2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-4144MEDIUM6.5An out-of-bounds read flaw was found in the QXL display device emulation in QEMU. The qxl_phys2virt() function does not ...
CVE-2022-46150MEDIUM4.3Discourse is an open-source discussion platform. Prior to version 2.8.13 of the `stable` branch and version 2.9.0.beta14...
CVE-2022-46148MEDIUM5.4Discourse is an open-source messaging platform. In versions 2.8.10 and prior on the `stable` branch and versions 2.9.0.b...
CVE-2022-44355MEDIUM6.1SolarView Compact 7.0 is vulnerable to Cross-site Scripting (XSS) via /network_test.php.
CVE-2022-36433MEDIUM6.1The blog-post creation functionality in the Amasty Blog Pro 2.10.3 plugin for Magento 2 allows injection of JavaScript c...
CVE-2022-45204MEDIUM5.5GPAC v2.1-DEV-rev428-gcb8ae46c8-master was discovered to contain a memory leak via the function dimC_box_read at isomedi...
CVE-2022-42100MEDIUM5.4KLiK SocialMediaWebsite Version 1.0.1 has XSS vulnerabilities that allow attackers to store XSS via location input reply...
CVE-2022-42099MEDIUM5.4KLiK SocialMediaWebsite Version 1.0.1 has XSS vulnerabilities that allow attackers to store XSS via location Forum Subje...
CVE-2022-41676MEDIUM5.4Raiden MAILD Mail Server website mail field has insufficient filtering for user input. A remote attacker with general us...
CVE-2022-36137MEDIUM4.8ChurchCRM Version 4.4.5 has XSS vulnerabilities that allow attackers to store XSS via location input sHeader.
CVE-2022-36136MEDIUM4.8ChurchCRM Version 4.4.5 has XSS vulnerabilities that allow attackers to store XSS via location input Deposit Comment.
CVE-2022-32966MEDIUM6.5RTL8168FP-CG Dash remote management function has missing authorization. An unauthenticated attacker within the adjacent ...
CVE-2022-45307MEDIUM4.3Insecure permissions in Chocolatey PHP package v8.1.12 and below grants all users in the Authenticated Users group write...
CVE-2022-45306MEDIUM4.3Insecure permissions in Chocolatey Azure-Pipelines-Agent package v2.211.1 and below grants all users in the Authenticate...
CVE-2022-45305MEDIUM4.3Insecure permissions in Chocolatey Python3 package v3.11.0 and below grants all users in the Authenticated Users group w...
CVE-2022-45304MEDIUM4.3Insecure permissions in Chocolatey Cmder package v1.3.20 and below grants all users in the Authenticated Users group wri...
CVE-2022-45301MEDIUM4.3Insecure permissions in Chocolatey Ruby package v3.1.2.1 and below grants all users in the Authenticated Users group wri...
CVE-2022-4129MEDIUM5.5A flaw was found in the Linux kernel's Layer 2 Tunneling Protocol (L2TP). A missing lock when clearing sk_user_data can ...
CVE-2022-4128MEDIUM5.5A NULL pointer dereference issue was discovered in the Linux kernel in the MPTCP protocol when traversing the subflow li...
CVE-2022-4127MEDIUM5.5A NULL pointer dereference issue was discovered in the Linux kernel in io_files_update_with_index_alloc. A local user co...
CVE-2022-45224MEDIUM4.8Web-Based Student Clearance System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in Admin/ad...
CVE-2022-45223MEDIUM4.8Web-Based Student Clearance System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in /Admin/a...
CVE-2022-45221MEDIUM4.8Web-Based Student Clearance System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in changepa...
CVE-2022-45214MEDIUM6.1A cross-site scripting (XSS) vulnerability in Sanitization Management System v1.0.0 allows attackers to execute arbitrar...
CVE-2022-38753MEDIUM6.3This update resolves a multi-factor authentication bypass attack

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now