2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-1932MEDIUM6.1The Rezgo Online Booking WordPress plugin before 4.1.8 does not sanitise and escape some parameters before outputting th...
CVE-2022-1322MEDIUM4.8The Coming Soon - Under Construction WordPress plugin through 1.1.9 does not sanitize and escape some of its settings, w...
CVE-2022-1251MEDIUM4.3The Ask me WordPress theme before 6.8.4 does not perform nonce checks when processing POST requests to the Edit Profile ...
CVE-2022-0446MEDIUM4.8The Simple Banner WordPress plugin before 2.12.0 does not properly sanitize its "Simple Banner Text" Settings allowing h...
CVE-2022-2932MEDIUM6.1Cross-site Scripting (XSS) - Reflected in GitHub repository bustle/mobiledoc-kit prior to 0.14.2.
CVE-2022-2890MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0.
CVE-2022-1340MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0.
CVE-2022-36251MEDIUM6.1Clinic's Patient Management System v1.0 is vulnerable to Cross Site Scripting (XSS) via patients.php.
CVE-2022-2885MEDIUM4.8Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0.
CVE-2022-35692MEDIUM5.3Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by an Improp...
CVE-2022-35554MEDIUM6.1Multiple reflected XSS vulnerabilities occur when handling error message of BPC SmartVista version 3.28.0 allowing an at...
CVE-2022-2790MEDIUM5.9Emerson Electric's Proficy Machine Edition Version 9.00 and prior is vulenrable to CWE-347 Improper Verification of Cryp...
CVE-2022-2789MEDIUM5.5Emerson Electric's Proficy Machine Edition Version 9.00 and prior is vulnerable to CWE-345 Insufficient Verification of ...
CVE-2022-36233MEDIUM5.5Tenda AC9 V15.03.2.13 is vulnerable to Buffer Overflow via httpd, form_fast_setting_wifi_set. httpd.
CVE-2022-36031MEDIUM6.5Directus is a free and open-source data platform for headless content management. The Directus process can be aborted by...
CVE-2022-36008MEDIUM6.5Frontier is Substrate's Ethereum compatibility layer. A security issue was discovered affecting parsing of the RPC resul...
CVE-2022-0542MEDIUM6.1Cross-site Scripting (XSS) - DOM in GitHub repository chatwoot/chatwoot prior to 2.7.0.
CVE-2022-37254MEDIUM5.4DolphinPHP 1.5.1 is vulnerable to Cross Site Scripting (XSS) via Background - > System - > system function - > configura...
CVE-2022-34624MEDIUM5.9Mealie1.0.0beta3 does not terminate download tokens after a user logs out, allowing attackers to perform a man-in-the-mi...
CVE-2022-34621MEDIUM6.5Mealie 1.0.0beta3 was discovered to contain an Insecure Direct Object Reference (IDOR) vulnerability which allows attack...
CVE-2022-35910MEDIUM5.4In Jellyfin before 10.8, stored XSS allows theft of an admin access token.
CVE-2022-1021MEDIUM5.4Insecure Storage of Sensitive Information in GitHub repository chatwoot/chatwoot prior to 2.6.0.
CVE-2022-1901MEDIUM5.3In affected versions of Octopus Deploy it is possible to unmask sensitive variables by using variable preview.
CVE-2022-34345MEDIUM6.2Improper input validation in the firmware for some Intel(R) NUC Laptop Kits before version BC0076 may allow a privileged...
CVE-2022-30944MEDIUM5.5Insufficiently protected credentials for Intel(R) AMT and Intel(R) Standard Manageability may allow a privileged user to...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now