2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-40011MEDIUM6.1Typora through 1.3.8 allows XSS if a document containing an SVG element with an attacker-controlled onload attribute is ...
CVE-2022-47946MEDIUM5.5An issue was discovered in the Linux kernel 5.10.x before 5.10.155. A use-after-free in io_sqpoll_wait_sq in fs/io_uring...
CVE-2022-4692MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.9.0.
CVE-2022-43849MEDIUM6.2IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1could allow a non-privileged local user to exploit a vulnerability in the AIX pfcdd k...
CVE-2022-43848MEDIUM6.2IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the AIX perfst...
CVE-2022-39164MEDIUM6.2IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1could allow a non-privileged local user to exploit a vulnerability in the AIX kernel ...
CVE-2022-43381MEDIUM6.2 IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1could allow a non-privileged local user to exploit a vulnerability in the AIX SMB cl...
CVE-2022-43380MEDIUM6.2 IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the AIX NFS k...
CVE-2022-40233MEDIUM6.2IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the AIX TCP/IP...
CVE-2022-39165MEDIUM6.2IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1could allow a non-privileged local user to exploit a vulnerability in CAA to cause a ...
CVE-2022-4698MEDIUM4.8The ProfilePress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several form fields in versions u...
CVE-2022-4697MEDIUM4.8The ProfilePress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘wp_user_cover_default_image_...
CVE-2022-47938MEDIUM6.5An issue was discovered in ksmbd in the Linux kernel 5.15 through 5.19 before 5.19.2. fs/ksmbd/smb2misc.c has an out-of-...
CVE-2022-44565MEDIUM5.3An improper access validation vulnerability exists in airMAX AC <8.7.11, airFiber 60/LR <2.6.2, airFiber 60 XG/HD <v1.0....
CVE-2022-47524MEDIUM5.4F-Secure SAFE Browser 19.1 before 19.2 for Android allows an IDN homograph attack.
CVE-2022-4690MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.9.0.
CVE-2022-4683MEDIUM6.5Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in GitHub repository usememos/memos prior to 0.9.0.
CVE-2022-46492MEDIUM6.5nbnbk commit 879858451d53261d10f77d4709aee2d01c72c301 was discovered to contain an arbitrary file read vulnerability via...
CVE-2022-40897MEDIUM5.9Python Packaging Authority (PyPA) setuptools before 65.5.1 allows remote attackers to cause a denial of service via HTML...
CVE-2022-23513MEDIUM5.3Pi-Hole is a network-wide ad blocking via your own Linux hardware, AdminLTE is a Pi-hole Dashboard for stats and more. I...
CVE-2022-47928MEDIUM6.1In MISP before 2.4.167, there is XSS in the template file uploads in app/View/Templates/upload_file.ctp.
CVE-2022-46491MEDIUM6.5A Cross-Site Request Forgery (CSRF) vulnerability in the Add Administrator function of the default version of nbnbk allo...
CVE-2022-4662MEDIUM5.5A flaw incorrect access control in the Linux kernel USB core subsystem was found in the way user attaches usb device. A ...
CVE-2022-43603MEDIUM5.9A denial of service vulnerability exists in the ZfileOutput::close() functionality of OpenImageIO Project OpenImageIO v2...
CVE-2022-43596MEDIUM5.9An information disclosure vulnerability exists in the IFFOutput channel interleaving functionality of OpenImageIO Projec...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now