2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-3105MEDIUM5.5An issue was discovered in the Linux kernel through 5.16-rc6. uapi_finalize in drivers/infiniband/core/uverbs_uapi.c lac...
CVE-2022-3104MEDIUM5.5An issue was discovered in the Linux kernel through 5.16-rc6. lkdtm_ARRAY_BOUNDS in drivers/misc/lkdtm/bugs.c lacks chec...
CVE-2022-31701MEDIUM5.3VMware Workspace ONE Access and Identity Manager contain a broken authentication vulnerability. VMware has evaluated the...
CVE-2022-23527MEDIUM6.1mod_auth_openidc is an OpenID Certified™ authentication and authorization module for the Apache 2.x HTTP server. Version...
CVE-2022-23520MEDIUM6.1rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. Prior to version 1.4.4, there i...
CVE-2022-46073MEDIUM6.1Helmet Store Showroom 1.0 is vulnerable to Cross Site Scripting (XSS).
CVE-2022-23519MEDIUM6.1rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. Prior to version 1.4.4, a possi...
CVE-2022-23518MEDIUM6.1rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. Versions >= 1.0.3, < 1.4.4 are ...
CVE-2022-4495MEDIUM6.1A vulnerability, which was classified as problematic, has been found in collective.dms.basecontent up to 1.6. This issue...
CVE-2022-23515MEDIUM6.1Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri...
CVE-2022-3590MEDIUM5.9WordPress is affected by an unauthenticated blind SSRF in the pingback feature. Because of a TOCTOU race condition betwe...
CVE-2022-3073MEDIUM6.1Quanos "SCHEMA ST4" example web templates in version Bootstrap 2019 v2/2021 v1/2022 v1/2022 SP1 v1 or below are prone to...
CVE-2022-23504MEDIUM4.9TYPO3 is an open source PHP based web content management system. Versions prior to 9.5.38, 10.4.33, 11.5.20, and 12.1.1 ...
CVE-2022-23502MEDIUM5.4TYPO3 is an open source PHP based web content management system. In versions prior to 10.4.33, 11.5.20, and 12.1.1, When...
CVE-2022-23501MEDIUM6.5TYPO3 is an open source PHP based web content management system. In versions prior to 8.7.49, 9.5.38, 10.4.33, 11.5.20, ...
CVE-2022-42141MEDIUM5.4Delta Electronics DX-2100-L1-CN 2.42 is vulnerable to Cross Site Scripting (XSS) via lform/urlfilter.
CVE-2022-44874MEDIUM5.5wasm3 commit 7890a2097569fde845881e0b352d813573e371f9 was discovered to contain a segmentation fault via the component o...
CVE-2022-46381MEDIUM6.1Certain Linear eMerge E3-Series devices are vulnerable to XSS via the type parameter (e.g., to the badging/badge_templat...
CVE-2022-43996MEDIUM5.4The csaf_provider package before 0.8.2 allows XSS via a crafted CSAF document uploaded as text/html. The endpoint upload...
CVE-2022-38355MEDIUM5.5Daikin SVMPC1 version 2.1.22 and prior and SVMPC2 version 1.2.3 and prior are vulnerable to attackers with access to t...
CVE-2022-4207MEDIUM5.4The Image Hover Effects Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several values th...
CVE-2022-38628MEDIUM6.1Nortek Linear eMerge E3-Series 0.32-08f, 0.32-07p, 0.32-07e, 0.32-09c, 0.32-09b, 0.32-09a, and 0.32-08e were discovered ...
CVE-2022-23499MEDIUM6.1HTML sanitizer is written in PHP, aiming to provide XSS-safe markup based on explicitly allowed tags, attributes and val...
CVE-2022-44707MEDIUM6.5Windows Kernel Denial of Service Vulnerability
CVE-2022-44699MEDIUM5.5Azure Network Watcher Agent Security Feature Bypass Vulnerability

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now