2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-23689MEDIUM4.3Multiple vulnerabilities exist in the processing of packet data by the LLDP service of AOS-CX. Successful exploitation o...
CVE-2022-23688MEDIUM4.3Multiple vulnerabilities exist in the processing of packet data by the LLDP service of AOS-CX. Successful exploitation o...
CVE-2022-23687MEDIUM4.3Multiple vulnerabilities exist in the processing of packet data by the LLDP service of AOS-CX. Successful exploitation o...
CVE-2022-23686MEDIUM4.3Multiple vulnerabilities exist in the processing of packet data by the LLDP service of AOS-CX. Successful exploitation o...
CVE-2022-23678MEDIUM5.9A vulnerability in the Aruba Virtual Intranet Access (VIA) client for Microsoft Windows operating system client communic...
CVE-2022-1628MEDIUM5.4The Simple SEO plugin for WordPress is vulnerable to attribute-based stored Cross-Site Scripting in versions up to, and ...
CVE-2022-26114MEDIUM6.1An improper neutralization of input during web page generation vulnerability [CWE-79] in the Webmail of FortiMail before...
CVE-2022-34882MEDIUM6.5Information Exposure Through an Error Message vulnerability in Hitachi RAID Manager Storage Replication Adapter allows r...
CVE-2022-38367MEDIUM5.3The Netic User Export add-on before 2.0.6 for Atlassian Jira does not perform authorization checks. This might allow an ...
CVE-2022-3127MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository jgraph/drawio prior to 20.2.8.
CVE-2022-2775MEDIUM5.5The Fast Flow WordPress plugin before 1.2.13 does not sanitise and escape some of its Widget settings, which could allow...
CVE-2022-2657MEDIUM4.3The Multivendor Marketplace Solution for WooCommerce WordPress plugin before 3.8.12 is lacking authorisation and CSRF in...
CVE-2022-2597MEDIUM5.4The Visual Portfolio, Photo Gallery & Post Grid WordPress plugin before 2.19.0 does not have proper authorisation checks...
CVE-2022-2543MEDIUM6.1The Visual Portfolio, Photo Gallery & Post Grid WordPress plugin before 2.18.0 does not have proper authorisation checks...
CVE-2022-2376MEDIUM5.3The Directorist WordPress plugin before 7.3.1 discloses the email address of all users in an AJAX action available to bo...
CVE-2022-2271MEDIUM4.8The WP Database Backup WordPress plugin before 5.9 does not escape some of its settings, which could allow high privileg...
CVE-2022-3123MEDIUM6.1Cross-site Scripting (XSS) - Reflected in GitHub repository splitbrain/dokuwiki prior to 2022-07-31a.
CVE-2022-38752MEDIUM6.5Using snakeYAML to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is run...
CVE-2022-38751MEDIUM6.5Using snakeYAML to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is run...
CVE-2022-38750MEDIUM5.5Using snakeYAML to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is run...
CVE-2022-38749MEDIUM6.5Using snakeYAML to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is run...
CVE-2022-39842MEDIUM6.1An issue was discovered in the Linux kernel before 5.19. In pxa3xx_gcu_write in drivers/video/fbdev/pxa3xx-gcu.c, the co...
CVE-2022-39050MEDIUM4.8An attacker who is logged into OTRS as an admin user may manipulate customer URL field to store JavaScript code to be ru...
CVE-2022-39049MEDIUM4.8An attacker who is logged into OTRS as an admin user may manipulate the URL to cause execution of JavaScript in the cont...
CVE-2022-39840MEDIUM4.8Cotonti Siena 0.9.20 allows admins to conduct stored XSS attacks via a direct message (DM).

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now