2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-40444MEDIUM5.3ZZCMS 2022 was discovered to contain a full path disclosure vulnerability via the page /admin/index.PHP? _server.
CVE-2022-40443MEDIUM5.3An absolute path traversal vulnerability in ZZCMS 2022 allows attackers to obtain sensitive information via a crafted GE...
CVE-2022-3267MEDIUM4.3Cross-Site Request Forgery (CSRF) in GitHub repository ikus060/rdiffweb prior to 2.4.6.
CVE-2022-2266MEDIUM6.1University Library Automation System developed by Yordam Bilgi Teknolojileri before version 19.2 has an unauthenticated ...
CVE-2022-39197MEDIUM6.1An XSS (Cross Site Scripting) vulnerability was found in HelpSystems Cobalt Strike through 4.7 that allowed a remote att...
CVE-2022-38512MEDIUM6.5The Translation module in Liferay Portal v7.4.3.12 through v7.4.3.36, and Liferay DXP 7.4 update 8 through 36 does not c...
CVE-2022-28980MEDIUM6.1Multiple cross-site scripting (XSS) vulnerabilities in Liferay Portal v7.4.3.4 and Liferay DXP v7.4 GA allows attackers ...
CVE-2022-28977MEDIUM6.1HtmlUtil.escapeRedirect in Liferay Portal 7.3.1 through 7.4.2, and Liferay DXP 7.0 fix pack 91 through 101, 7.1 fix pack...
CVE-2022-39975MEDIUM4.3The Layout module in Liferay Portal v7.3.3 through v7.4.3.34, and Liferay DXP 7.3 before update 10, and 7.4 before updat...
CVE-2022-35896MEDIUM6An issue SMM memory leak vulnerability in SMM driver (SMRAM was discovered in Insyde InsydeH2O with kernel 5.0 through 5...
CVE-2022-28982MEDIUM6.1A cross-site scripting (XSS) vulnerability in Liferay Portal v7.3.3 through v7.4.2 and Liferay DXP v7.3 before service p...
CVE-2022-28979MEDIUM6.1Liferay Portal v7.1.0 through v7.4.2 and Liferay DXP 7.1 before fix pack 26, 7.2 before fix pack 15, and 7.3 before serv...
CVE-2022-28978MEDIUM5.4Stored cross-site scripting (XSS) vulnerability in the Site module's user membership administration page in Liferay Port...
CVE-2022-3233MEDIUM4.3Cross-Site Request Forgery (CSRF) in GitHub repository ikus060/rdiffweb prior to 2.4.6.
CVE-2022-38073MEDIUM5.4Multiple Authenticated (custom specific plugin role) Persistent Cross-Site Scripting (XSS) vulnerability in Awesome Supp...
CVE-2022-36390MEDIUM5.4Authenticated (subscriber+) Reflected Cross-Site Scripting (XSS) vulnerability in Totalsoft Event Calendar – Calendar pl...
CVE-2022-36383MEDIUM5.4Multiple Authenticated (contributor+) Stored Cross-Site Scripting (XSS) vulnerabilities in WHA Word Search Puzzles game ...
CVE-2022-36365MEDIUM5.4Multiple Authenticated (contributor+) Stored Cross-Site Scripting (XSS) vulnerabilities in WHA Crossword plugin <= 1.1.1...
CVE-2022-40219MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in SedLex FavIcon Switcher plugin <= 1.2.11 at WordPress allows plugin s...
CVE-2022-35621MEDIUM5.3Access control vulnerability in Evoh NFT EvohClaimable contract with sha256 hash code fa2084d5abca91a62ed1d2f1cad3ec318e...
CVE-2022-29800MEDIUM4.7A time-of-check-time-of-use (TOCTOU) race condition vulnerability was found in networkd-dispatcher. This flaw exists bec...
CVE-2022-29799MEDIUM5.5A vulnerability was found in networkd-dispatcher. This flaw exists because no functions are sanitized by the Operational...
CVE-2022-23951MEDIUM5.5In Keylime before 6.3.0, quote responses from the agent can contain possibly untrusted ZIP data which can lead to zip bo...
CVE-2022-40029MEDIUM4.8SourceCodester Simple Task Managing System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via...
CVE-2022-40028MEDIUM4.8SourceCodester Simple Task Managing System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now