2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-2448MEDIUM4.8The reSmush.it WordPress plugin before 0.4.6 does not sanitise and escape some of its settings, which could allow high p...
CVE-2022-2350MEDIUM5.3The Disable User Login WordPress plugin through 1.0.1 does not have authorisation and CSRF checks when updating its sett...
CVE-2022-20944MEDIUM6.8A vulnerability in the software image verification functionality of Cisco IOS XE Software for Cisco Catalyst 9200 Series...
CVE-2022-20864MEDIUM4.6A vulnerability in the password-recovery disable feature of Cisco IOS XE ROM Monitor (ROMMON) Software for Cisco Catalys...
CVE-2022-20830MEDIUM5.3A vulnerability in authentication mechanism of Cisco Software-Defined Application Visibility and Control (SD-AVC) on Cis...
CVE-2022-40257MEDIUM5.4An HTML injection vulnerability exists in CERT/CC VINCE software prior to 1.50.4. An authenticated attacker can inject a...
CVE-2022-40248MEDIUM5.4An HTML injection vulnerability exists in CERT/CC VINCE software prior to 1.50.4. An authenticated attacker can inject a...
CVE-2022-3442MEDIUM6.1A vulnerability was found in Crealogix EBICS 7.0. It has been rated as problematic. Affected by this issue is some unkno...
CVE-2022-26121MEDIUM5.3An exposure of resource to wrong sphere vulnerability [CWE-668] in FortiAnalyzer and FortiManager GUI 7.0.0 through 7.0....
CVE-2022-3438MEDIUM6.1Open Redirect in GitHub repository ikus060/rdiffweb prior to 2.5.0a4.
CVE-2022-42724MEDIUM4.3app/Controller/UsersController.php in MISP before 2.4.164 allows attackers to discover role names (this is information t...
CVE-2022-42012MEDIUM6.5An issue was discovered in D-Bus before 1.12.24, 1.13.x and 1.14.x before 1.14.4, and 1.15.x before 1.15.2. An authentic...
CVE-2022-42011MEDIUM6.5An issue was discovered in D-Bus before 1.12.24, 1.13.x and 1.14.x before 1.14.4, and 1.15.x before 1.15.2. An authentic...
CVE-2022-42010MEDIUM6.5An issue was discovered in D-Bus before 1.12.24, 1.13.x and 1.14.x before 1.14.4, and 1.15.x before 1.15.2. An authentic...
CVE-2022-42703MEDIUM5.5mm/rmap.c in the Linux kernel before 5.19.7 has a use-after-free related to leaf anon_vma double reuse.
CVE-2022-3435MEDIUM4.3A vulnerability classified as problematic has been found in Linux Kernel. This affects the function fib_nh_match of the ...
CVE-2022-3434MEDIUM5.4A vulnerability was found in SourceCodester Web-Based Student Clearance System. It has been rated as problematic. Affect...
CVE-2022-39281MEDIUM6.5fat_free_crm is a an open source, Ruby on Rails customer relationship management platform (CRM). In versions prior to 0....
CVE-2022-41442MEDIUM6.1PicUploader v2.6.3 was discovered to contain cross-site scripting (XSS) vulnerability via the setStorageParams function ...
CVE-2022-39291MEDIUM5.4ZoneMinder is a free, open source Closed-circuit television software application. Affected versions of zoneminder are su...
CVE-2022-39290MEDIUM6.5ZoneMinder is a free, open source Closed-circuit television software application. In affected versions authenticated use...
CVE-2022-39285MEDIUM5.4ZoneMinder is a free, open source Closed-circuit television software application The file parameter is vulnerable to a c...
CVE-2022-31681MEDIUM6.5VMware ESXi contains a null-pointer deference vulnerability. A malicious actor with privileges within the VMX process on...
CVE-2022-39287MEDIUM6.5tiny-csrf is a Node.js cross site request forgery (CSRF) protection middleware. In versions prior to 1.1.0 cookies were ...
CVE-2022-32593MEDIUM6.7In vowe, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of p...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now