2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-45150MEDIUM6.1A reflected cross-site scripting vulnerability was discovered in Moodle. This flaw exists due to insufficient sanitizati...
CVE-2022-45149MEDIUM5.4A vulnerability was found in Moodle which exists due to insufficient validation of the HTTP request origin in course red...
CVE-2022-42895MEDIUM6.5There is an infoleak vulnerability in the Linux kernel's net/bluetooth/l2cap_core.c's l2cap_parse_conf_req function whic...
CVE-2022-4045MEDIUM6.5A denial-of-service vulnerability in the Mattermost allows an authenticated user to crash the server via multiple reques...
CVE-2022-4044MEDIUM6.5A denial-of-service vulnerability in Mattermost allows an authenticated user to crash the server via multiple large auto...
CVE-2022-4019MEDIUM6.5A denial-of-service vulnerability in the Mattermost Playbooks plugin allows an authenticated user to crash the server vi...
CVE-2022-45472MEDIUM5.4CAE LearningSpace Enterprise (with Intuity License) image 267r patch 639 allows DOM XSS, related to ontouchmove and onpo...
CVE-2022-41446MEDIUM5.4An access control issue in /Admin/dashboard.php of Record Management System using CodeIgniter v1.0 allows attackers to a...
CVE-2022-38147MEDIUM5.4Silverstripe silverstripe/framework through 4.11 allows XSS (issue 3 of 3).
CVE-2022-37421MEDIUM5.4Silverstripe silverstripe/cms through 4.11.0 allows XSS.
CVE-2022-42095MEDIUM4.8Backdrop CMS version 1.23.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Page con...
CVE-2022-38145MEDIUM5.4Silverstripe silverstripe/framework through 4.11 allows XSS (issue 1 of 3) via remote attackers adding a Javascript payl...
CVE-2022-37430MEDIUM5.4Silverstripe silverstripe/framework through 4.11 allows XSS vulnerability via href attribute of a link (issue 2 of 2).
CVE-2022-37429MEDIUM5.4Silverstripe silverstripe/framework through 4.11 allows XSS (issue 1 of 2) via JavaScript payload to the href attribute ...
CVE-2022-35500MEDIUM5.4Amasty Blog 2.10.3 is vulnerable to Cross Site Scripting (XSS) via leave comment functionality.
CVE-2022-38724MEDIUM5.4Silverstripe silverstripe/framework through 4.11.0, silverstripe/assets through 1.11.0, and silverstripe/asset-admin thr...
CVE-2022-37774MEDIUM5.3There is a broken access control vulnerability in the Maarch RM 2.8.3 solution. When accessing some specific document (p...
CVE-2022-37773MEDIUM6.5An authenticated SQL Injection vulnerability in the statistics page (/statistics/retrieve) of Maarch RM 2.8, via the fil...
CVE-2022-45536MEDIUM4.9AeroCMS v0.0.1 was discovered to contain a SQL Injection vulnerability via the id parameter at \admin\post_comments.php....
CVE-2022-45535MEDIUM4.9AeroCMS v0.0.1 was discovered to contain a SQL Injection vulnerability via the edit parameter at \admin\categories.php. ...
CVE-2022-45529MEDIUM4.9AeroCMS v0.0.1 was discovered to contain a SQL Injection vulnerability via the post_category_id parameter at \admin\incl...
CVE-2022-39397MEDIUM4.3aliyun-oss-client is a rust client for Alibaba Cloud OSS. Users of this library will be affected, the incoming secret wi...
CVE-2022-39199MEDIUM5.9immudb is a database with built-in cryptographic proof and verification. immudb client SDKs use server's UUID to disting...
CVE-2022-40228MEDIUM5.4 IBM DataPower Gateway 10.0.3.0 through 10.0.4.0, 10.0.1.0 through 10.0.1.9, 2018.4.1.0 through 2018.4.1.22, and 10.5....
CVE-2022-3500MEDIUM5.1A vulnerability was found in keylime. This security issue happens in some circumstances, due to some improperly handled ...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now