2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-35945MEDIUM6.1GLPI stands for Gestionnaire Libre de Parc Informatique and is a Free Asset and IT Management Software package, that pro...
CVE-2022-31187MEDIUM5.4GLPI stands for Gestionnaire Libre de Parc Informatique and is a Free Asset and IT Management Software package, that pro...
CVE-2022-31143MEDIUM5.3GLPI stands for Gestionnaire Libre de Parc Informatique and is a Free Asset and IT Management Software package, that pro...
CVE-2022-1778MEDIUM4.4Improper Input Validation vulnerability in Hitachi Energy MicroSCADA X SYS600 while reading a specific configuration fil...
CVE-2022-0029MEDIUM5.5An improper link resolution vulnerability in the Palo Alto Networks Cortex XDR agent on Windows devices allows a local a...
CVE-2022-20231MEDIUM6.7In smc_intc_request_fiq of arm_gic.c, there is a possible out of bounds write due to improper input validation. This cou...
CVE-2022-38796MEDIUM6.1A Host Header Injection vulnerability in Feehi CMS 2.1.1 may allow an attacker to spoof a particular header. This can be...
CVE-2022-22520MEDIUM5.3A remote, unauthenticated attacker can enumerate valid users by sending specific requests to the webservice of MB connec...
CVE-2022-40626MEDIUM6.1An unauthenticated user can create a link with reflected Javascript code inside the backurl parameter and send it to oth...
CVE-2022-37139MEDIUM5.4Loan Management System version 1.0 suffers from a persistent cross site scripting vulnerability.
CVE-2022-37137MEDIUM5.4PayMoney 3.3 is vulnerable to Stored Cross-Site Scripting (XSS) during replying the ticket. The XSS can be obtain from i...
CVE-2022-36668MEDIUM5.4Garage Management System 1.0 is vulnerable to Stored Cross Site Scripting (XSS) on several parameters. The vulnerabiliti...
CVE-2022-38770MEDIUM5.3The mobile application in Transtek Mojodat FAM (Fixed Asset Management) 2.4.6 allows remote attackers to fetch other use...
CVE-2022-37191MEDIUM6.5The component "cuppa/api/index.php" of CuppaCMS v1.0 is Vulnerable to LFI. An authenticated user can read system files v...
CVE-2022-31861MEDIUM5.4Cross site Scripting (XSS) in ThingsBoard IoT Platform through 3.3.4.1 via a crafted value being sent to the audit logs.
CVE-2022-31324MEDIUM6.5An arbitrary file download vulnerability in the downloadAction() function of Penta Security Systems Inc WAPPLES v6.0 r3 ...
CVE-2022-39816MEDIUM6.5In NOKIA 1350 OMS R14.2, Insufficiently Protected Credentials (cleartext administrator password) occur in the edit confi...
CVE-2022-39814MEDIUM6.1In NOKIA 1350 OMS R14.2, an Open Redirect vulnerability occurs is the login page via next HTTP GET parameter.
CVE-2022-38497MEDIUM5.5LIEF commit 365a16a was discovered to contain a segmentation violation via the component CoreFile.tcc:69.
CVE-2022-38496MEDIUM5.5LIEF commit 365a16a was discovered to contain a reachable assertion abort via the component BinaryStream.hpp.
CVE-2022-38329MEDIUM4.3A CSRF vulnerability in Shopxian CMS 3.0.0 could allow an unauthenticated, remote attacker to craft a malicious link, po...
CVE-2022-38307MEDIUM5.5LIEF commit 5d1d643 was discovered to contain a segmentation violation via the function LIEF::MachO::SegmentCommand::fil...
CVE-2022-35637MEDIUM6.5IBM Db2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, 11.1, and 11.5 is vulnerable to a denial of service after entering ...
CVE-2022-34336MEDIUM5.4IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows...
CVE-2022-22483MEDIUM6.5IBM Db2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, 11.1, and 11.5 is vulnerable to an information disclosure in some s...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now