2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-44031 | MEDIUM | 6.1 | 0.4% | Dec 12, 2022 | Redmine before 4.2.9 and 5.0.x before 5.0.4 allows persistent XSS in its Textile formatter due to improper sanitization ... |
| CVE-2022-4414 | MEDIUM | 6.1 | 0.4% | Dec 12, 2022 | Cross-site Scripting (XSS) - DOM in GitHub repository nuxt/framework prior to v3.0.0-rc.13. |
| CVE-2022-4413 | MEDIUM | 6.1 | 0.5% | Dec 12, 2022 | Cross-site Scripting (XSS) - Reflected in GitHub repository nuxt/framework prior to v3.0.0-rc.13. |
| CVE-2022-4408 | MEDIUM | 5.4 | 0.5% | Dec 11, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.9. |
| CVE-2022-4407 | MEDIUM | 6.1 | 4.4% | Dec 11, 2022 | Cross-site Scripting (XSS) - Reflected in GitHub repository thorsten/phpmyfaq prior to 3.1.9. |
| CVE-2022-4401 | MEDIUM | 5.4 | 0.4% | Dec 11, 2022 | A vulnerability was found in pallidlight online-course-selection-system. It has been classified as problematic. Affected... |
| CVE-2022-4400 | MEDIUM | 6.1 | 0.4% | Dec 11, 2022 | A vulnerability was found in zbl1996 FS-Blog and classified as problematic. This issue affects some unknown processing o... |
| CVE-2022-4397 | MEDIUM | 6.5 | 0.2% | Dec 10, 2022 | A vulnerability was found in morontt zend-blog-number-2. It has been classified as problematic. Affected is an unknown f... |
| CVE-2022-4396 | MEDIUM | 5.4 | 0.6% | Dec 10, 2022 | A vulnerability was found in RDFlib pyrdfa3 and classified as problematic. This issue affects the function _get_option o... |
| CVE-2022-45292 | MEDIUM | 5.3 | 0.5% | Dec 9, 2022 | User invites for Funkwhale v1.2.8 do not permanently expire after being used for signup and can be used again after an a... |
| CVE-2022-34297 | MEDIUM | 5.4 | 0.6% | Dec 9, 2022 | Yii Yii2 Gii through 2.2.4 allows stored XSS by injecting a payload into any field. |
| CVE-2022-41299 | MEDIUM | 5.4 | 0.3% | Dec 9, 2022 | IBM Cloud Transformation Advisor 2.0.1 through 3.3.1 is vulnerable to cross-site scripting. This vulnerability allows us... |
| CVE-2022-4336 | MEDIUM | 5.4 | 0.3% | Dec 9, 2022 | In BAOTA linux panel there exists a stored xss vulnerability attackers can use to obtain sensitive information via the l... |
| CVE-2022-29839 | MEDIUM | 5.5 | 0.1% | Dec 9, 2022 | Insufficiently Protected Credentials vulnerability in the remote backups application on Western Digital My Cloud devices... |
| CVE-2022-29838 | MEDIUM | 4.6 | 0.3% | Dec 9, 2022 | Improper Authentication vulnerability in the encrypted volumes and auto mount features of Western Digital My Cloud devic... |
| CVE-2022-25630 | MEDIUM | 5.4 | 1.5% | Dec 9, 2022 | An authenticated user can embed malicious content with XSS into the admin group policy page. |
| CVE-2022-25629 | MEDIUM | 5.4 | 0.4% | Dec 9, 2022 | An authenticated user who has the privilege to add/edit annotations on the Content tab, can craft a malicious annotation... |
| CVE-2022-4264 | MEDIUM | 4.3 | 0.5% | Dec 9, 2022 | Incorrect Privilege Assignment in M-Files Web (Classic) in M-Files before 22.8.11691.0 allows low privilege user to chan... |
| CVE-2022-44213 | MEDIUM | 4.8 | 0.4% | Dec 9, 2022 | ZKTeco Xiamen Information Technology ZKBio ECO ADMS <=3.1-164 is vulnerable to Cross Site Scripting (XSS). |
| CVE-2022-4377 | MEDIUM | 5.4 | 0.4% | Dec 9, 2022 | A vulnerability was found in S-CMS 5.0 Build 20220328. It has been declared as problematic. Affected by this vulnerabili... |
| CVE-2022-33187 | MEDIUM | 4.9 | 0.5% | Dec 9, 2022 | Brocade SANnav before v2.2.1 logs usernames and encoded passwords in debug-enabled logs. The vulnerability could allow ... |
| CVE-2022-38765 | MEDIUM | 6.5 | 0.5% | Dec 9, 2022 | Canon Medical Informatics Vitrea Vision 7.7.76.1 does not adequately enforce access controls. An authenticated user is a... |
| CVE-2022-41947 | MEDIUM | 5.4 | 0.4% | Dec 8, 2022 | DHIS 2 is an open source information system for data capture, management, validation, analytics and visualization. Throu... |
| CVE-2022-46158 | MEDIUM | 4.3 | 0.5% | Dec 8, 2022 | PrestaShop is an open-source e-commerce solution. Versions prior to 1.7.8.8 did not properly restrict host filesystem ac... |
| CVE-2022-46153 | MEDIUM | 6.5 | 0.5% | Dec 8, 2022 | Traefik is an open source HTTP reverse proxy and load balancer. In affected versions there is a potential vulnerability ... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now