2022 CVE Vulnerabilities

27,525 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-2658MEDIUM4.8The WP Spell Check WordPress plugin before 9.13 does not escape ignored words, which could allow high privilege users su...
CVE-2022-45438MEDIUM5.3When explicitly enabling the feature flag DASHBOARD_CACHE (disabled by default), the system allowed for an unauthenticat...
CVE-2022-43721MEDIUM5.4An authenticated attacker with update datasets permission could change a dataset link to an untrusted site, users could ...
CVE-2022-43720MEDIUM5.4An authenticated attacker with write CSS template permissions can create a record with specific HTML tags that will not ...
CVE-2022-43718MEDIUM5.4Upload data forms do not correctly render user input leading to possible XSS attack vectors that can be performed by aut...
CVE-2022-43717MEDIUM5.4Dashboard rendering does not sufficiently sanitize the content of markdown components leading to possible XSS attack vec...
CVE-2022-41703MEDIUM5.4A vulnerability in the SQL Alchemy connector of Apache Superset allows an authenticated user with read access to a speci...
CVE-2022-2815MEDIUM6.5Insecure Storage of Sensitive Information in GitHub repository publify/publify prior to 9.2.10.
CVE-2022-38467MEDIUM6.1Reflected Cross-Site Scripting (XSS) vulnerability in CRM Perks Forms – WordPress Form Builder <= 1.1.0 ver.
CVE-2022-41956MEDIUM6.5Autolab is a course management service, initially developed by a team of students at Carnegie Mellon University, that en...
CVE-2022-23532MEDIUM6.5APOC (Awesome Procedures on Cypher) is an add-on library for Neo4j that provides hundreds of procedures and functions. A...
CVE-2022-48091MEDIUM5.4Tramyardg hotel-mgmt-system version 2022.4 is vulnerable to Cross Site Scripting (XSS) via process_update_profile.php.
CVE-2022-48090MEDIUM6.5Tramyardg hotel-mgmt-system version 2022.4 is vulnerable to SQL Injection via /app/dao/CustomerDAO.php.
CVE-2022-42288MEDIUM5.3NVIDIA BMC contains a vulnerability in IPMI handler, where an unauthorized attacker can use certain oracles to guess a v...
CVE-2022-42284MEDIUM5.5NVIDIA BMC stores user passwords in an obfuscated form in a database accessible by the host. This may lead to a credenti...
CVE-2022-42282MEDIUM5.5NVIDIA BMC contains a vulnerability in SPX REST API, where an authorized attacker can access arbitrary files, which may ...
CVE-2022-42281MEDIUM6.7NVIDIA DGX A100 contains a vulnerability in SBIOS in the FsRecovery, which may allow a highly privileged local attacker ...
CVE-2022-48258MEDIUM5.3In Eternal Terminal 6.2.1, etserver and etclient have world-readable logfiles.
CVE-2022-48257MEDIUM5.3In Eternal Terminal 6.2.1, etserver and etclient have predictable logfile names in /tmp.
CVE-2022-46438MEDIUM5.4A cross-site scripting (XSS) vulnerability in the /admin/article_category.php component of DouPHP v1.7 20221118 allows a...
CVE-2022-42704MEDIUM5.4A cross-site scripting (XSS) vulnerability in Employee Service Center (esc) and Service Portal (sp) in ServiceNow Quebec...
CVE-2022-47102MEDIUM5.4A cross-site scripting (XSS) vulnerability in Student Study Center Management System V 1.0 allows attackers to execute a...
CVE-2022-46622MEDIUM6.1A cross-site scripting (XSS) vulnerability in Judging Management System v1.0 allows attackers to execute arbitrary web s...
CVE-2022-45729MEDIUM6.1A cross-site scripting (XSS) vulnerability in Doctor Appointment Management System v1.0.0 allows attackers to execute ar...
CVE-2022-45728MEDIUM6.1Doctor Appointment Management System v1.0.0 was discovered to contain a cross-site scripting (XSS) vulnerability.

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now