2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-41433MEDIUM4.8EyesOfNetwork Web Interface v5.3 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the ...
CVE-2022-41432MEDIUM4.8EyesOfNetwork Web Interface v5.3 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the ...
CVE-2022-43046MEDIUM4.8Food Ordering Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the compone...
CVE-2022-44746MEDIUM5.5Sensitive information disclosure due to insecure folder permissions. The following products are affected: Acronis Cyber ...
CVE-2022-44745MEDIUM5.5Sensitive information leak through log files. The following products are affected: Acronis Cyber Protect Home Office (Wi...
CVE-2022-38164MEDIUM6.5A vulnerability affecting F-Secure SAFE browser for Android and iOS was discovered. A maliciously crafted website could ...
CVE-2022-43351MEDIUM6.5Sanitization Management System v1.0 was discovered to contain an arbitrary file deletion vulnerability via the component...
CVE-2022-43317MEDIUM6.1A cross-site scripting (XSS) vulnerability in /hrm/index.php?msg of Human Resource Management System v1.0 allows attacke...
CVE-2022-2188MEDIUM5.5Privilege escalation vulnerability in DXL Broker for Windows prior to 6.0.0.280 allows local users to gain elevated priv...
CVE-2022-3873MEDIUM6.1Cross-site Scripting (XSS) - DOM in GitHub repository jgraph/drawio prior to 20.5.2.
CVE-2022-3489MEDIUM5.3The WP Hide WordPress plugin through 0.0.2 does not have authorisation and CSRF checks in place when updating the custom...
CVE-2022-3462MEDIUM4.8The Highlight Focus WordPress plugin through 1.1 does not sanitise and escape some of its settings, which could allow hi...
CVE-2022-3451MEDIUM4.3The Product Stock Manager WordPress plugin before 1.0.5 does not have authorisation and proper CSRF checks in multiple A...
CVE-2022-2387MEDIUM4.3The Easy Digital Downloads WordPress plugin before 3.0 does not have CSRF check in place when deleting payment history, ...
CVE-2022-44795MEDIUM6.5An issue was discovered in Object First Ootbi BETA build 1.0.7.712. A flaw was found in the Web Service, which could lea...
CVE-2022-44793MEDIUM6.5handle_ipv6IpForwarding in agent/mibgroup/ip-mib/ip_scalars.c in Net-SNMP 5.4.3 through 5.9.3 has a NULL Pointer Excepti...
CVE-2022-44792MEDIUM6.5handle_ipDefaultTTL in agent/mibgroup/ip-mib/ip_scalars.c in Net-SNMP 5.8 through 5.9.3 has a NULL Pointer Exception bug...
CVE-2022-3869MEDIUM6.1Code Injection in GitHub repository froxlor/froxlor prior to 0.10.38.2.
CVE-2022-43572MEDIUM6.5In Splunk Enterprise versions below 8.2.9, 8.1.12, and 9.0.2, sending a malformed file through the Splunk-to-Splunk (S2S...
CVE-2022-43570MEDIUM6.5In Splunk Enterprise versions below 8.1.12, 8.2.9, and 9.0.2, an authenticated user can perform an extensible markup lan...
CVE-2022-43569MEDIUM5.4In Splunk Enterprise versions below 8.1.12, 8.2.9, and 9.0.2, an authenticated user can inject and store arbitrary scrip...
CVE-2022-43568MEDIUM6.1In Splunk Enterprise versions below 8.1.12, 8.2.9, and 9.0.2, a View allows for a Reflected Cross Site Scripting via Jav...
CVE-2022-43564MEDIUM6.5In Splunk Enterprise versions below 8.1.12, 8.2.9, and 9.0.2, a remote user who can create search macros and schedule se...
CVE-2022-43562MEDIUM5.4In Splunk Enterprise versions below 8.1.12, 8.2.9, and 9.0.2, Splunk Enterprise fails to properly validate and escape th...
CVE-2022-39384MEDIUM5.6OpenZeppelin Contracts is a library for secure smart contract development. Before version 4.4.1 but after 3.2.0, initial...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now