2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-39067MEDIUM6.5There is a buffer overflow vulnerability in ZTE MF286R. Due to lack of input validation on parameters of the wifi interf...
CVE-2022-41952MEDIUM5.3Synapse before 1.52.0 with URL preview functionality enabled will attempt to generate URL previews for media stream URLs...
CVE-2022-41445MEDIUM4.8A cross-site scripting (XSS) vulnerability in Record Management System using CodeIgniter 1.0 allows attackers to execute...
CVE-2022-42097MEDIUM4.8Backdrop CMS version 1.23.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via 'Comment.' .
CVE-2022-42094MEDIUM4.8Backdrop CMS version 1.23.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the 'Card' c...
CVE-2022-38462MEDIUM6.1Silverstripe silverstripe/framework through 4.11 is vulnerable to XSS by carefully crafting a return URL on a /dev/build...
CVE-2022-2513MEDIUM5.5A vulnerability exists in the Intelligent Electronic Device (IED) Connectivity Package (ConnPack) credential storage fun...
CVE-2022-40954MEDIUM5.5Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Airfl...
CVE-2022-45363MEDIUM5.4Auth. (subscriber+) Stored Cross-Site Scripting (XSS) in Muffingroup Betheme theme <= 26.6.1 on WordPress.
CVE-2022-4111MEDIUM6.5Unrestricted file size limit can lead to DoS in tooljet/tooljet <1.27 by allowing a logged in attacker to upload profile...
CVE-2022-41940MEDIUM6.5Engine.IO is the implementation of transport-based cross-browser/cross-device bi-directional communication layer for Soc...
CVE-2022-41223MEDIUM6.8The Director database component of MiVoice Connect through 19.3 (22.22.6100.0) could allow an authenticated attacker to ...
CVE-2022-40765MEDIUM6.8A vulnerability in the Edge Gateway component of Mitel MiVoice Connect through 19.3 (22.22.6100.0) could allow an authen...
CVE-2022-43709MEDIUM4.9MyBB 1.8.31 has a SQL injection vulnerability in the Admin CP's Users module allows remote authenticated users to modify...
CVE-2022-43708MEDIUM6.1MyBB 1.8.31 has a (issue 2 of 2) cross-site scripting (XSS) vulnerabilities in the post Attachments interface allow atta...
CVE-2022-43707MEDIUM6.1MyBB 1.8.31 has a Cross-site scripting (XSS) vulnerability in the visual MyCode editor (SCEditor) allows remote attacker...
CVE-2022-44788MEDIUM6.5An issue was discovered in Appalti & Contratti 9.12.2. It allows Session Fixation. When a user logs in providing a JSESS...
CVE-2022-44787MEDIUM6.1An issue was discovered in Appalti & Contratti 9.12.2. The web applications are vulnerable to a Reflected Cross-Site Scr...
CVE-2022-42096MEDIUM4.8Backdrop CMS version 1.23.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via Post content...
CVE-2022-4105MEDIUM5.4A stored XSS in a kiwi Test Plan can run malicious javascript which could be chained with an HTML injection to perform a...
CVE-2022-43117MEDIUM5.4Sourcecodester Password Storage Application in PHP/OOP and MySQL 1.0 was discovered to contain multiple cross-site scrip...
CVE-2022-40746MEDIUM6.7IBM i Access Family 1.1.2 through 1.1.4 and 1.1.4.3 through 1.1.9.0 could allow a local authenticated attacker to execut...
CVE-2022-38755MEDIUM5.3A vulnerability has been identified in Micro Focus Filr in versions prior to 4.3.1.1. The vulnerability could be exploit...
CVE-2022-35897MEDIUM6.8An stack buffer overflow vulnerability leads to arbitrary code execution issue was discovered in Insyde InsydeH2O with k...
CVE-2022-40470MEDIUM4.8Phpgurukul Blood Donor Management System 1.0 allows Cross Site Scripting via Add Blood Group Name Feature.

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now