2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-46160MEDIUM4.3Tuleap is an Open Source Suite to improve management of software developments and collaboration. In versions prior to 14...
CVE-2022-41915MEDIUM6.5Netty project is an event-driven asynchronous network application framework. Starting in version 4.1.83.Final and prior ...
CVE-2022-23473MEDIUM4.3Tuleap is an Open Source Suite to improve management of software developments and collaboration. In versions prior to 14...
CVE-2022-41275MEDIUM6.1In SAP Solution Manager (Enterprise Search) - versions 740, and 750, an unauthenticated attacker can generate a link tha...
CVE-2022-41274MEDIUM6.5SAP Disclosure Management - version 10.1, allows an authenticated attacker to exploit certain misconfigured application ...
CVE-2022-41273MEDIUM6.1Due to improper input sanitization in SAP Sourcing and SAP Contract Lifecycle Management - version 1100, an attacker can...
CVE-2022-41266MEDIUM6.1Due to a lack of proper input validation, SAP Commerce Webservices 2.0 (Swagger UI) - versions 1905, 2005, 2105, 2011, 2...
CVE-2022-41263MEDIUM4.3Due to a missing authentication check, SAP Business Objects Business Intelligence Platform (Web Intelligence) - versions...
CVE-2022-41262MEDIUM6.1Due to insufficient input validation, SAP NetWeaver AS Java (HTTP Provider Service) - version 7.50, allows an unauthenti...
CVE-2022-41261MEDIUM5.5SAP Solution Manager (Diagnostic Agent) - version 7.20, allows an authenticated attacker on Windows system to access a f...
CVE-2022-46906MEDIUM5.4Insufficient processing of user input in WebSoft HCM 2021.2.3.327 allows an authenticated attacker to inject arbitrary H...
CVE-2022-46905MEDIUM6.1Insufficient processing of user input in WebSoft HCM 2021.2.3.327 allows an unauthenticated attacker to inject arbitrary...
CVE-2022-46904MEDIUM5.4Insufficient processing of user input in WebSoft HCM 2021.2.3.327 allows an authenticated attacker to inject arbitrary H...
CVE-2022-46903MEDIUM5.4Insufficient processing of user input in WebSoft HCM 2021.2.3.327 allows an authenticated attacker to inject arbitrary H...
CVE-2022-4312MEDIUM5.5 A cleartext storage of sensitive information vulnerability exists in PcVue versions 8.10 through 15.2.3. This could all...
CVE-2022-4311MEDIUM6.5 An insertion of sensitive information into log file vulnerability exists in PcVue versions 15 through 15.2.2. This coul...
CVE-2022-4097MEDIUM5.3The All-In-One Security (AIOS) WordPress plugin before 5.0.8 is susceptible to IP Spoofing attacks, which can lead to by...
CVE-2022-4016MEDIUM6.5The Booster for WooCommerce WordPress plugin before 5.6.7, Booster Plus for WooCommerce WordPress plugin before 5.6.6, B...
CVE-2022-4010MEDIUM4.8The Image Hover Effects WordPress plugin before 5.5 does not sanitise and escape some of its settings, which could allow...
CVE-2022-4005MEDIUM5.4The Donation Button WordPress plugin through 4.0.0 does not sanitize and escapes some parameters, which could allow user...
CVE-2022-4004MEDIUM4.3The Donation Button WordPress plugin through 4.0.0 does not properly check for privileges and nonce tokens in its "donat...
CVE-2022-4000MEDIUM4.8The WooCommerce Shipping WordPress plugin through 1.2.11 does not sanitise and escape some of its settings, which could ...
CVE-2022-3946MEDIUM6.5The Welcart e-Commerce WordPress plugin before 2.8.4 does not have authorisation and CSRF in an AJAX action, allowing an...
CVE-2022-3935MEDIUM5.4The Welcart e-Commerce WordPress plugin before 2.8.4 does not sanitise and escape some parameters, which could allow any...
CVE-2022-3934MEDIUM5.4The FlatPM WordPress plugin before 3.0.13 does not sanitise and escape some parameters before outputting them back in pa...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now