2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-44031MEDIUM6.1Redmine before 4.2.9 and 5.0.x before 5.0.4 allows persistent XSS in its Textile formatter due to improper sanitization ...
CVE-2022-4414MEDIUM6.1Cross-site Scripting (XSS) - DOM in GitHub repository nuxt/framework prior to v3.0.0-rc.13.
CVE-2022-4413MEDIUM6.1Cross-site Scripting (XSS) - Reflected in GitHub repository nuxt/framework prior to v3.0.0-rc.13.
CVE-2022-4408MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.9.
CVE-2022-4407MEDIUM6.1Cross-site Scripting (XSS) - Reflected in GitHub repository thorsten/phpmyfaq prior to 3.1.9.
CVE-2022-4401MEDIUM5.4A vulnerability was found in pallidlight online-course-selection-system. It has been classified as problematic. Affected...
CVE-2022-4400MEDIUM6.1A vulnerability was found in zbl1996 FS-Blog and classified as problematic. This issue affects some unknown processing o...
CVE-2022-4397MEDIUM6.5A vulnerability was found in morontt zend-blog-number-2. It has been classified as problematic. Affected is an unknown f...
CVE-2022-4396MEDIUM5.4A vulnerability was found in RDFlib pyrdfa3 and classified as problematic. This issue affects the function _get_option o...
CVE-2022-45292MEDIUM5.3User invites for Funkwhale v1.2.8 do not permanently expire after being used for signup and can be used again after an a...
CVE-2022-34297MEDIUM5.4Yii Yii2 Gii through 2.2.4 allows stored XSS by injecting a payload into any field.
CVE-2022-41299MEDIUM5.4IBM Cloud Transformation Advisor 2.0.1 through 3.3.1 is vulnerable to cross-site scripting. This vulnerability allows us...
CVE-2022-4336MEDIUM5.4In BAOTA linux panel there exists a stored xss vulnerability attackers can use to obtain sensitive information via the l...
CVE-2022-29839MEDIUM5.5Insufficiently Protected Credentials vulnerability in the remote backups application on Western Digital My Cloud devices...
CVE-2022-29838MEDIUM4.6Improper Authentication vulnerability in the encrypted volumes and auto mount features of Western Digital My Cloud devic...
CVE-2022-25630MEDIUM5.4An authenticated user can embed malicious content with XSS into the admin group policy page.
CVE-2022-25629MEDIUM5.4An authenticated user who has the privilege to add/edit annotations on the Content tab, can craft a malicious annotation...
CVE-2022-4264MEDIUM4.3Incorrect Privilege Assignment in M-Files Web (Classic) in M-Files before 22.8.11691.0 allows low privilege user to chan...
CVE-2022-44213MEDIUM4.8ZKTeco Xiamen Information Technology ZKBio ECO ADMS <=3.1-164 is vulnerable to Cross Site Scripting (XSS).
CVE-2022-4377MEDIUM5.4A vulnerability was found in S-CMS 5.0 Build 20220328. It has been declared as problematic. Affected by this vulnerabili...
CVE-2022-33187MEDIUM4.9Brocade SANnav before v2.2.1 logs usernames and encoded passwords in debug-enabled logs. The vulnerability could allow ...
CVE-2022-38765MEDIUM6.5Canon Medical Informatics Vitrea Vision 7.7.76.1 does not adequately enforce access controls. An authenticated user is a...
CVE-2022-41947MEDIUM5.4DHIS 2 is an open source information system for data capture, management, validation, analytics and visualization. Throu...
CVE-2022-46158MEDIUM4.3PrestaShop is an open-source e-commerce solution. Versions prior to 1.7.8.8 did not properly restrict host filesystem ac...
CVE-2022-46153MEDIUM6.5Traefik is an open source HTTP reverse proxy and load balancer. In affected versions there is a potential vulnerability ...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now