2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-41710MEDIUM5.5Markdownify version 1.4.1 allows an external attacker to remotely obtain arbitrary local files on any client that attemp...
CVE-2022-40276MEDIUM5.5Zettlr version 2.3.0 allows an external attacker to remotely obtain arbitrary local files on any client that attempts to...
CVE-2022-40235MEDIUM6.5"IBM InfoSphere Information Server 11.7 could allow a user to cause a denial of service by removing the ability to run j...
CVE-2022-40230MEDIUM6.5"IBM MQ Appliance 9.2 CD, 9.2 LTS, 9.3 CD, and LTS 9.3 does not invalidate session after logout which could allow an aut...
CVE-2022-40131MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in a3rev Software Page View Count plugin <= 2.5.5 on WordPress allows an...
CVE-2022-38712MEDIUM5.9"IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 Web services could allow a man-in-the-middle attacker to conduc...
CVE-2022-38710MEDIUM5.3IBM Robotic Process Automation 21.0.1 and 21.0.2 could disclose sensitive version to an unauthorized control sphere info...
CVE-2022-36428MEDIUM4.8Auth. (admin+) Cross-Site Scripting (XSS) vulnerability in Stage Rock Convert plugin <= 2.11.0 on WordPress.
CVE-2022-36404MEDIUM5.4Missing Authorization, Cross-Site Request Forgery (CSRF) vulnerability in David Cole Simple SEO (WordPress plugin) plugi...
CVE-2022-35642MEDIUM5.4"IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed ...
CVE-2022-35279MEDIUM4.3"IBM Business Automation Workflow 18.0.0.0, 18.0.0.1, 18.0.0.2, 19.0.0.1, 19.0.0.2, 19.0.0.3, 20.0.0.1, 20.0.0.2, 21.0.2...
CVE-2022-34339MEDIUM6.5"IBM Cognos Analytics 11.2.1, 11.2.0, 11.1.7 stores user credentials in plain clear text which can be read by an authent...
CVE-2022-30615MEDIUM5.4"IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed ...
CVE-2022-22442MEDIUM6.5"IBM InfoSphere Information Server 11.7 could allow an authenticated user to access information restricted to users with...
CVE-2022-43372MEDIUM4.8Emlog Pro v1.7.1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability at /admin/store.php.
CVE-2022-42753MEDIUM6.1SalonERP version 3.0.2 allows an external attacker to steal the cookie of arbitrary users. This is possible because the ...
CVE-2022-3852MEDIUM6.5The VR Calendar plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.3.3...
CVE-2022-3675MEDIUM5.5Fedora CoreOS supports setting a GRUB bootloader password using a Butane config. When this feature is enabled, GRUB requ...
CVE-2022-2696MEDIUM6.5The Restaurant Menu – Food Ordering System – Table Reservation plugin for WordPress is vulnerable to authorization bypas...
CVE-2022-39376MEDIUM6.5GLPI stands for Gestionnaire Libre de Parc Informatique. GLPI is a Free Asset and IT Management Software package that pr...
CVE-2022-39375MEDIUM5.4GLPI stands for Gestionnaire Libre de Parc Informatique. GLPI is a Free Asset and IT Management Software package that pr...
CVE-2022-39373MEDIUM4.8GLPI stands for Gestionnaire Libre de Parc Informatique. GLPI is a Free Asset and IT Management Software package that pr...
CVE-2022-39372MEDIUM5.4GLPI stands for Gestionnaire Libre de Parc Informatique. GLPI is a Free Asset and IT Management Software package that pr...
CVE-2022-39371MEDIUM5.4GLPI stands for Gestionnaire Libre de Parc Informatique. GLPI is a Free Asset and IT Management Software package that pr...
CVE-2022-39370MEDIUM4.3GLPI stands for Gestionnaire Libre de Parc Informatique. GLPI is a Free Asset and IT Management Software package that pr...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now