2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-31175MEDIUM4.7CKEditor 5 is a JavaScript rich text editor. A cross-site scripting vulnerability has been discovered affecting three op...
CVE-2022-35867MEDIUM6.7This vulnerability allows local attackers to escalate privileges on affected installations of xhyve. An attacker must fi...
CVE-2022-35864MEDIUM6.5This vulnerability allows remote attackers to disclose sensitive information on affected installations of BMC Track-It! ...
CVE-2022-34872MEDIUM6.5This vulnerability allows remote attackers to disclose sensitive information on affected installations of Centreon. Auth...
CVE-2022-27484MEDIUM4.3A unverified password change in Fortinet FortiADC version 6.2.0 through 6.2.3, 6.1.x, 6.0.x, 5.x.x allows an authenticat...
CVE-2022-23442MEDIUM4.3An improper access control vulnerability [CWE-284] in FortiOS versions 6.2.0 through 6.2.11, 6.4.0 through 6.4.8 and 7.0...
CVE-2022-36800MEDIUM4.3Affected versions of Atlassian Jira Service Management Server and Data Center allow remote attackers without the "Browse...
CVE-2022-27620MEDIUM4.9Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in webapi component in Syno...
CVE-2022-27619MEDIUM5.9Cleartext transmission of sensitive information vulnerability in authentication management in Synology Note Station Clie...
CVE-2022-27618MEDIUM6.5Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in webapi component in Syno...
CVE-2022-27617MEDIUM4.3Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in webapi component in Syno...
CVE-2022-36197MEDIUM5.4BigTree CMS 4.4.16 was discovered to contain an arbitrary file upload vulnerability which allows attackers to execute ar...
CVE-2022-33917MEDIUM5.5An issue was discovered in the Arm Mali GPU Kernel Driver (Valhall r29p0 through r38p0). A non-privileged user can make ...
CVE-2022-36968MEDIUM4.3In Progress WS_FTP Server prior to version 8.7.3, forms within the administrative interface did not include a nonce to m...
CVE-2022-36967MEDIUM6.1In Progress WS_FTP Server prior to version 8.7.3, multiple reflected cross-site scripting (XSS) vulnerabilities exist in...
CVE-2022-34619MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in Mealie v0.5.5 allows attackers to execute arbitrary web scripts or ...
CVE-2022-30572MEDIUM6.5The iWay Service Manager Console component of TIBCO Software Inc.'s TIBCO iWay Service Manager contains an easily exploi...
CVE-2022-30571MEDIUM5.4The iWay Service Manager Console component of TIBCO Software Inc.'s TIBCO iWay Service Manager contains easily exploitab...
CVE-2022-35222MEDIUM6.8HiCOS Citizen verification component has a stack-based buffer overflow vulnerability due to insufficient parameter lengt...
CVE-2022-35221MEDIUM5.4Teamplus Pro community discussion has an ‘allocation of resource without limits or throttling’ vulnerability on thread s...
CVE-2022-35220MEDIUM6.5Teamplus Pro community discussion function has an ‘allocation of resource without limits or throttling’ vulnerability. A...
CVE-2022-35219MEDIUM5.5The NHI card’s web service component has a stack-based buffer overflow vulnerability due to insufficient validation for ...
CVE-2022-35218MEDIUM5.5The NHI card’s web service component has a heap-based buffer overflow vulnerability due to insufficient validation for p...
CVE-2022-23733MEDIUM5.4A stored XSS vulnerability was identified in GitHub Enterprise Server that allowed the injection of arbitrary attributes...
CVE-2022-1293MEDIUM6.1The embedded neutralization of Script-Related HTML Tag, was by-passed in the case of some extra conditions.

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now