2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-38251MEDIUM4.8Nagios XI v5.8.6 was discovered to contain a cross-site scripting (XSS) vulnerability via the System Performance Setting...
CVE-2022-38249MEDIUM6.1Nagios XI v5.8.6 was discovered to contain a cross-site scripting (XSS) vulnerability via the MTR component in version 1...
CVE-2022-38248MEDIUM6.1Nagios XI before v5.8.7 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities at auditlog.php.
CVE-2022-38247MEDIUM4.8Nagios XI v5.8.6 was discovered to contain a cross-site scripting (XSS) vulnerability via the System Settings page under...
CVE-2022-36083MEDIUM5.3JOSE is "JSON Web Almost Everything" - JWA, JWS, JWE, JWT, JWK, JWKS with no dependencies using runtime's native crypto ...
CVE-2022-36082MEDIUM5.3mangadex-downloader is a command-line tool to download manga from MangaDex. When using `file:<location>` command and `<l...
CVE-2022-36080MEDIUM6.1Wikmd is a file based wiki that uses markdown. Prior to version 1.7.1, an attacker could capture user's session cookies ...
CVE-2022-30312MEDIUM6.5The Trend Controls IC protocol through 2022-05-06 allows Cleartext Transmission of Sensitive Information. According to F...
CVE-2022-36661MEDIUM6.5xhyve commit dfbe09b was discovered to contain a NULL pointer dereference via the component vi_pci_read(). This vulnerab...
CVE-2022-36659MEDIUM6.5xhyve commit dfbe09b was discovered to contain a NULL pointer dereference via the component vi_pci_write(). This vulnera...
CVE-2022-37731MEDIUM6.1ftcms 2.1 poster.PHP has a XSS vulnerability. The attacker inserts malicious JavaScript code into the web page, causing ...
CVE-2022-31167MEDIUM6.5XWiki Platform Security Parent POM contains the security APIs for XWiki Platform, a generic wiki platform. Starting with...
CVE-2022-31251MEDIUM6.3A Incorrect Default Permissions vulnerability in the packaging of the slurm testsuite of openSUSE Factory allows local a...
CVE-2022-21950MEDIUM5.3A Improper Access Control vulnerability in the systemd service of cana in openSUSE Backports SLE-15-SP3, openSUSE Backpo...
CVE-2022-38528MEDIUM6.5Open Asset Import Library (assimp) commit 3c253ca was discovered to contain a segmentation violation via the component A...
CVE-2022-35913MEDIUM4.3Samourai Wallet Stonewallx2 0.99.98e allows a denial of service via a P2P coinjoin. The attacker and victim must follow ...
CVE-2022-1522MEDIUM5.3The Cognex 3D-A1000 Dimensioning System in firmware version 1.0.3 (3354) and prior is vulnerable to CWE-117: Improper Ou...
CVE-2022-36072MEDIUM5.9SilverwareGames.io is a social network for users to play video games online. In version 1.1.8 and prior, due to an unobv...
CVE-2022-37253MEDIUM5.4Persistent cross-site scripting (XSS) in Crime Reporting System 1.0 allows a remote attacker to introduce arbitary Javas...
CVE-2022-36057MEDIUM4.8Discourse-Chat is an asynchronous messaging plugin for the Discourse open-source discussion platform. Users of Discourse...
CVE-2022-32277MEDIUM5.3Squiz Matrix CMS 6.20 is vulnerable to an Insecure Direct Object Reference caused by failure to correctly validate autho...
CVE-2022-37771MEDIUM6.7IObit Malware Fighter v9.2 for Microsoft Windows lacks tamper protection, allowing authenticated attackers with Administ...
CVE-2022-36670MEDIUM6.7PCProtect Endpoint prior to v5.17.470 for Microsoft Windows lacks tamper protection, allowing authenticated attackers wi...
CVE-2022-36032MEDIUM5.3ReactPHP HTTP is a streaming HTTP client and server implementation for ReactPHP. In ReactPHP's HTTP server component ver...
CVE-2022-31792MEDIUM5.4A stored cross-site scripting (XSS) vulnerability exists in the management web interface of WatchGuard Firebox and XTM a...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now