2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-3415MEDIUM6.1The Chat Bubble WordPress plugin before 2.3 does not sanitise and escape some contact parameters, which could allow unau...
CVE-2022-2450MEDIUM4.3The reSmush.it : the only free Image Optimizer & compress plugin WordPress plugin before 0.4.4 lacks authorization in va...
CVE-2022-2449MEDIUM6.5The reSmush.it : the only free Image Optimizer & compress plugin WordPress plugin before 0.4.4 does not perform CSRF che...
CVE-2022-3988MEDIUM6.1A vulnerability was found in Frappe. It has been rated as problematic. Affected by this issue is some unknown functional...
CVE-2022-37290MEDIUM5.5GNOME Nautilus 42.2 allows a NULL pointer dereference and get_basename application crash via a pasted ZIP archive.
CVE-2022-3978MEDIUM4.3A vulnerability, which was classified as problematic, was found in NodeBB up to 2.5.7. This affects an unknown part of t...
CVE-2022-3975MEDIUM6.1A vulnerability, which was classified as problematic, has been found in NukeViet CMS. Affected by this issue is the func...
CVE-2022-3971MEDIUM5.6A vulnerability was found in matrix-appservice-irc up to 0.35.1. It has been declared as critical. This vulnerability af...
CVE-2022-3969MEDIUM5.5A vulnerability was found in OpenKM up to 6.3.11 and classified as problematic. Affected by this issue is the function g...
CVE-2022-3968MEDIUM6.1A vulnerability has been found in emlog and classified as problematic. Affected by this vulnerability is an unknown func...
CVE-2022-3963MEDIUM5.4A vulnerability was found in gnuboard5. It has been classified as problematic. Affected is an unknown function of the fi...
CVE-2022-45195MEDIUM5.3SimpleXMQ before 3.4.0, as used in SimpleX Chat before 4.2, does not apply a key derivation function to intended data, w...
CVE-2022-45194MEDIUM4.7CBRN-Analysis before 22 allows XXE attacks via am mws XML document, leading to NTLMv2-SSP hash disclosure.
CVE-2022-41905MEDIUM6.1WsgiDAV is a generic and extendable WebDAV server based on WSGI. Implementations using this library with directory brows...
CVE-2022-41904MEDIUM6.5Element iOS is an iOS Matrix client provided by Element. It is based on MatrixSDK. Prior to version 1.9.7, events encryp...
CVE-2022-40750MEDIUM5.4IBM WebSphere Application Server 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to ...
CVE-2022-36776MEDIUM5.4IBM Cloud Pak for Security (CP4S) 1.10.0.0 79and 1.10.2.0 is vulnerable to cross-site scripting. This vulnerability allo...
CVE-2022-31772MEDIUM6.5 IBM MQ 8.0, 9.0 LTS, 9.1 CD, 9.1 LTS, 9.2 CD, and 9.2 LTS could allow an authenticated and authorized user to cause a d...
CVE-2022-3959MEDIUM5.3A vulnerability, which was classified as problematic, has been found in drogon up to 1.8.1. Affected by this issue is so...
CVE-2022-3957MEDIUM6.5A vulnerability classified as problematic was found in GPAC. Affected by this vulnerability is the function svg_parse_pr...
CVE-2022-36367MEDIUM4.4Incorrect default permissions in the Intel(R) Support Android application before version v22.02.28 may allow a privilege...
CVE-2022-36349MEDIUM5.5Insecure default variable initialization in BIOS firmware for some Intel(R) NUC Boards and Intel(R) NUC Kits before vers...
CVE-2022-35276MEDIUM6.7Improper access control in BIOS firmware for some Intel(R) NUC 8 Compute Elements before version CBWHL357.0096 may allow...
CVE-2022-34152MEDIUM6.7Improper input validation in BIOS firmware for some Intel(R) NUC Boards, Intel(R) NUC Kits before version TY0070 may all...
CVE-2022-33176MEDIUM6.7Improper input validation in BIOS firmware for some Intel(R) NUC 11 Performance kits and Intel(R) NUC 11 Performance Min...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now