2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-44449MEDIUM4.8Stored cross-site scripting vulnerability in Zenphoto versions prior to 1.6 allows remote a remote authenticated attacke...
CVE-2022-43543MEDIUM5.4KDDI +Message App, NTT DOCOMO +Message App, and SoftBank +Message App contain a vulnerability caused by improper handlin...
CVE-2022-25929MEDIUM5.4The package smoothie from 1.31.0 and before 1.36.1 are vulnerable to Cross-site Scripting (XSS) due to improper user inp...
CVE-2022-4617MEDIUM6.1Cross-site Scripting (XSS) - Reflected in GitHub repository microweber/microweber prior to 1.3.2.
CVE-2022-46318MEDIUM5.3The HAware module has a function logic error. Successful exploitation of this vulnerability will affect the account remo...
CVE-2022-46313MEDIUM5.3The sensor privacy module has an authentication vulnerability. Successful exploitation of this vulnerability may cause u...
CVE-2022-43382MEDIUM4.4IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1could allow a local user with elevated privileges to exploit a vulnerability in the l...
CVE-2022-41590MEDIUM5.5Some smartphones have authentication-related (including session management) vulnerabilities as the setup wizard is bypas...
CVE-2022-39166MEDIUM4.9 IBM Security Guardium 11.4 could allow a privileged user to obtain sensitive information inside of an HTTP response. IB...
CVE-2022-46771MEDIUM4.6 IBM UrbanCode Deploy (UCD) 6.2.0.0 through 6.2.7.18, 7.0.5.0 through 7.0.5.13, 7.1.0.0 through 7.1.2.9, 7.2.0.0 through...
CVE-2022-46430MEDIUM4.8TP-Link TL-WR740N V1 and V2 v3.12.4 and earlier allows authenticated attackers to execute arbitrary code or cause a Deni...
CVE-2022-46428MEDIUM4.8TP-Link TL-WR1043ND V1 3.13.15 and earlier allows authenticated attackers to execute arbitrary code or cause a Denial of...
CVE-2022-46422MEDIUM4.8An issue in Netgear WNR2000 v1 1.2.3.7 and earlier allows authenticated attackers to cause a Denial of Service (DoS) via...
CVE-2022-46139MEDIUM6.5TP-Link TL-WR940N V4 3.16.9 and earlier allows authenticated attackers to cause a Denial of Service (DoS) via uploading ...
CVE-2022-39304MEDIUM4.7ghinstallation provides transport, which implements http.RoundTripper to provide authentication as an installation for G...
CVE-2022-43875MEDIUM5.5IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4 could allow an authenticated user to lock ...
CVE-2022-43872MEDIUM5.3 IBM Financial Transaction Manager 3.2.4 authorization checks are done incorrectly for some HTTP requests which allows g...
CVE-2022-4619MEDIUM4.8The Sidebar Widgets by CodeLights plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘Extra CSS c...
CVE-2022-47551MEDIUM6.5Apiman 1.5.7 through 2.2.3.Final has insufficient checks for read permissions within the Apiman Manager REST API. The ro...
CVE-2022-46402MEDIUM6.5The Microchip RN4870 module firmware 1.43 (and the Microchip PIC LightBlue Explorer Demo 4.2 DT100112) accepts PairCon_r...
CVE-2022-46401MEDIUM5.4The Microchip RN4870 module firmware 1.43 (and the Microchip PIC LightBlue Explorer Demo 4.2 DT100112) accepts PauseEncR...
CVE-2022-46400MEDIUM5.4The Microchip RN4870 module firmware 1.43 (and the Microchip PIC LightBlue Explorer Demo 4.2 DT100112) allows attackers ...
CVE-2022-23543MEDIUM5.4Silverware Games is a social network where people can play games online. Users can attach URLs to YouTube videos, the si...
CVE-2022-23536MEDIUM6.5Cortex provides multi-tenant, long term storage for Prometheus. A local file inclusion vulnerability exists in Cortex ve...
CVE-2022-43887MEDIUM5.3 IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 could be vulnerable to sensitive information exposure by passing API ke...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now