contain a cross-site scripting (XSS) vulnerability.
CVE-2022-29416MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Afterpay Gateway for WooCommerce <= 3.5.0 versions.
CVE-2022-27628MEDIUM6.5Cross-Site Request Forgery (CSRF) vulnerability in AA-Team WZone – Lite Version plugin 3.1 Lite versions.
CVE-2022-42909MEDIUM5.4WEPA Print Away does not verify that a user has authorization to access documents before generating print orders and ass...
CVE-2022-42908MEDIUM5.4WEPA Print Away is vulnerable to a stored XSS. It does not properly sanitize uploaded filenames, allowing an attacker to...
CVE-2022-48074MEDIUM5.3An issue in NoMachine before v8.2.3 allows attackers to execute arbitrary commands via a crafted .nxs file.
CVE-2022-48023MEDIUM4.3Insufficient privilege verification in Zammad v5.3.0 allows an authenticated attacker to perform changes on the tags of ...
CVE-2022-48022MEDIUM4.3An issue in the component /api/v1/mentions of Zammad v5.3.0 allows authenticated attackers with agent permissions to vie...
CVE-2022-47131MEDIUM4.8A Cross-Site Request Forgery (CSRF) in Academy LMS before v5.10 allows an attacker to arbitrarily create a page.
CVE-2022-47130MEDIUM4.3A Cross-Site Request Forgery (CSRF) in Academy LMS before v5.10 allows a discount coupon to be arbitrarily created if an...
CVE-2022-48140MEDIUM5.4DedeCMS v5.7.97 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /file_manage_view....
CVE-2022-3560MEDIUM5.5A flaw was found in pesign. The pesign package provides a systemd service used to start the pesign daemon. This service ...
CVE-2022-43665MEDIUM5.5A denial of service vulnerability exists in the malware scan functionality of ESTsoft Alyac 2.5.8.645. A specially-craft...
CVE-2022-2546MEDIUM4.7The All-in-One WP Migration WordPress plugin before 7.63 uses the wrong content type, and does not properly escape the r...
CVE-2022-40268MEDIUM4.7Improper Restriction of Rendered UI Layers or Frames vulnerability in Mitsubishi Electric Corporation GOT2000 Series GT2...
CVE-2022-37034MEDIUM5.3In dotCMS 5.x-22.06, it is possible to call the TempResource multiple times, each time requesting the dotCMS server to d...
CVE-2022-45783MEDIUM6.5An issue was discovered in dotCMS core 4.x through 22.10.2. An authenticated directory traversal vulnerability in the do...
CVE-2022-3913MEDIUM5.3Rapid7 Nexpose and InsightVM versions 6.6.82 through 6.6.177 fail to validate the certificate of the update server when ...
CVE-2022-37033MEDIUM6.5In dotCMS 5.x-22.06, TempFileAPI allows a user to create a temporary file based on a passed in URL, while attempting to ...
CVE-2022-3083MEDIUM5.4All versions of Landis+Gyr E850 (ZMQ200) are vulnerable to CWE-784: Reliance on Cookies Without Validation and Integrity...
CVE-2022-46934MEDIUM6.1kkFileView v4.1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the url parameter at /control...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now