2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-37796MEDIUM5.4In Simple Online Book Store System 1.0 in /admin_book.php the Title, Author, and Description parameters are vulnerable t...
CVE-2022-40325MEDIUM6.1SysAid Help Desk before 22.1.65 allows XSS via the Asset Dashboard, aka FR# 67262.
CVE-2022-40324MEDIUM6.1SysAid Help Desk before 22.1.65 allows XSS via the Linked SRs field, aka FR# 67258.
CVE-2022-40323MEDIUM6.1SysAid Help Desk before 22.1.65 allows XSS in the Password Services module, aka FR# 67241.
CVE-2022-40322MEDIUM6.1SysAid Help Desk before 22.1.65 allows XSS, aka FR# 66542 and 65579.
CVE-2022-25295MEDIUM5.4This affects the package github.com/gophish/gophish before 0.12.0. The Open Redirect vulnerability exists in the next qu...
CVE-2022-38266MEDIUM6.5An issue in the Leptonica linked library (v1.79.0) allows attackers to cause an arithmetic exception leading to a Denial...
CVE-2022-36087MEDIUM6.5OAuthLib is an implementation of the OAuth request-signing logic for Python 3.6+. In OAuthLib versions 3.1.1 until 3.2.1...
CVE-2022-38639MEDIUM5.4A cross-site scripting (XSS) vulnerability in Markdown-Nice v1.8.22 allows attackers to execute arbitrary web scripts or...
CVE-2022-36109MEDIUM6.3Moby is an open-source project created by Docker to enable software containerization. A bug was found in Moby (Docker En...
CVE-2022-40317MEDIUM5.4OpenKM 6.3.11 allows stored XSS related to the javascript: substring in an A element.
CVE-2022-39810MEDIUM6.1An issue was discovered in WSO2 Enterprise Integrator 6.4.0. A Reflected Cross-Site Scripting (XSS) vulnerability has be...
CVE-2022-39809MEDIUM6.1An issue was discovered in WSO2 Enterprise Integrator 6.4.0. A Reflected Cross-Site Scripting (XSS) vulnerability has be...
CVE-2022-38613MEDIUM6.5A Path Traversal vulnerability in SmartVista Cardgen v3.28.0 allows authenticated attackers to read arbitrary files in t...
CVE-2022-36617MEDIUM4.9Arq Backup 7.19.5.0 and below stores backup encryption passwords using reversible encryption. This issue allows attacker...
CVE-2022-34165MEDIUM5.4IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 and IBM WebSphere Application Server Liberty 17.0.0.3 through 22...
CVE-2022-40191MEDIUM5.4Authenticated (subscriber+) Stored Cross-Site Scripting (XSS) vulnerability in Ali Khallad's Contact Form By Mega Forms ...
CVE-2022-40133MEDIUM5.5A use-after-free(UAF) vulnerability was found in function 'vmw_execbuf_tie_context' in drivers/gpu/vmxgfx/vmxgfx_execbuf...
CVE-2022-3169MEDIUM5.5A flaw was found in the Linux kernel. A denial of service flaw may occur if there is a consecutive request of the NVME_I...
CVE-2022-3147MEDIUM6.5Mattermost version 7.0.x and earlier fails to sufficiently limit the in-memory sizes of concurrently uploaded JPEG image...
CVE-2022-3077MEDIUM5.5A buffer overflow vulnerability was found in the Linux kernel Intel’s iSMT SMBus host controller driver in the way it ha...
CVE-2022-38457MEDIUM5.5A use-after-free(UAF) vulnerability was found in function 'vmw_cmd_res_check' in drivers/gpu/vmxgfx/vmxgfx_execbuf.c in ...
CVE-2022-38096MEDIUM5.5A NULL pointer dereference vulnerability was found in vmwgfx driver in drivers/gpu/vmxgfx/vmxgfx_execbuf.c in GPU compon...
CVE-2022-38081MEDIUM5.5OpenHarmony-v3.1.2 and prior versions have a permission bypass vulnerability. LAN attackers can bypass the distributed p...
CVE-2022-38068MEDIUM4.8Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Apasionados Export Post Info plugin <= 1.1.0 a...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now