2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-4308HIGH8.8Plaintext Storage of a Password vulnerability in Secomea GateManager (USB wizard) allows Authentication abuse on SiteMan...
CVE-2022-38125MEDIUM5.5Improper Restriction of Communication Channel to Intended Endpoints vulnerability in Secomea SiteManager (FTP Agent modu...
CVE-2022-2507MEDIUM5.3In affected versions of Octopus Deploy it is possible to render user supplied input into the webpage
CVE-2022-43378MEDIUM6.5 A CWE-1021: Improper Restriction of Rendered UI Layers or Frames vulnerability exists that could cause the user t...
CVE-2022-43377HIGH7.5 A CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists that could cause account ...
CVE-2022-43376MEDIUM6.1 A CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists t...
CVE-2022-34755MEDIUM6.7 A CWE-427 - Uncontrolled Search Path Element vulnerability exists that could allow an attacker with a local privileged ...
CVE-2022-45836MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in W3 Eden, Inc. Download Manager plugin <= 3.2.59 versions.
CVE-2022-44632MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Denis Buka Content Repeater – Custom Posts Simplified ...
CVE-2022-46640CRITICAL9.8Nanoleaf Desktop App before v1.3.1 was discovered to contain a command injection vulnerability which is exploited via a ...
CVE-2022-45839MEDIUM5.4Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in WHA WHA Puzzle plugin <= 1.0.9 versions.
CVE-2022-45838MEDIUM6.1Unauth. Stored Cross-Site Scripting (XSS) vulnerability in Repute InfoSystems ARForms Form Builder plugin <= 1.5.5 versi...
CVE-2022-44735MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Gus Sevilla WP Clictracker plugin <= 1.0.5 versions.
CVE-2022-46389MEDIUM6.1There exists a reflected XSS within the logout functionality of ServiceNow versions lower than Quebec Patch 10 Hotfix 11...
CVE-2022-44726MEDIUM5.4The TouchDown Timesheet tracking component 4.1.4 for Jira allows XSS in the calendar view.
CVE-2022-45849MEDIUM5.4Auth. (subscriber+) Reflected Cross-Site Scripting (XSS) vulnerability in Silkalns Activello theme <= 1.4.4 versions.
CVE-2022-44734MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in BestWebSoft Car Rental by BestWebSoft plugin <= 1.1.2 ...
CVE-2022-43480MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Magneticlab Sàrl Homepage Pop-up plugin <= 1.2.5 versi...
CVE-2022-43458MEDIUM5.4Auth. (contributor+) Cross-Site Scripting (XSS) vulnerability in Code Tides Advanced Floating Content plugin <= 1.2.1 ve...
CVE-2022-48314MEDIUM6.5The Bluetooth module has a vulnerability of bypassing the user confirmation in the pairing process. Successful exploitat...
CVE-2022-48313MEDIUM6.5The Bluetooth module has a vulnerability of bypassing the user confirmation in the pairing process. Successful exploitat...
CVE-2022-48312CRITICAL9.1The HwPCAssistant module has the out-of-bounds read/write vulnerability. Successful exploitation of this vulnerability m...
CVE-2022-34128CRITICAL9.8The Cartography (aka positions) plugin before 6.0.1 for GLPI allows remote code execution via PHP code in the POST data ...
CVE-2022-34127HIGH7.5The Managentities plugin before 4.0.2 for GLPI allows reading local files via directory traversal in the inc/cri.class.p...
CVE-2022-34126HIGH7.5The Activity plugin before 3.1.1 for GLPI allows reading local files via directory traversal in the front/cra.send.php f...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now