2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-27912MEDIUM5.3An issue was discovered in Joomla! 4.0.0 through 4.2.3. Sites with publicly enabled debug mode exposed data of previous ...
CVE-2022-3644MEDIUM5.5The collection remote for pulp_ansible stores tokens in plaintext instead of using pulp's encrypted field and exposes th...
CVE-2022-36454MEDIUM6.5A vulnerability in the MiCollab Client API of Mitel MiCollab through 9.5.0.101 could allow an authenticated attacker to ...
CVE-2022-3392MEDIUM4.8The WP Humans.txt WordPress plugin through 1.0.6 does not sanitise and escape some of its settings, which could allow hi...
CVE-2022-3391MEDIUM4.8The Retain Live Chat WordPress plugin through 0.1 does not sanitise and escape some of its settings, which could allow h...
CVE-2022-3350MEDIUM4.8The Contact Bank WordPress plugin through 3.0.30 does not sanitise and escape some of its Form settings, which could all...
CVE-2022-3344MEDIUM5.5A flaw was found in the KVM's AMD nested virtualization (SVM). A malicious L1 guest could purposely fail to intercept th...
CVE-2022-3247MEDIUM6.5The Blog2Social: Social Media Auto Post & Scheduler WordPress plugin before 6.9.10 does not have authorisation in an AJA...
CVE-2022-3097MEDIUM6.5The Plugin LBstopattack WordPress plugin before 1.1.3 does not use nonces when saving its settings, making it possible f...
CVE-2022-39837MEDIUM5.5An issue was discovered in Connected Vehicle Systems Alliance (COVESA) dlt-daemon through 2.18.8. Due to a faulty DLT fi...
CVE-2022-39836MEDIUM5.5An issue was discovered in Connected Vehicle Systems Alliance (COVESA) dlt-daemon through 2.18.8. Due to a faulty DLT fi...
CVE-2022-39351MEDIUM4.4Dependency-Track is a Component Analysis platform that allows organizations to identify and reduce risk in the software ...
CVE-2022-39350MEDIUM5.4@dependencytrack/frontend is a Single Page Application (SPA) used in Dependency-Track, an open source Component Analysis...
CVE-2022-39349MEDIUM5.5The Tasks.org Android app is an open-source app for to-do lists and reminders. The Tasks.org app uses the activity `Shar...
CVE-2022-39340MEDIUM5.3OpenFGA is an authorization/permission engine. Prior to version 0.2.4, the `streamed-list-objects` endpoint was not vali...
CVE-2022-39315MEDIUM5.3Kirby is a Content Management System. Prior to versions 3.5.8.2, 3.6.6.2, 3.7.5.1, and 3.8.1, a user enumeration vulnera...
CVE-2022-38200MEDIUM6.1A cross site scripting vulnerability exists in some map service configurations of ArcGIS Server versions 10.8.1 and 10.7...
CVE-2022-38199MEDIUM6.1A remote file download issue can occur in some capabilities of Esri ArcGIS Server web services that may in some edge cas...
CVE-2022-38198MEDIUM6.1There is a reflected cross site scripting issue in the Esri ArcGIS Server services directory versions 10.9.1 and below t...
CVE-2022-38197MEDIUM6.1Esri ArcGIS Server versions 10.9.1 and below have an unvalidated redirect issue that may allow a remote, unauthenticated...
CVE-2022-38195MEDIUM6.1There is as reflected cross site scripting issue in Esri ArcGIS Server versions 10.9.1 and below which may allow a remot...
CVE-2022-36783MEDIUM5.4AlgoSec – FireFlow Reflected Cross-Site-Scripting (RXSS) A malicious user injects JavaScript code into a parameter calle...
CVE-2022-35739MEDIUM5.3PRTG Network Monitor through 22.2.77.2204 does not prevent custom input for a device’s icon, which can be modified to in...
CVE-2022-34870MEDIUM5.4Apache Geode versions up to 1.15.0 are vulnerable to a Cross-Site Scripting (XSS) via data injection when using Pulse we...
CVE-2022-33757MEDIUM6.5An authenticated attacker could read Nessus Debug Log file attachments from the web UI without having the correct privil...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now