2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-34618MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in Mealie 1.0.0beta3 allows attackers to execute arbitrary web scripts...
CVE-2022-35921MEDIUM4.3fof/byobu is a private discussions extension for Flarum forum. Affected versions were found to not respect private discu...
CVE-2022-35918MEDIUM6.5Streamlit is a data oriented application development framework for python. Users hosting Streamlit app(s) that use custo...
CVE-2022-35917MEDIUM5.3Solana Pay is a protocol and set of reference implementations that enable developers to incorporate decentralized paymen...
CVE-2022-35916MEDIUM5.3OpenZeppelin Contracts is a library for secure smart contract development. Contracts using the cross chain utilities for...
CVE-2022-35915MEDIUM5.3OpenZeppelin Contracts is a library for secure smart contract development. The target contract of an EIP-165 `supportsIn...
CVE-2022-31193MEDIUM6.1DSpace open source software is a repository application which provides durable access to digital resources. dspace-jspui...
CVE-2022-31192MEDIUM6.1DSpace open source software is a repository application which provides durable access to digital resources. dspace-jspui...
CVE-2022-31191MEDIUM6.1DSpace open source software is a repository application which provides durable access to digital resources. dspace-jspui...
CVE-2022-31189MEDIUM5.3DSpace open source software is a repository application which provides durable access to digital resources. dspace-jspui...
CVE-2022-35118MEDIUM6.1PyroCMS v3.9 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities.
CVE-2022-34530MEDIUM5.3An issue in the login and reset password functionality of Backdrop CMS v1.22.0 allows attackers to enumerate usernames v...
CVE-2022-31190MEDIUM5.3DSpace open source software is a repository application which provides durable access to digital resources. dspace-xmlui...
CVE-2022-31185MEDIUM5.3mprweb is a hosting platform for the makedeb Package Repository. Email addresses were found to not have been hidden, eve...
CVE-2022-31182MEDIUM5.3Discourse is the an open source discussion platform. In affected versions a maliciously crafted request for static asset...
CVE-2022-31178MEDIUM4.3eLabFTW is an electronic lab notebook manager for research teams. A vulnerability was discovered which allows a logged i...
CVE-2022-31155MEDIUM4.3Sourcegraph is an opensource code search and navigation engine. In Sourcegraph versions before 3.41.0, it is possible fo...
CVE-2022-31154MEDIUM4.3Sourcegraph is an opensource code search and navigation engine. It is possible for an authenticated Sourcegraph user to ...
CVE-2022-31148MEDIUM5.4Shopware is an open source e-commerce software. In versions from 5.7.0 a persistent cross site scripting (XSS) vulnerabi...
CVE-2022-31128MEDIUM5.4Tuleap is a Free & Open Source Suite to improve management of software developments and collaboration. In affected versi...
CVE-2022-31109MEDIUM6.1laminas-diactoros is a PHP package containing implementations of the PSR-7 HTTP message interfaces and PSR-17 HTTP messa...
CVE-2022-34307MEDIUM4.3IBM CICS TX 11.1 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to ...
CVE-2022-34164MEDIUM5.5IBM CICS TX 11.1 could allow a local user to impersonate another legitimate user due to improper input validation. IBM X...
CVE-2022-34163MEDIUM6.1IBM CICS TX 11.1 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. Thi...
CVE-2022-34162MEDIUM6.1IBM CICS TX 11.1 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to vi...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now