2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-42127MEDIUM5.3The Friendly Url module in Liferay Portal 7.4.3.5 through 7.4.3.36, and Liferay DXP 7.4 update 1 though 36 does not prop...
CVE-2022-42126MEDIUM4.3The Asset Libraries module in Liferay Portal 7.3.5 through 7.4.3.28, and Liferay DXP 7.3 before update 8, and DXP 7.4 be...
CVE-2022-42119MEDIUM5.4Certain Liferay products are vulnerable to Cross Site Scripting (XSS) via the Commerce module. This affects Liferay Port...
CVE-2022-42118MEDIUM6.1A Cross-site scripting (XSS) vulnerability in the Portal Search module in Liferay Portal 7.1.0 through 7.4.2, and Lifera...
CVE-2022-42111MEDIUM5.4A Cross-site scripting (XSS) vulnerability in the Sharing module's user notification in Liferay Portal 7.2.1 through 7.4...
CVE-2022-42110MEDIUM6.1A Cross-site scripting (XSS) vulnerability in the Announcements module in Liferay Portal 7.1.0 through 7.4.2, and Lifera...
CVE-2022-33986MEDIUM6.4DMA attacks on the parameter buffer used by the VariableRuntimeDxe software SMI handler could lead to a TOCTOU attack. D...
CVE-2022-33906MEDIUM6.4DMA transactions which are targeted at input buffers used for the FwBlockServiceSmm software SMI handler could cause SMR...
CVE-2022-32267MEDIUM6.4DMA transactions which are targeted at input buffers used for the SmmResourceCheckDxe software SMI handler cause SMRAM c...
CVE-2022-31243MEDIUM6.4Update description and links DMA transactions which are targeted at input buffers used for the software SMI handler used...
CVE-2022-30774MEDIUM6.4DMA attacks on the parameter buffer used by the PnpSmm driver could change the contents after parameter values have been...
CVE-2022-43695MEDIUM4.8Concrete CMS (formerly concrete5) below 8.5.10 and between 9.0.0 and 9.1.2 is vulnerable to Stored Cross-Site Scripting ...
CVE-2022-43691MEDIUM5.3Concrete CMS (formerly concrete5) below 8.5.10 and between 9.0.0 and 9.1.2 inadvertently disclose server-side sensitive ...
CVE-2022-43690MEDIUM6.3Concrete CMS (formerly concrete5) below 8.5.10 and between 9.0.0 and 9.1.2 did not use strict comparison for the legacy_...
CVE-2022-43689MEDIUM5.3Concrete CMS (formerly concrete5) below 8.5.10 and between 9.0.0 and 9.1.2 is vulnerable to XXE based DNS requests leadi...
CVE-2022-43688MEDIUM4.8Concrete CMS (formerly concrete5) below 8.5.10 and between 9.0.0 and 9.1.2 is vulnerable to Stored Cross-Site Scripting ...
CVE-2022-43687MEDIUM5.4Concrete CMS (formerly concrete5) below 8.5.10 and between 9.0.0 and 9.1.2 does not issue a new session ID upon successf...
CVE-2022-40903MEDIUM6.5Aiphone GT-DMB-N 3-in-1 Video Entrance Station with NFC Reader 1.0.3 does not mitigate against repeated failed access at...
CVE-2022-33982MEDIUM6.4DMA attacks on the parameter buffer used by the Int15ServiceSmm software SMI handler could lead to a TOCTOU attack on th...
CVE-2022-33907MEDIUM6.4DMA transactions which are targeted at input buffers used for the software SMI handler used by the IdeBusDxe driver coul...
CVE-2022-43968MEDIUM6.1Concrete CMS (formerly concrete5) below 8.5.10 and between 9.0.0 and 9.1.2 is vulnerable to Reflected XSS in the dashboa...
CVE-2022-43967MEDIUM6.1Concrete CMS (formerly concrete5) below 8.5.10 and between 9.0.0 and 9.1.2 is vulnerable to Reflected XSS in the multili...
CVE-2022-43686MEDIUM6.5In Concrete CMS (formerly concrete5) below 8.5.10 and between 9.0.0 and 9.1.2, the authTypeConcreteCookieMap table can b...
CVE-2022-32266MEDIUM6.4DMA attacks on the parameter buffer used by a software SMI handler used by the driver PcdSmmDxe could lead to a TOCTOU a...
CVE-2022-30773MEDIUM6.4DMA attacks on the parameter buffer used by the IhisiSmm driver could change the contents after parameter values have be...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now