2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-38975MEDIUM5.4DOM-based cross-site scripting vulnerability in EC-CUBE 4 series (EC-CUBE 4.0.0 to 4.1.2) allows a remote attacker to in...
CVE-2022-38335MEDIUM5.4Vtiger CRM v7.4.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the e-mail template mo...
CVE-2022-37028MEDIUM5.4ISAMS 22.2.3.2 is prone to stored Cross-site Scripting (XSS) attack on the title field for groups, allowing an attacker ...
CVE-2022-23006MEDIUM6.7A stack-based buffer overflow vulnerability was found on Western Digital My Cloud Home, My Cloud Home Duo, and SanDisk i...
CVE-2022-30003MEDIUM5.4Sourcecodester Online Market Place Site 1.0 is vulnerable to Cross Site Scripting (XSS), allowing attackers to register ...
CVE-2022-40044MEDIUM5.4Centreon v20.10.18 was discovered to contain a cross-site scripting (XSS) vulnerability via the esc_name (Escalation Nam...
CVE-2022-3201MEDIUM5.4Insufficient validation of untrusted input in DevTools in Google Chrome on Chrome OS prior to 105.0.5195.125 allowed an ...
CVE-2022-3057MEDIUM6.5Inappropriate implementation in iframe Sandbox in Google Chrome prior to 105.0.5195.52 allowed a remote attacker to leak...
CVE-2022-3056MEDIUM6.5Insufficient policy enforcement in Content Security Policy in Google Chrome prior to 105.0.5195.52 allowed a remote atta...
CVE-2022-3054MEDIUM6.5Insufficient policy enforcement in DevTools in Google Chrome prior to 105.0.5195.52 allowed a remote attacker to potenti...
CVE-2022-3053MEDIUM4.3Inappropriate implementation in Pointer Lock in Google Chrome on Mac prior to 105.0.5195.52 allowed a remote attacker to...
CVE-2022-3048MEDIUM6.8Inappropriate implementation in Chrome OS lockscreen in Google Chrome on Chrome OS prior to 105.0.5195.52 allowed a loca...
CVE-2022-3047MEDIUM6.5Insufficient policy enforcement in Extensions API in Google Chrome prior to 105.0.5195.52 allowed an attacker who convin...
CVE-2022-3044MEDIUM6.5Inappropriate implementation in Site Isolation in Google Chrome prior to 105.0.5195.52 allowed a remote attacker who had...
CVE-2022-2861MEDIUM6.5Inappropriate implementation in Extensions API in Google Chrome prior to 104.0.5112.101 allowed an attacker who convince...
CVE-2022-2860MEDIUM6.5Insufficient policy enforcement in Cookies in Google Chrome prior to 104.0.5112.101 allowed a remote attacker to bypass ...
CVE-2022-2856MEDIUM6.5Insufficient validation of untrusted input in Intents in Google Chrome on Android prior to 104.0.5112.101 allowed a remo...
CVE-2022-39219MEDIUM6.5Bifrost is a middleware package which can synchronize MySQL/MariaDB binlog data to other types of databases. Versions 1....
CVE-2022-3299MEDIUM6.5A vulnerability was found in Open5GS up to 2.4.10. It has been declared as problematic. Affected by this vulnerability i...
CVE-2022-3135MEDIUM4.8The SEO Smart Links WordPress plugin through 3.0.1 does not sanitise and escape some of its settings, which could allow ...
CVE-2022-3098MEDIUM4.3The Login Block IPs WordPress plugin through 1.0.0 does not have CSRF check in place when updating its settings, which c...
CVE-2022-3074MEDIUM4.8The Slider Hero WordPress plugin before 8.4.4 does not escape the slider Name, which could allow high-privileged users t...
CVE-2022-3070MEDIUM4.8The Generate PDF WordPress plugin before 3.6 does not sanitise and escape its settings, allowing high privilege users su...
CVE-2022-3069MEDIUM4.8The WordLift WordPress plugin before 3.37.2 does not sanitise and escape its settings, allowing high privilege users suc...
CVE-2022-3062MEDIUM6.1The Simple File List WordPress plugin before 4.4.12 does not escape parameters before outputting them back in attributes...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now