2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-39026MEDIUM5.4U-Office Force UserDefault page has insufficient filtering for special characters in the HTTP header fields. A remote at...
CVE-2022-39025MEDIUM6.1U-Office Force PrintMessage function has insufficient filtering for special characters. An unauthenticated remote attack...
CVE-2022-39024MEDIUM6.1U-Office Force Bulletin function has insufficient filtering for special characters. An unauthenticated remote attacker c...
CVE-2022-39023MEDIUM6.5U-Office Force Download function has a path traversal vulnerability. A remote attacker with general user privilege can e...
CVE-2022-39022MEDIUM6.5U-Office Force Download function has a path traversal vulnerability. A remote attacker with general user privilege can e...
CVE-2022-39021MEDIUM6.1U-Office Force login function has an Open Redirect vulnerability. An unauthenticated remote attacker can exploit this vu...
CVE-2022-44034MEDIUM6.4An issue was discovered in the Linux kernel through 6.0.6. drivers/char/pcmcia/scr24x_cs.c has a race condition and resu...
CVE-2022-44033MEDIUM6.4An issue was discovered in the Linux kernel through 6.0.6. drivers/char/pcmcia/cm4040_cs.c has a race condition and resu...
CVE-2022-44032MEDIUM6.4An issue was discovered in the Linux kernel through 6.0.6. drivers/char/pcmcia/cm4000_cs.c has a race condition and resu...
CVE-2022-44023MEDIUM5.3PwnDoc through 0.5.3 might allow remote attackers to identify disabled user account names by leveraging response message...
CVE-2022-44022MEDIUM5.3PwnDoc through 0.5.3 might allow remote attackers to identify valid user account names by leveraging response timings fo...
CVE-2022-44020MEDIUM5.5An issue was discovered in OpenStack Sushy-Tools through 0.21.0 and VirtualBMC through 2.2.2. Changing the boot device c...
CVE-2022-43283MEDIUM5.5wasm2c v1.0.29 was discovered to contain an abort in CWriter::Write.
CVE-2022-3402MEDIUM6.1The Log HTTP Requests plugin for WordPress is vulnerable to Stored Cross-Site Scripting via logged HTTP requests in vers...
CVE-2022-3228MEDIUM6.5Using custom code, an attacker can write into name or description fields larger than the appropriate buffer size causing...
CVE-2022-43170MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in the Dashboard Configuration feature (index.php?module=dashboard_con...
CVE-2022-43169MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in the Users Access Groups feature (/index.php?module=users_groups/use...
CVE-2022-43167MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in the Users Alerts feature (/index.php?module=users_alerts/users_aler...
CVE-2022-43166MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in the Global Entities feature (/index.php?module=entities/entities) o...
CVE-2022-43165MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in the Global Variables feature (/index.php?module=global_vars/vars) o...
CVE-2022-43164MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in the Global Lists feature (/index.php?module=global_lists/lists) of ...
CVE-2022-3400MEDIUM6.5The Bricks theme for WordPress is vulnerable to authorization bypass due to a missing capability check on the bricks_sav...
CVE-2022-39367MEDIUM6.5QTIWorks is a software suite for standards-based assessment delivery. Prior to version 1.0-beta15, the QTIWorks Engine a...
CVE-2022-37424MEDIUM6.5Files or Directories Accessible to External Parties vulnerability in OpenNebula on Linux allows File Discovery.
CVE-2022-3018MEDIUM4.9An information disclosure vulnerability in GitLab CE/EE affecting all versions starting from 9.3 before 15.2.5, all vers...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now