2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-1932 | MEDIUM | 6.1 | 0.5% | Aug 22, 2022 | The Rezgo Online Booking WordPress plugin before 4.1.8 does not sanitise and escape some parameters before outputting th... |
| CVE-2022-1322 | MEDIUM | 4.8 | 0.5% | Aug 22, 2022 | The Coming Soon - Under Construction WordPress plugin through 1.1.9 does not sanitize and escape some of its settings, w... |
| CVE-2022-1251 | MEDIUM | 4.3 | 0.3% | Aug 22, 2022 | The Ask me WordPress theme before 6.8.4 does not perform nonce checks when processing POST requests to the Edit Profile ... |
| CVE-2022-0446 | MEDIUM | 4.8 | 0.4% | Aug 22, 2022 | The Simple Banner WordPress plugin before 2.12.0 does not properly sanitize its "Simple Banner Text" Settings allowing h... |
| CVE-2022-2932 | MEDIUM | 6.1 | 0.7% | Aug 22, 2022 | Cross-site Scripting (XSS) - Reflected in GitHub repository bustle/mobiledoc-kit prior to 0.14.2. |
| CVE-2022-2890 | MEDIUM | 5.4 | 0.7% | Aug 22, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0. |
| CVE-2022-1340 | MEDIUM | 5.4 | 0.4% | Aug 22, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0. |
| CVE-2022-36251 | MEDIUM | 6.1 | 0.5% | Aug 22, 2022 | Clinic's Patient Management System v1.0 is vulnerable to Cross Site Scripting (XSS) via patients.php. |
| CVE-2022-2885 | MEDIUM | 4.8 | 0.4% | Aug 21, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0. |
| CVE-2022-35692 | MEDIUM | 5.3 | 0.7% | Aug 19, 2022 | Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by an Improp... |
| CVE-2022-35554 | MEDIUM | 6.1 | 0.6% | Aug 19, 2022 | Multiple reflected XSS vulnerabilities occur when handling error message of BPC SmartVista version 3.28.0 allowing an at... |
| CVE-2022-2790 | MEDIUM | 5.9 | 0.1% | Aug 19, 2022 | Emerson Electric's Proficy Machine Edition Version 9.00 and prior is vulenrable to CWE-347 Improper Verification of Cryp... |
| CVE-2022-2789 | MEDIUM | 5.5 | 0.1% | Aug 19, 2022 | Emerson Electric's Proficy Machine Edition Version 9.00 and prior is vulnerable to CWE-345 Insufficient Verification of ... |
| CVE-2022-36233 | MEDIUM | 5.5 | 0.3% | Aug 19, 2022 | Tenda AC9 V15.03.2.13 is vulnerable to Buffer Overflow via httpd, form_fast_setting_wifi_set. httpd. |
| CVE-2022-36031 | MEDIUM | 6.5 | 0.8% | Aug 19, 2022 | Directus is a free and open-source data platform for headless content management. The Directus process can be aborted by... |
| CVE-2022-36008 | MEDIUM | 6.5 | 0.9% | Aug 19, 2022 | Frontier is Substrate's Ethereum compatibility layer. A security issue was discovered affecting parsing of the RPC resul... |
| CVE-2022-0542 | MEDIUM | 6.1 | 0.8% | Aug 19, 2022 | Cross-site Scripting (XSS) - DOM in GitHub repository chatwoot/chatwoot prior to 2.7.0. |
| CVE-2022-37254 | MEDIUM | 5.4 | 0.4% | Aug 19, 2022 | DolphinPHP 1.5.1 is vulnerable to Cross Site Scripting (XSS) via Background - > System - > system function - > configura... |
| CVE-2022-34624 | MEDIUM | 5.9 | 0.7% | Aug 19, 2022 | Mealie1.0.0beta3 does not terminate download tokens after a user logs out, allowing attackers to perform a man-in-the-mi... |
| CVE-2022-34621 | MEDIUM | 6.5 | 0.7% | Aug 19, 2022 | Mealie 1.0.0beta3 was discovered to contain an Insecure Direct Object Reference (IDOR) vulnerability which allows attack... |
| CVE-2022-35910 | MEDIUM | 5.4 | 0.7% | Aug 19, 2022 | In Jellyfin before 10.8, stored XSS allows theft of an admin access token. |
| CVE-2022-1021 | MEDIUM | 5.4 | 0.6% | Aug 19, 2022 | Insecure Storage of Sensitive Information in GitHub repository chatwoot/chatwoot prior to 2.6.0. |
| CVE-2022-1901 | MEDIUM | 5.3 | 0.5% | Aug 19, 2022 | In affected versions of Octopus Deploy it is possible to unmask sensitive variables by using variable preview. |
| CVE-2022-34345 | MEDIUM | 6.2 | 0.3% | Aug 18, 2022 | Improper input validation in the firmware for some Intel(R) NUC Laptop Kits before version BC0076 may allow a privileged... |
| CVE-2022-30944 | MEDIUM | 5.5 | 0.2% | Aug 18, 2022 | Insufficiently protected credentials for Intel(R) AMT and Intel(R) Standard Manageability may allow a privileged user to... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now