2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-39839MEDIUM4.8Cotonti Siena 0.9.20 allows admins to conduct stored XSS attacks via a forum post.
CVE-2022-39196MEDIUM6.5Blackboard Learn 1.10.1 allows remote authenticated users to read unintended files by entering student credentials and t...
CVE-2022-36647MEDIUM5.5PKUVCL davs2 v1.6.205 was discovered to contain a global buffer overflow via the function parse_sequence_header() at sou...
CVE-2022-36639MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in /client.php of Garage Management System v1.0 allows attackers to ex...
CVE-2022-36638MEDIUM5.3An access control issue in the component print.php of Garage Management System v1.0 allows unauthenticated attackers to ...
CVE-2022-35933MEDIUM6.1This package is a PrestaShop module that allows users to post reviews and rate products. There is a vulnerability where ...
CVE-2022-34378MEDIUM5.5Dell PowerScale OneFS, versions 9.0.0 up to and including 9.1.0.20, 9.2.1.13, 9.3.0.6, and 9.4.0.3, contain a relative p...
CVE-2022-22101MEDIUM5.5Denial of service in multimedia due to uncontrolled resource consumption while parsing an incoming HAB message in Snapdr...
CVE-2022-38170MEDIUM4.7In Apache Airflow prior to 2.3.4, an insecure umask was configured for numerous Airflow components when running with the...
CVE-2022-25370MEDIUM5.4Apache OFBiz uses the Birt plugin (https://eclipse.github.io/birt-website/) to create data visualizations and reports. I...
CVE-2022-39194MEDIUM4.9An issue was discovered in the MediaWiki through 1.38.2. The community configuration pages for the GrowthExperiments ext...
CVE-2022-39190MEDIUM5.5An issue was discovered in net/netfilter/nf_tables_api.c in the Linux kernel before 5.19.6. A denial of service can occu...
CVE-2022-39188MEDIUM4.7An issue was discovered in include/asm-generic/tlb.h in the Linux kernel before 5.19. Because of a race condition (unmap...
CVE-2022-37679MEDIUM4.8Miniblog.Core v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /blog/edit. Thi...
CVE-2022-36637MEDIUM5.4Garage Management System v1.0 was discovered to contain a persistent cross-site scripting (XSS) vulnerability via the br...
CVE-2022-36600MEDIUM4.8BlogEngine v3.3.8.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /blogengine/ap...
CVE-2022-36593MEDIUM6.5kkFileView v4.0.0 was discovered to contain an arbitrary file deletion vulnerability via the fileName parameter at /cont...
CVE-2022-3078MEDIUM5.5An issue was discovered in the Linux kernel through 5.16-rc6. There is a lack of check after calling vzalloc() and lack ...
CVE-2022-2806MEDIUM5.5It was found that the ovirt-log-collector/sosreport collects the RHV admin password unfiltered. Fixed in: sos-4.2-20.el8...
CVE-2022-2764MEDIUM4.9A flaw was found in Undertow. Denial of service can be achieved as Undertow server waits for the LAST_CHUNK forever for ...
CVE-2022-2739MEDIUM5.3The version of podman as released for Red Hat Enterprise Linux 7 Extras via RHSA-2022:2190 advisory included an incorrec...
CVE-2022-2663MEDIUM5.3An issue was found in the Linux kernel in nf_conntrack_irc where the message handling can be confused and incorrectly ma...
CVE-2022-2447MEDIUM6.6A flaw was found in Keystone. There is a time lag (up to one hour in a default configuration) between when security poli...
CVE-2022-2403MEDIUM6.5A credentials leak was found in the OpenShift Container Platform. The private key for the external cluster certificate w...
CVE-2022-2308MEDIUM6.5A flaw was found in vDPA with VDUSE backend. There are currently no checks in VDUSE kernel driver to ensure the size of ...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now