2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-38654MEDIUM5.5HCL Domino is susceptible to an information disclosure vulnerability. In some scenarios, local calls made on the server...
CVE-2022-27894MEDIUM5.4The Foundry Blobster service was found to have a cross-site scripting (XSS) vulnerability that could have allowed an att...
CVE-2022-20969MEDIUM5.4A vulnerability in multiple management dashboard pages of Cisco Umbrella could allow an authenticated, remote attacker t...
CVE-2022-20963MEDIUM5.4A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticat...
CVE-2022-20951MEDIUM6.5A vulnerability in the web-based management interface of Cisco BroadWorks CommPilot application could allow an authentic...
CVE-2022-20942MEDIUM6.5A vulnerability in the web-based management interface of Cisco Email Security Appliance (ESA), Cisco Secure Email and We...
CVE-2022-20937MEDIUM5.3A vulnerability in a feature that monitors RADIUS requests on Cisco Identity Services Engine (ISE) Software could allow ...
CVE-2022-20867MEDIUM6.5A vulnerability in web-based management interface of the of Cisco Email Security Appliance and Cisco Secure Email and We...
CVE-2022-20772MEDIUM5.3A vulnerability in Cisco Email Security Appliance (ESA) and Cisco Secure Email and Web Manager could allow an unauthenti...
CVE-2022-27893MEDIUM4.2The Foundry Magritte plugin osisoft-pi-web-connector versions 0.15.0 - 0.43.0 was found to be logging in a manner that c...
CVE-2022-3721MEDIUM4.6Code Injection in GitHub repository froxlor/froxlor prior to 0.10.39.
CVE-2022-38582MEDIUM6.5Incorrect access control in the anti-virus driver wsdkd.sys of Watchdog Antivirus v1.4.158 allows attackers to write arb...
CVE-2022-44724MEDIUM5.4The Handy Tip macro in Stiltsoft Handy Macros for Confluence Server/Data Center 3.x before 3.5.5 allows remote attackers...
CVE-2022-43561MEDIUM4.8In Splunk Enterprise versions below 8.1.12, 8.2.9, and 9.0.2, a remote user that holds the “power” Splunk role can store...
CVE-2022-44628MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in JumpDEMAND Inc. 4ECPS Web Forms plugin <= 0.2.17 on Wo...
CVE-2022-44627MEDIUM5.4Cross-Site Request Forgery (CSRF) vulnerability in David Cole Simple SEO plugin <= 1.8.12 on WordPress allows attackers ...
CVE-2022-43451MEDIUM6.5OpenHarmony-v3.1.2 and prior versions had an Multiple path traversal vulnerability in appspawn and nwebspawn services. L...
CVE-2022-43449MEDIUM5.5OpenHarmony-v3.1.2 and prior versions had an Arbitrary file read vulnerability via download_server. Local attackers can ...
CVE-2022-42749MEDIUM6.1CandidATS version 3.0.0 on 'page' of the 'ajax.php' resource, allows an external attacker to steal the cookie of arbitra...
CVE-2022-42748MEDIUM6.1CandidATS version 3.0.0 on 'sortDirection' of the 'ajax.php' resource, allows an external attacker to steal the cookie o...
CVE-2022-42747MEDIUM6.1CandidATS version 3.0.0 on 'sortBy' of the 'ajax.php' resource, allows an external attacker to steal the cookie of arbit...
CVE-2022-42746MEDIUM6.1CandidATS version 3.0.0 on 'indexFile' of the 'ajax.php' resource, allows an external attacker to steal the cookie of ar...
CVE-2022-42743MEDIUM5.3deep-parse-json version 1.0.2 allows an external attacker to edit or add new properties to an object. This is possible b...
CVE-2022-41714MEDIUM5.3fastest-json-copy version 1.0.1 allows an external attacker to edit or add new properties to an object. This is possible...
CVE-2022-41713MEDIUM5.3deep-object-diff version 1.1.0 allows an external attacker to edit or add new properties to an object. This is possible ...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now