2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-43590MEDIUM5.5A null pointer dereference vulnerability exists in the handle_ioctl_0x830a0_systembuffer functionality of Callback techn...
CVE-2022-43589MEDIUM5.5A null pointer dereference vulnerability exists in the handle_ioctl_8314C functionality of Callback technologies CBFS Fi...
CVE-2022-43588MEDIUM5.5A null pointer dereference vulnerability exists in the handle_ioctl_83150 functionality of Callback technologies CBFS Fi...
CVE-2022-45914MEDIUM6.5The ESL (Electronic Shelf Label) protocol, as implemented by (for example) the OV80e934802 RF transceiver on the ETAG-21...
CVE-2022-45225MEDIUM6.1Book Store Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in /bsms_ci/index...
CVE-2022-39333MEDIUM6.1Nexcloud desktop is the Desktop sync client for Nextcloud. An attacker can inject arbitrary HyperText Markup Language in...
CVE-2022-39332MEDIUM5.4Nexcloud desktop is the Desktop sync client for Nextcloud. An attacker can inject arbitrary HyperText Markup Language in...
CVE-2022-39325MEDIUM6.1BaserCMS is a content management system with a japanese language focus. In affected versions there is a cross-site scrip...
CVE-2022-41926MEDIUM5.5Nextcould talk android is the android OS implementation of the nextcloud talk chat system. In affected versions the rece...
CVE-2022-39346MEDIUM6.5Nextcloud server is an open source personal cloud server. Affected versions of nextcloud server did not properly limit u...
CVE-2022-39339MEDIUM4.3user_oidc is an OpenID Connect user backend for Nextcloud. In versions prior to 1.2.1 sensitive information such as the ...
CVE-2022-39338MEDIUM5.4user_oidc is an OpenID Connect user backend for Nextcloud. Versions prior to 1.2.1 did not properly validate discovery u...
CVE-2022-39334MEDIUM4.7Nextcloud also ships a CLI utility called nextcloudcmd which is sometimes used for automated scripting and headless serv...
CVE-2022-39331MEDIUM5.4Nexcloud desktop is the Desktop sync client for Nextcloud. An attacker can inject arbitrary HyperText Markup Language in...
CVE-2022-45475MEDIUM6.5Tiny File Manager version 2.4.8 allows an unauthenticated remote attacker to access the application's internal files. Th...
CVE-2022-41712MEDIUM6.5Frappe version 14.10.0 allows an external attacker to remotely obtain arbitrary local files. This is possible because th...
CVE-2022-0698MEDIUM6.1Microweber version 1.3.1 allows an unauthenticated user to perform an account takeover via an XSS on the 'select-file' p...
CVE-2022-45218MEDIUM6.1Human Resource Management System v1.0.0 was discovered to contain a cross-site scripting (XSS) vulnerability. This vulne...
CVE-2022-45210MEDIUM4.3Jeecg-boot v3.4.3 was discovered to contain a SQL injection vulnerability via the component /sys/user/deleteRecycleBin.
CVE-2022-45208MEDIUM4.3Jeecg-boot v3.4.3 was discovered to contain a SQL injection vulnerability via the component /sys/user/putRecycleBin.
CVE-2022-45205MEDIUM5.3Jeecg-boot v3.4.3 was discovered to contain a SQL injection vulnerability via the component /sys/dict/queryTableData.
CVE-2022-45040MEDIUM5.4A cross-site scripting (XSS) vulnerability in /admin/pages/sections_save.php of WBCE CMS v1.5.4 allows attackers to exec...
CVE-2022-45038MEDIUM5.4A cross-site scripting (XSS) vulnerability in /admin/settings/save.php of WBCE CMS v1.5.4 allows attackers to execute ar...
CVE-2022-45037MEDIUM5.4A cross-site scripting (XSS) vulnerability in /admin/users/index.php of WBCE CMS v1.5.4 allows attackers to execute arbi...
CVE-2022-45036MEDIUM5.4A cross-site scripting (XSS) vulnerability in the Search Settings module of WBCE CMS v1.5.4 allows attackers to execute ...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now