2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-2330MEDIUM6.5Improper Restriction of XML External Entity Reference vulnerability in DLP Endpoint for Windows prior to 11.9.100 allows...
CVE-2022-26529MEDIUM6.5Realtek Linux/Android Bluetooth Mesh SDK has a buffer overflow vulnerability due to insufficient validation for segmente...
CVE-2022-26528MEDIUM6.5Realtek Linux/Android Bluetooth Mesh SDK has a buffer overflow vulnerability due to insufficient validation for the leng...
CVE-2022-26527MEDIUM6.5Realtek Linux/Android Bluetooth Mesh SDK has a buffer overflow vulnerability due to insufficient validation for the size...
CVE-2022-25646MEDIUM6.1All versions of package x-data-spreadsheet are vulnerable to Cross-site Scripting (XSS) due to missing sanitization of v...
CVE-2022-25635MEDIUM6.5Realtek Linux/Android Bluetooth Mesh SDK has a buffer overflow vulnerability due to insufficient validation for broadcas...
CVE-2022-21385MEDIUM6.2A flaw in net_rds_alloc_sgs() in Oracle Linux kernels allows unprivileged local users to crash the machine. CVSS 3.1 Bas...
CVE-2022-3035MEDIUM4.8Cross-site Scripting (XSS) - Stored in GitHub repository snipe/snipe-it prior to v6.0.11.
CVE-2022-36037MEDIUM5.4kirby is a content management system (CMS) that adapts to many different projects and helps you build your own ideal int...
CVE-2022-2638MEDIUM6.5The Export All URLs WordPress plugin before 4.4 does not validate the path of the file to be removed on the system which...
CVE-2022-2599MEDIUM6.1The Anti-Malware Security and Brute-Force Firewall WordPress plugin before 4.21.83 does not sanitise and escape some par...
CVE-2022-2538MEDIUM6.1The WP Hide & Security Enhancer WordPress plugin before 1.8 does not escape a parameter before outputting it back in an ...
CVE-2022-2537MEDIUM6.1The WooCommerce PDF Invoices & Packing Slips WordPress plugin before 3.0.1 does not sanitise and escape some parameters ...
CVE-2022-2374MEDIUM4.8The Simply Schedule Appointments WordPress plugin before 1.5.7.7 does not sanitise and escape some of its settings, whic...
CVE-2022-2373MEDIUM5.3The Simply Schedule Appointments WordPress plugin before 1.5.7.7 is missing authorisation in a REST endpoint, allowing u...
CVE-2022-2267MEDIUM4.3The Mailchimp for WooCommerce WordPress plugin before 2.7.1 has an AJAX action that allows any logged in users (such as ...
CVE-2022-2080MEDIUM4.3The Sensei LMS WordPress plugin before 4.5.2 does not ensure that the sender of a private message is either the teacher ...
CVE-2022-2034MEDIUM5.3The Sensei LMS WordPress plugin before 4.5.0 does not have proper permissions set in one of its REST endpoint, allowing ...
CVE-2022-1663MEDIUM6.5The Stop Spam Comments WordPress plugin through 0.2.1.2 does not properly generate the Javascript access token for preve...
CVE-2022-36033MEDIUM6.1jsoup is a Java HTML parser, built for HTML editing, cleaning, scraping, and cross-site scripting (XSS) safety. jsoup ma...
CVE-2022-27546MEDIUM6.1HCL iNotes is susceptible to a Reflected Cross-site Scripting (XSS) vulnerability caused by improper validation of user-...
CVE-2022-35962MEDIUM5.7Zulip is an open source team chat and Zulip Mobile is an app for iOS and Andriod users. In Zulip Mobile through version ...
CVE-2022-31677MEDIUM5.4An Insufficient Session Expiration issue was discovered in the Pinniped Supervisor (before v0.19.0). A user authenticati...
CVE-2022-2953MEDIUM5.5LibTIFF 4.4.0 has an out-of-bounds read in extractImageSection in tools/tiffcrop.c:6905, allowing attackers to cause a d...
CVE-2022-1204MEDIUM5.5A use-after-free flaw was found in the Linux kernel’s Amateur Radio AX.25 protocol functionality in the way a user conne...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now