2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-30672MEDIUM5.5Adobe InDesign versions 16.4.2 (and earlier) and 17.3 (and earlier) are affected by an out-of-bounds read vulnerability ...
CVE-2022-30671MEDIUM5.5Adobe InDesign versions 16.4.2 (and earlier) and 17.3 (and earlier) are affected by an out-of-bounds read vulnerability ...
CVE-2022-28857MEDIUM5.5Adobe InDesign versions 16.4.2 (and earlier) and 17.3 (and earlier) are affected by an out-of-bounds read vulnerability ...
CVE-2022-28856MEDIUM5.5Adobe InDesign versions 16.4.2 (and earlier) and 17.3 (and earlier) are affected by an out-of-bounds read vulnerability ...
CVE-2022-28855MEDIUM5.5Adobe InDesign versions 16.4.2 (and earlier) and 17.3 (and earlier) are affected by an out-of-bounds read vulnerability ...
CVE-2022-28854MEDIUM5.5Adobe InDesign versions 16.4.2 (and earlier) and 17.3 (and earlier) are affected by an out-of-bounds read vulnerability ...
CVE-2022-3225MEDIUM5.7Improper Control of Dynamically-Managed Code Resources in GitHub repository budibase/budibase prior to 1.3.20.
CVE-2022-38410MEDIUM5.5Adobe Illustrator versions 26.4 (and earlier) and 25.4.7 (and earlier) are affected by an out-of-bounds read vulnerabili...
CVE-2022-38409MEDIUM5.5Adobe Illustrator versions 26.4 (and earlier) and 25.4.7 (and earlier) are affected by an out-of-bounds read vulnerabili...
CVE-2022-37775MEDIUM6.1Genesys PureConnect Interaction Web Tools Chat Service (up to at least 26- September- 2019) allows XSS within the Printa...
CVE-2022-36402MEDIUM5.5An integer overflow vulnerability was found in vmwgfx driver in drivers/gpu/vmxgfx/vmxgfx_execbuf.c in GPU component of ...
CVE-2022-37248MEDIUM5.4Craft CMS 4.2.0.1 is vulnerable to Cross Site Scripting (XSS) via src/helpers/Cp.php.
CVE-2022-37250MEDIUM5.4Craft CMS 4.2.0.1 suffers from Stored Cross Site Scripting (XSS) in /admin/myaccount.
CVE-2022-38846MEDIUM5.9EspoCRM version 7.1.8 is vulnerable to Missing Secure Flag allowing the browser to send plain text cookies over an insec...
CVE-2022-38845MEDIUM6.1Cross Site Scripting in Import feature in EspoCRM 7.1.8 allows remote users to run malicious JavaScript in victim s brow...
CVE-2022-3223MEDIUM6.1Cross-site Scripting (XSS) - Stored in GitHub repository jgraph/drawio prior to 20.3.1.
CVE-2022-2913MEDIUM4.3The Login No Captcha reCAPTCHA WordPress plugin before 1.7 doesn't check the proper IP address allowing attackers to spo...
CVE-2022-2912MEDIUM4.3The Craw Data WordPress plugin through 1.0.0 does not implement nonce checks, which could allow attackers to make a logg...
CVE-2022-2887MEDIUM4.8The WP Server Health Stats WordPress plugin before 1.7.0 does not escape some of its settings, which could allow high pr...
CVE-2022-2877MEDIUM5.3The Titan Anti-spam & Security WordPress plugin before 7.3.1 does not properly checks HTTP headers in order to validate ...
CVE-2022-2863MEDIUM4.9The Migration, Backup, Staging WordPress plugin before 0.9.76 does not sanitise and validate a parameter before using it...
CVE-2022-2799MEDIUM4.8The Affiliates Manager WordPress plugin before 2.9.14 does not sanitise and escape some of its settings, which could all...
CVE-2022-2737MEDIUM4.8The WP STAGING WordPress plugin before 2.9.18 does not sanitise and escape some of its settings, which could allow high ...
CVE-2022-2669MEDIUM6.1The WP Taxonomy Import WordPress plugin through 1.0.4 does not sanitise and escape a parameter before outputting it back...
CVE-2022-2655MEDIUM6.1The Classified Listing Pro WordPress plugin before 2.0.20 does not escape a generated URL before outputting it back in a...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now