2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-37313MEDIUM5.3OX App Suite through 7.10.6 allows SSRF because the anti-SSRF protection mechanism only checks the first DNS AA or AAAA ...
CVE-2022-37312MEDIUM5.3OX App Suite through 7.10.6 has Uncontrolled Resource Consumption via a large request body containing a redirect URL to ...
CVE-2022-37311MEDIUM5.3OX App Suite through 7.10.6 has Uncontrolled Resource Consumption via a large location request parameter to the redirect...
CVE-2022-37307MEDIUM6.1OX App Suite through 7.10.6 allows XSS via XHTML CDATA for a snippet, as demonstrated by the onerror attribute of an IMG...
CVE-2022-31469MEDIUM6.1OX App Suite through 7.10.6 allows XSS via a deep link, as demonstrated by class="deep-link-app" for a /#!!&app=%2e./ UR...
CVE-2022-4741MEDIUM6.5A vulnerability was found in docconv up to 1.2.0 and classified as problematic. This issue affects the function ConvertD...
CVE-2022-4740MEDIUM6.1A vulnerability, which was classified as problematic, has been found in kkFileView. Affected by this issue is the functi...
CVE-2022-4738MEDIUM6.1A vulnerability classified as problematic has been found in SourceCodester Blood Bank Management System 1.0. Affected is...
CVE-2022-4736MEDIUM6.1A vulnerability was found in Venganzas del Pasado and classified as problematic. Affected by this issue is some unknown ...
CVE-2022-41317MEDIUM6.5An issue was discovered in Squid 4.9 through 4.17 and 5.0.6 through 5.6. Due to inconsistent handling of internal URIs, ...
CVE-2022-4735MEDIUM6.1A vulnerability classified as problematic was found in asrashley dash-live. This vulnerability affects the function read...
CVE-2022-4731MEDIUM5.4A vulnerability, which was classified as problematic, was found in myapnea up to 29.0.x. Affected is an unknown function...
CVE-2022-45895MEDIUM6.5Planet eStream before 6.72.10.07 discloses sensitive information, related to the ON cookie (findable in HTML source code...
CVE-2022-45894MEDIUM6.5GetFile.aspx in Planet eStream before 6.72.10.07 allows ..\ directory traversal to read arbitrary local files.
CVE-2022-44381MEDIUM5.3Snipe-IT through 6.0.14 allows attackers to check whether a user account exists because of response variations in a /pas...
CVE-2022-44380MEDIUM5.4Snipe-IT before 6.0.14 is vulnerable to Cross Site Scripting (XSS) for View Assigned Assets.
CVE-2022-44014MEDIUM6.5An issue was discovered in Simmeth Lieferantenmanager before 5.6. In the design of the API, a user is inherently able to...
CVE-2022-44012MEDIUM5.4An issue was discovered in /DS/LM_API/api/SelectionService/InsertQueryWithActiveRelationsReturnId in Simmeth Lieferanten...
CVE-2022-45892MEDIUM5.4In Planet eStream before 6.72.10.07, multiple Stored Cross-Site Scripting (XSS) vulnerabilities exist: Disclaimer, Searc...
CVE-2022-45890MEDIUM6.1In Planet eStream before 6.72.10.07, a Reflected Cross-Site Scripting (XSS) vulnerability exists via any metadata filter...
CVE-2022-47934MEDIUM6.5Brave Browser before 1.43.88 allowed a remote attacker to cause a denial of service in private and guest windows via a c...
CVE-2022-47933MEDIUM6.5Brave Browser before 1.42.51 allowed a remote attacker to cause a denial of service via a crafted HTML file that referen...
CVE-2022-47932MEDIUM6.5Brave Browser before 1.43.34 allowed a remote attacker to cause a denial of service via a crafted HTML file that mention...
CVE-2022-43860MEDIUM4.3IBM Navigator for i 7.3, 7.4, and 7.5 could allow an authenticated user to obtain sensitive information they are authori...
CVE-2022-22449MEDIUM5.3IBM Security Verify Governance, Identity Manager 10.01 could allow a remote attacker to obtain sensitive information whe...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now