2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-2882MEDIUM4.3An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.6 before 15.2.5, all versions start...
CVE-2022-26884MEDIUM6.5Users can read any files by log server, Apache DolphinScheduler users should upgrade to version 2.0.6 or higher.
CVE-2022-41702MEDIUM5.4The affected product DIAEnergie (versions prior to v1.9.01.002) is vulnerable to a stored cross-site scripting vulnerabi...
CVE-2022-41701MEDIUM5.4The affected product DIAEnergie (versions prior to v1.9.01.002) is vulnerable to a stored cross-site scripting vulnerabi...
CVE-2022-41651MEDIUM5.4The affected product DIAEnergie (versions prior to v1.9.01.002) is vulnerable to a stored cross-site scripting vulnerabi...
CVE-2022-41555MEDIUM5.4The affected product DIAEnergie (versions prior to v1.9.01.002) is vulnerable to a stored cross-site scripting vulnerabi...
CVE-2022-40965MEDIUM5.4The affected product DIAEnergie (versions prior to v1.9.01.002) is vulnerable to a stored cross-site scripting vulnerabi...
CVE-2022-3387MEDIUM5.3 Advantech R-SeeNet Versions 2.4.19 and prior are vulnerable to path traversal attacks. An unauthorized attacker could r...
CVE-2022-0072MEDIUM5.8Directory Traversal vulnerability in LiteSpeed Technologies OpenLiteSpeed Web Server and LiteSpeed Web Server dashboards...
CVE-2022-32407MEDIUM6.1Softr v2.0 was discovered to contain a Cross-Site Scripting (XSS) vulnerability via the First Name parameter under the C...
CVE-2022-42055MEDIUM6.5Multiple command injection vulnerabilities in GL.iNet GoodCloud IoT Device Management System Version 1.00.220412.00 via ...
CVE-2022-42054MEDIUM5.4Multiple stored cross-site scripting (XSS) vulnerabilities in GL.iNet GoodCloud IoT Device Management System Version 1.0...
CVE-2022-31898MEDIUM6.8gl-inet GL-MT300N-V2 Mango v3.212 and GL-AX1800 Flint v3.214 were discovered to contain multiple command injection vulne...
CVE-2022-40184MEDIUM4.8Incomplete filtering of JavaScript code in different configuration fields of the web based interface of the VIDEOJET mul...
CVE-2022-40183MEDIUM4.7An error in the URL handler of the VIDEOJET multi 4000 may lead to a reflected cross site scripting (XSS) in the web-bas...
CVE-2022-24670MEDIUM6.5An attacker can use the unrestricted LDAP queries to determine configuration entries
CVE-2022-24669MEDIUM6.5It may be possible to gain some details of the deployment through a well-crafted attack. This may allow that data to be ...
CVE-2022-39364MEDIUM6.5Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform. In Nextcloud Server pri...
CVE-2022-42993MEDIUM5.4Password Storage Application v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Setup pag...
CVE-2022-42991MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in Simple Online Public Access Catalog v1.0 allows attackers to execut...
CVE-2022-39330MEDIUM4.3Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform. Nextcloud Server prior ...
CVE-2022-39329MEDIUM5.3Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform. Nextcloud Server and Ne...
CVE-2022-36182MEDIUM6.1Hashicorp Boundary v0.8.0 is vulnerable to Clickjacking which allow for the interception of login credentials, re-direct...
CVE-2022-42992MEDIUM5.4Multiple stored cross-site scripting (XSS) vulnerabilities in Train Scheduler App v1.0 allow attackers to execute arbitr...
CVE-2022-3716MEDIUM5.4A vulnerability classified as problematic was found in SourceCodester Online Medicine Ordering System 1.0. Affected by t...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now