2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-32834MEDIUM5.5An access issue was addressed with improvements to the sandbox. This issue is fixed in macOS Monterey 12.5, macOS Big Su...
CVE-2022-34837MEDIUM6.1Storing Passwords in a Recoverable Format vulnerability in ABB Zenon 8.20 allows an attacker who successfully exploit th...
CVE-2022-2569MEDIUM5.5The affected device stores sensitive information in cleartext, which may allow an authenticated user to access session d...
CVE-2022-37153MEDIUM6.1An issue was discovered in Artica Proxy 4.30.000000. There is a XSS vulnerability via the password parameter in /fw.logi...
CVE-2022-33172MEDIUM5.5de.fac2 1.34 allows bypassing the User Presence protection mechanism when there is malware on the victim's PC.
CVE-2022-38089MEDIUM5.4Stored cross-site scripting vulnerability in Exment ((PHP8) exceedone/exment v5.0.2 and earlier and exceedone/laravel-ad...
CVE-2022-38080MEDIUM5.4Reflected cross-site scripting vulnerability in Exment ((PHP8) exceedone/exment v5.0.2 and earlier and exceedone/laravel...
CVE-2022-37418MEDIUM6.4The Remote Keyless Entry (RKE) receiving unit on certain Nissan, Kia, and Hyundai vehicles through 2017 allows remote at...
CVE-2022-37305MEDIUM6.4The Remote Keyless Entry (RKE) receiving unit on certain Honda vehicles through 2018 allows remote attackers to perform ...
CVE-2022-36945MEDIUM6.4The Remote Keyless Entry (RKE) receiving unit on certain Mazda vehicles through 2020 allows remote attackers to perform ...
CVE-2022-38463MEDIUM6.1ServiceNow through San Diego Patch 4b and Patch 6 allows reflected XSS in the logout functionality.
CVE-2022-38172MEDIUM6.1ServiceNow through San Diego Patch 3 allows XSS via the name field during creation of a new dashboard for the Performanc...
CVE-2022-38665MEDIUM6.5Jenkins CollabNet Plugins Plugin 2.0.8 and earlier stores a RabbitMQ password unencrypted in its global configuration fi...
CVE-2022-38664MEDIUM5.4Jenkins Job Configuration History Plugin 1165.v8cc9fd1f4597 and earlier does not escape the job name on the System Confi...
CVE-2022-38663MEDIUM6.5Jenkins Git Plugin 4.11.4 and earlier does not properly mask (i.e., replace with asterisks) credentials in the build log...
CVE-2022-37428MEDIUM6.5PowerDNS Recursor up to and including 4.5.9, 4.6.2 and 4.7.1, when protobuf logging is enabled, has Improper Cleanup upo...
CVE-2022-36405MEDIUM5.4Authenticated (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in amCharts: Charts and Maps plugin <= 1.4 ...
CVE-2022-36347MEDIUM5.4Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Alpine Press Alpine PhotoTile for Pinterest pl...
CVE-2022-36341MEDIUM5.4Authenticated (subscriber+) plugin settings change leading to Stored Cross-Site Scripting (XSS) vulnerability in Akash s...
CVE-2022-36282MEDIUM5.4Authenticated (editor+) Stored Cross-Site Scripting (XSS) vulnerability in Roman Pronskiy's Search Exclude plugin <= 1.2...
CVE-2022-35242MEDIUM5.3Unauthenticated plugin settings change vulnerability in 59sec THE Leads Management System: 59sec LITE plugin <= 3.4.1 at...
CVE-2022-35235MEDIUM4.9Authenticated (admin+) Arbitrary File Read vulnerability in XplodedThemes WPide plugin <= 2.6 at WordPress.
CVE-2022-34868MEDIUM6.5Authenticated Arbitrary Settings Update vulnerability in YooMoney ЮKassa для WooCommerce plugin <= 2.3.0 at WordPress.
CVE-2022-34658MEDIUM5.4Multiple Authenticated (contributor+) Persistent Cross-Site Scripting (XSS) vulnerabilities in W3 Eden Download Manager ...
CVE-2022-34648MEDIUM5.4Authenticated (author+) Stored Cross-Site Scripting (XSS) vulnerability in dmitrylitvinov Uploading SVG, WEBP and ICO fi...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now