2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-29481MEDIUM6.5A leftover debug code vulnerability exists in the console nvram functionality of InHand Networks InRouter302 V3.5.45. A ...
CVE-2022-26023MEDIUM6.5A leftover debug code vulnerability exists in the console verify functionality of InHand Networks InRouter302 V3.5.45. A...
CVE-2022-0031MEDIUM6.7A local privilege escalation (PE) vulnerability in the Palo Alto Networks Cortex XSOAR engine software running on a Linu...
CVE-2022-43488MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in Advanced Dynamic Pricing for WooCommerce plugin <= 4.1.5 on WordPress...
CVE-2022-43121MEDIUM6.1A cross-site scripting (XSS) vulnerability in the CMS Field Add page of Intelliants Subrion CMS v4.2.1 allows attackers ...
CVE-2022-43120MEDIUM6.1A cross-site scripting (XSS) vulnerability in the /panel/fields/add component of Intelliants Subrion CMS v4.2.1 allows a...
CVE-2022-43119MEDIUM6.1A cross-site scripting (XSS) vulnerability in Clansphere CMS v2011.4 allows attackers to execute arbitrary web scripts o...
CVE-2022-43118MEDIUM6.1A cross-site scripting (XSS) vulnerability in flatCore-CMS v2.1.0 allows attackers to execute arbitrary web scripts or H...
CVE-2022-41978MEDIUM6.5Auth. (subscriber+) Arbitrary Options Update vulnerability in Zoho CRM Lead Magnet plugin <= 1.7.5.8 on WordPress.
CVE-2022-43321MEDIUM6.1Shopwind v3.4.3 was discovered to contain a reflected cross-site scripting (XSS) vulnerability in the component /common/...
CVE-2022-43320MEDIUM6.1FeehiCMS v2.1.1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the id parameter at /...
CVE-2022-43144MEDIUM5.4A cross-site scripting (XSS) vulnerability in Canteen Management System v1.0 allows attackers to execute arbitrary web s...
CVE-2022-30515MEDIUM5.3ZKTeco BioTime 8.5.4 is missing authentication on folders containing employee photos, allowing an attacker to view them ...
CVE-2022-41260MEDIUM6.1SAP Financial Consolidation - version 1010, does not sufficiently encode user-controlled input which may allow an unauth...
CVE-2022-41259MEDIUM6.5SAP SQL Anywhere - version 17.0, allows an authenticated attacker to prevent legitimate users from accessing a SQL Anywh...
CVE-2022-41258MEDIUM6.5Due to insufficient input validation, SAP Financial Consolidation - version 1010, allows an authenticated attacker to in...
CVE-2022-41215MEDIUM4.7SAP NetWeaver ABAP Server and ABAP Platform allows an unauthenticated attacker to redirect users to a malicious site due...
CVE-2022-41212MEDIUM4.9Due to insufficient input validation, SAP NetWeaver Application Server ABAP and ABAP Platform allows an attacker with hi...
CVE-2022-41208MEDIUM5.4Due to insufficient input validation, SAP Financial Consolidation - version 1010, allows an authenticated attacker with ...
CVE-2022-41207MEDIUM6.1SAP Biller Direct allows an unauthenticated attacker to craft a legitimate looking URL. When clicked by an unsuspecting ...
CVE-2022-41205MEDIUM6.1SAP GUI allows an authenticated attacker to execute scripts in the local network. On successful exploitation, the attack...
CVE-2022-3821MEDIUM5.5An off-by-one Error issue was discovered in Systemd in format_timespan() function of time-util.c. An attacker could supp...
CVE-2022-20465MEDIUM4.6In dismiss and related functions of KeyguardHostViewController.java and related files, there is a possible lockscreen by...
CVE-2022-20457MEDIUM5.5In getMountModeInternal of StorageManagerService.java, there is a possible prevention of package installation due to imp...
CVE-2022-20454MEDIUM6.7In fdt_next_tag of fdt.c, there is a possible out of bounds write due to an integer overflow. This could lead to local e...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now