2022 CVE Vulnerabilities

27,525 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-43455MEDIUM6.5Sewio’s Real-Time Location System (RTLS) Studio version 2.0.0 up to and including version 2.6.2 is vulnerable to imprope...
CVE-2022-46660MEDIUM6.5 An unauthorized user could alter or write files with full control over the path and content of the file.
CVE-2022-43494MEDIUM6.5 An unauthorized user could be able to read any file on the system, potentially exposing sensitive information. ...
CVE-2022-39429MEDIUM4.3Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 19c and 21c...
CVE-2022-47929MEDIUM5.5In the Linux kernel before 6.1.6, a NULL pointer dereference bug in the traffic control subsystem allows an unprivileged...
CVE-2022-39195MEDIUM6.1A cross-site scripting (XSS) vulnerability in the LISTSERV 17 web interface allows remote attackers to inject arbitrary ...
CVE-2022-2907MEDIUM6.5An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.9 before 15.1.6, all versions start...
CVE-2022-37436MEDIUM5.3Prior to Apache HTTP Server 2.4.55, a malicious backend can cause the response headers to be truncated early, resulting ...
CVE-2022-40704MEDIUM6.1A XSS vulnerability was found in phoromatic_r_add_test_details.php in phoronix-test-suite.
CVE-2022-4121MEDIUM5.5In libetpan a null pointer dereference in mailimap_mailbox_data_status_free in low-level/imap/mailimap_types.c was found...
CVE-2022-41861MEDIUM6.5A flaw was found in freeradius. A malicious RADIUS client or home server can send a malformed abinary attribute which ca...
CVE-2022-2893MEDIUM6.5RONDS EPM version 1.19.5 does not properly validate the filename parameter, which could allow an unauthorized user to s...
CVE-2022-42462MEDIUM4.8Auth. Stored Cross-Site Scripting (XSS) vulnerability in Adeel Ahmed's IP Blacklist Cloud plugin <= 5.00 versions.
CVE-2022-45440MEDIUM4.4A vulnerability exists in the FTP server of the Zyxel AX7501-B0 firmware prior to V5.17(ABPC.3)C0, which processes symbo...
CVE-2022-45439MEDIUM6.5A pair of spare WiFi credentials is stored in the configuration file of the Zyxel AX7501-B0 firmware prior to V5.17(ABPC...
CVE-2022-4658MEDIUM5.4The RSSImport WordPress plugin through 4.6.1 does not validate and escape one of its shortcode attributes, which could a...
CVE-2022-4655MEDIUM5.4The Welcart e-Commerce WordPress plugin before 2.8.9 does not validate and escapes one of its shortcode attributes, whic...
CVE-2022-4653MEDIUM5.4The Greenshift WordPress plugin before 4.8.9 does not validate and escape one of its shortcode attributes, which could a...
CVE-2022-4648MEDIUM5.4The Real Testimonials WordPress plugin before 2.6.0 does not validate and escape some of its shortcode attributes before...
CVE-2022-4578MEDIUM5.4The Video Conferencing with Zoom WordPress plugin before 4.0.10 does not validate and escape some of its shortcode attri...
CVE-2022-4571MEDIUM5.4The Seriously Simple Podcasting WordPress plugin before 2.19.1 does not validate and escape some of its shortcode attrib...
CVE-2022-4549MEDIUM4.3The Tickera WordPress plugin before 3.5.1.0 does not have CSRF check in place when updating its settings, which could al...
CVE-2022-4544MEDIUM5.4The MashShare WordPress plugin before 3.8.7 does not validate and escape some of its shortcode attributes before outputt...
CVE-2022-4508MEDIUM5.4The ConvertKit WordPress plugin before 2.0.5 does not validate and escapes some of its shortcode attributes before outpu...
CVE-2022-4507MEDIUM5.4The Real Cookie Banner WordPress plugin before 3.4.10 does not validate and escapes some of its shortcode attributes bef...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now