2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-36116MEDIUM5.3An issue was discovered in Blue Prism Enterprise 6.0 through 7.01. In a misconfigured environment that exposes the Blue ...
CVE-2022-31798MEDIUM6.1Nortek Linear eMerge E3-Series 0.32-07p devices are vulnerable to /card_scan.php?CardFormatNo= XSS with session fixation...
CVE-2022-2980MEDIUM5.5NULL Pointer Dereference in GitHub repository vim/vim prior to 9.0.0259.
CVE-2022-36527MEDIUM5.4Jfinal CMS v5.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the post...
CVE-2022-20865MEDIUM6.7A vulnerability in the CLI of Cisco FXOS Software could allow an authenticated, local attacker to inject arbitrary comma...
CVE-2022-37953MEDIUM6.1An HTTP response splitting vulnerability exists in the AM Gateway Challenge-Response dialog of WorkstationST (<v07.09.15...
CVE-2022-37952MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability exists in the iHistorian Data Display of WorkstationST (<v07.09.15)...
CVE-2022-36358MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in SEO Scout plugin <= 0.9.83 at WordPress allows attackers to trick use...
CVE-2022-32746MEDIUM5.4A flaw was found in the Samba AD LDAP server. The AD DC database audit logging module can access LDAP message values fre...
CVE-2022-32742MEDIUM4.3A flaw was found in Samba. Some SMB1 write requests were not correctly range-checked to ensure the client had sent enoug...
CVE-2022-2991MEDIUM6.7A heap-based buffer overflow was found in the Linux kernel's LightNVM subsystem. The issue results from the lack of prop...
CVE-2022-23715MEDIUM6.5A flaw was discovered in ECE before 3.4.0 that might lead to the disclosure of sensitive information such as user passwo...
CVE-2022-23235MEDIUM5.3Active IQ Unified Manager for VMware vSphere, Linux, and Microsoft Windows versions prior to 9.10P1 are susceptible to a...
CVE-2022-37162MEDIUM5.4Claroline 13.5.7 and prior is vulnerable to Cross Site Scripting (XSS). An attacker can obtain javascript code execution...
CVE-2022-37161MEDIUM6.1Claroline 13.5.7 and prior is vulnerable to Cross Site Scripting (XSS) via SVG file upload.
CVE-2022-37160MEDIUM5.4Claroline 13.5.7 and prior allows an authenticated attacker to elevate privileges via the arbitrary creation of a privil...
CVE-2022-37292MEDIUM5.5Tenda AX12 V22.03.01.21_CN is vulnerable to Buffer Overflow. This overflow is triggered in the sub_42FDE4 function, whic...
CVE-2022-37238MEDIUM5.4MDaemon Technologies SecurityGateway for Email Servers 8.5.2 is vulnerable to Cross Site Scripting (XSS) via the current...
CVE-2022-37245MEDIUM5.4MDaemon Technologies SecurityGateway for Email Servers 8.5.2 is vulnerable to Cross Site Scripting (XSS) via the Blackli...
CVE-2022-37244MEDIUM5.4MDaemon Technologies SecurityGateway for Email Servers 8.5.2 is vulnerable to IFRAME Injectionvia the currentRequest par...
CVE-2022-37243MEDIUM5.4MDaemon Technologies SecurityGateway for Email Servers 8.5.2 is vulnerable to Cross Site Scripting (XSS) via the whiteli...
CVE-2022-37241MEDIUM5.4MDaemon Technologies SecurityGateway for Email Servers 8.5.2 is vulnerable to Cross Site Scripting (XSS) via the data_le...
CVE-2022-37239MEDIUM5.4MDaemon Technologies SecurityGateway for Email Servers 8.5.2 is vulnerable to Cross Site Scripting (XSS) via the rulles_...
CVE-2022-32857MEDIUM4.3This issue was addressed by using HTTPS when sending information over the network. This issue is fixed in macOS Monterey...
CVE-2022-32838MEDIUM5.5A logic issue was addressed with improved state management. This issue is fixed in macOS Monterey 12.5, macOS Big Sur 11...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now