2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-24952MEDIUM6.5Several denial of service vulnerabilities exist in Eternal Terminal prior to version 6.2.0, including a DoS triggered re...
CVE-2022-38358MEDIUM6.1Improper neutralization of input during web page generation leaves the Eyes of Network web application vulnerable to cro...
CVE-2022-38191MEDIUM5.4There is an HTML injection issue in Esri Portal for ArcGIS versions 10.9.0 and below which may allow a remote, authentic...
CVE-2022-38190MEDIUM6.1A stored Cross Site Scripting (XSS) vulnerability in Esri Portal for ArcGIS configurable apps may allow a remote, unauth...
CVE-2022-38188MEDIUM6.1There is a reflected XSS vulnerability in Esri Portal for ArcGIS versions 10.9.1 which may allow a remote attacker able ...
CVE-2022-38186MEDIUM6.1There is a reflected XSS vulnerability in Esri Portal for ArcGIS versions 10.8.1 and below which may allow a remote atta...
CVE-2022-24654MEDIUM5.4Authenticated stored cross-site scripting (XSS) vulnerability in "Field Server Address" field in INTELBRAS ATA 200 Firmw...
CVE-2022-2824MEDIUM5.4Authorization Bypass Through User-Controlled Key in GitHub repository openemr/openemr prior to 7.0.0.1.
CVE-2022-33991MEDIUM5.3dproxy-nexgen (aka dproxy nexgen) forwards and caches DNS queries with the CD (aka checking disabled) bit set to 1. This...
CVE-2022-33989MEDIUM5.3dproxy-nexgen (aka dproxy nexgen) uses a static UDP source port (selected randomly only at boot time) in upstream querie...
CVE-2022-33993MEDIUM5.3Misinterpretation of special domain name characters in DNRD (aka Domain Name Relay Daemon) 2.20.3 leads to cache poisoni...
CVE-2022-35961MEDIUM6.5OpenZeppelin Contracts is a library for secure smart contract development. The functions `ECDSA.recover` and `ECDSA.tryR...
CVE-2022-35954MEDIUM5The GitHub Actions ToolKit provides a set of packages to make creating actions easier. The `core.exportVariable` functio...
CVE-2022-35948MEDIUM5.3undici is an HTTP/1.1 client, written from scratch for Node.js.`=< undici@5.8.0` users are vulnerable to _CRLF Injection...
CVE-2022-2814MEDIUM6.1A vulnerability has been found in SourceCodester Simple and Nice Shopping Cart Script and classified as problematic. Aff...
CVE-2022-2811MEDIUM6.1A vulnerability classified as problematic has been found in SourceCodester Guest Management System. This affects an unkn...
CVE-2022-2535MEDIUM5.3The SearchWP Live Ajax Search WordPress plugin before 1.6.2 does not ensure that users making a live search are limited ...
CVE-2022-2384MEDIUM4.8The Digital Publications by Supsystic WordPress plugin before 1.7.4 does not sanitise and escape its settings, allowing ...
CVE-2022-2378MEDIUM6.1The Easy Student Results WordPress plugin through 2.2.8 does not sanitise and escape a parameter before outputting it ba...
CVE-2022-2152MEDIUM4.8The Duplicate Page and Post WordPress plugin before 2.8 does not sanitise and escape its settings, allowing high privile...
CVE-2022-2116MEDIUM6.1The Contact Form DB WordPress plugin before 1.8.0 does not sanitise and escape some parameters before outputting them ba...
CVE-2022-35953MEDIUM6.1BookWyrm is a social network for tracking your reading, talking about books, writing reviews, and discovering what to re...
CVE-2022-38183MEDIUM6.5In Gitea before 1.16.9, it was possible for users to add existing issues to projects. Due to improper access controls, a...
CVE-2022-2800MEDIUM6.1A vulnerability, which was classified as problematic, has been found in SourceCodester Gym Management System. Affected b...
CVE-2022-2622MEDIUM6.5Insufficient validation of untrusted input in Safe Browsing in Google Chrome on Windows prior to 104.0.5112.79 allowed a...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now