2022 CVE Vulnerabilities
27,525 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-50948 | MEDIUM | 6.4 | 0.2% | May 10, 2026 | Motopress Hotel Booking Lite 4.2.4 contains a stored cross-site scripting vulnerability that allows authenticated attack... |
| CVE-2022-50947 | MEDIUM | 6.4 | 0.2% | May 10, 2026 | WordPress Plugin Testimonial Slider and Showcase 2.2.6 contains a stored cross-site scripting vulnerability that allows ... |
| CVE-2022-50946 | MEDIUM | 6.4 | 0.2% | May 10, 2026 | WordPress Plugin Netroics Blog Posts Grid 1.0 contains a stored cross-site scripting vulnerability that allows authentic... |
| CVE-2022-50945 | MEDIUM | 6.4 | 0.2% | May 10, 2026 | WordPress 3dady Real-Time Web Stats plugin 1.0 contains a stored cross-site scripting vulnerability that allows authenti... |
| CVE-2022-50943 | MEDIUM | 6.1 | 0.3% | May 10, 2026 | Moodle LMS 4.0 contains a cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious s... |
| CVE-2022-45899 | MEDIUM | 6.5 | 0.8% | May 8, 2026 | Nokia Broadcast Message Center (BMC) before 13.1 allows an unauthenticated remote attacker to do OS command injection as... |
| CVE-2022-26523 | MEDIUM | 5.3 | 0.3% | May 8, 2026 | The socket connection handler in aswArPot.sys in the Avast and AVG Windows Anti Rootkit driver before 22.1 allows local ... |
| CVE-2022-23961 | MEDIUM | 6.1 | 0.2% | May 8, 2026 | In Thruk Monitoring through 2.46.3, the login field of the login form is vulnerable to reflected XSS. This vulnerability... |
| CVE-2022-41650 | MEDIUM | 6.5 | 0.3% | Feb 17, 2026 | Missing Authorization vulnerability in Paul Custom Content by Country (by Shield Security) custom-content-by-country.Thi... |
| CVE-2022-50980 | MEDIUM | 6.5 | 0.2% | Feb 2, 2026 | A unauthenticated adjacent attacker could potentially disrupt operations by switching between multiple configuration pre... |
| CVE-2022-50979 | MEDIUM | 6.5 | 0.2% | Feb 2, 2026 | An unauthenticated adjacent attacker could potentially disrupt operations by switching between multiple configuration pr... |
| CVE-2022-50952 | MEDIUM | 6.4 | 0.2% | Feb 1, 2026 | Banco Guayaquil 8.0.0 mobile iOS application contains a persistent cross-site scripting vulnerability in the TextBox Nam... |
| CVE-2022-50951 | MEDIUM | 6.4 | 0.3% | Feb 1, 2026 | WiFi File Transfer 1.0.8 contains a persistent cross-site scripting vulnerability that allows remote attackers to inject... |
| CVE-2022-50942 | MEDIUM | 5.4 | 0.3% | Feb 1, 2026 | Incinga Web 2.8.2 contains a client-side cross-site scripting vulnerability that allows remote attackers to inject malic... |
| CVE-2022-50941 | MEDIUM | 6.4 | 0.3% | Feb 1, 2026 | BootCommerce 3.2.1 contains persistent input validation vulnerabilities that allow remote attackers to inject malicious ... |
| CVE-2022-50940 | MEDIUM | 6.4 | 0.3% | Feb 1, 2026 | Knap Advanced PHP Login 3.1.3 contains a persistent cross-site scripting vulnerability that allows remote attackers to i... |
| CVE-2022-50797 | MEDIUM | 6.4 | 0.4% | Feb 1, 2026 | Stripe Green Downloads Wordpress Plugin 2.03 contains a persistent cross-site scripting vulnerability allowing remote at... |
| CVE-2022-50937 | MEDIUM | 6.1 | 0.3% | Jan 13, 2026 | Ametys CMS v4.4.1 contains a persistent cross-site scripting vulnerability in the link directory's input fields for exte... |
| CVE-2022-50906 | MEDIUM | 4.8 | 0.4% | Jan 13, 2026 | e107 CMS 3.2.1 contains an upload restriction bypass vulnerability that allows authenticated administrators to upload ma... |
| CVE-2022-50905 | MEDIUM | 6.1 | 0.6% | Jan 13, 2026 | e107 CMS version 3.2.1 contains multiple vulnerabilities that allow cross-site scripting (XSS) attacks. The first vulner... |
| CVE-2022-50896 | MEDIUM | 6.1 | 0.3% | Jan 13, 2026 | Testa 3.5.1 contains a reflected cross-site scripting vulnerability in the login.php redirect parameter that allows atta... |
| CVE-2022-50891 | MEDIUM | 5.1 | 0.2% | Jan 13, 2026 | Owlfiles File Manager 12.0.1 contains a cross-site scripting vulnerability that allows attackers to inject malicious scr... |
| CVE-2022-50802 | MEDIUM | 6.1 | 0.3% | Dec 30, 2025 | ETAP Safety Manager 1.0.0.32 contains a cross-site scripting vulnerability in the 'action' GET parameter that allows una... |
| CVE-2022-50801 | MEDIUM | 5.1 | 0.2% | Dec 30, 2025 | JM-DATA ONU JF511-TV version 1.0.67 is vulnerable to authenticated stored cross-site scripting (XSS) attacks, allowing a... |
| CVE-2022-50689 | MEDIUM | 5.5 | 0.2% | Dec 22, 2025 | Cobian Reflector 0.9.93 RC1 contains a denial of service vulnerability that allows attackers to crash the application by... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now