2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-34574 | MEDIUM | 5.7 | 0.6% | Jul 25, 2022 | An access control issue in Wavlink WiFi-Repeater RPTA2-77W.M4300.01.GD.2017Sep19 allows attackers to obtain the key info... |
| CVE-2022-34573 | MEDIUM | 6.3 | 0.6% | Jul 25, 2022 | An access control issue in Wavlink WiFi-Repeater RPTA2-77W.M4300.01.GD.2017Sep19 allows attackers to arbitrarily configu... |
| CVE-2022-34572 | MEDIUM | 5.7 | 0.6% | Jul 25, 2022 | An access control issue in Wavlink WiFi-Repeater RPTA2-77W.M4300.01.GD.2017Sep19 allows attackers to obtain the telnet p... |
| CVE-2022-22999 | MEDIUM | 4.8 | 0.3% | Jul 25, 2022 | Western Digital My Cloud devices are vulnerable to a cross side scripting vulnerability that can allow a malicious user ... |
| CVE-2022-35288 | MEDIUM | 6.5 | 0.6% | Jul 25, 2022 | IBM Security Verify Information Queue 10.0.2 could allow a user to obtain sensitive information that could be used in fu... |
| CVE-2022-34962 | MEDIUM | 5.4 | 0.9% | Jul 25, 2022 | OpenTeknik LLC OSSN OPEN SOURCE SOCIAL NETWORK v6.3 LTS was discovered to contain a stored cross-site scripting (XSS) vu... |
| CVE-2022-2059 | MEDIUM | 4.8 | 0.4% | Jul 25, 2022 | In Pandora FMS v7.0NG.761 and below, in the agent creation section, the alias parameter is vulnerable to a Stored Cross ... |
| CVE-2022-2032 | MEDIUM | 4.8 | 0.4% | Jul 25, 2022 | In Pandora FMS v7.0NG.761 and below, in the file manager section, the dirname parameter is vulnerable to a Stored Cross ... |
| CVE-2022-35653 | MEDIUM | 6.1 | 3.7% | Jul 25, 2022 | A reflected XSS issue was identified in the LTI module of Moodle. The vulnerability exists due to insufficient sanitizat... |
| CVE-2022-35652 | MEDIUM | 6.1 | 0.9% | Jul 25, 2022 | An open redirect issue was found in Moodle due to improper sanitization of user-supplied data in mobile auto-login featu... |
| CVE-2022-35651 | MEDIUM | 6.1 | 0.8% | Jul 25, 2022 | A stored XSS and blind SSRF vulnerability was found in Moodle, occurs due to insufficient sanitization of user-supplied ... |
| CVE-2022-34964 | MEDIUM | 4.8 | 0.7% | Jul 25, 2022 | OpenTeknik LLC OSSN OPEN SOURCE SOCIAL NETWORK v6.3 LTS was discovered to contain a stored cross-site scripting (XSS) vu... |
| CVE-2022-34963 | MEDIUM | 5.4 | 0.9% | Jul 25, 2022 | OpenTeknik LLC OSSN OPEN SOURCE SOCIAL NETWORK v6.3 LTS was discovered to contain a stored cross-site scripting (XSS) vu... |
| CVE-2022-34961 | MEDIUM | 5.4 | 0.9% | Jul 25, 2022 | OpenTeknik LLC OSSN OPEN SOURCE SOCIAL NETWORK v6.3 LTS was discovered to contain a stored cross-site scripting (XSS) vu... |
| CVE-2022-2523 | MEDIUM | 6.1 | 0.7% | Jul 25, 2022 | Cross-site Scripting (XSS) - Reflected in GitHub repository beancount/fava prior to 1.22.2. |
| CVE-2022-2514 | MEDIUM | 6.1 | 0.7% | Jul 25, 2022 | The time and filter parameters in Fava prior to v1.22 are vulnerable to reflected XSS due to the lack of escaping of err... |
| CVE-2022-21802 | MEDIUM | 6.1 | 0.6% | Jul 25, 2022 | The package grapesjs before 0.19.5 are vulnerable to Cross-site Scripting (XSS) due to an improper sanitization of the c... |
| CVE-2022-1307 | MEDIUM | 4.3 | 0.6% | Jul 25, 2022 | Inappropriate implementation in full screen in Google Chrome on Android prior to 100.0.4896.88 allowed a remote attacker... |
| CVE-2022-1306 | MEDIUM | 4.3 | 0.6% | Jul 25, 2022 | Inappropriate implementation in compositing in Google Chrome prior to 100.0.4896.88 allowed a remote attacker to spoof t... |
| CVE-2022-2341 | MEDIUM | 4.8 | 0.6% | Jul 25, 2022 | The Simple Page Transition WordPress plugin through 1.4.1 does not sanitise and escape some of its settings, which could... |
| CVE-2022-2340 | MEDIUM | 4.8 | 0.6% | Jul 25, 2022 | The W-DALIL WordPress plugin through 2.0 does not sanitise and escape some of its fields, which could allow high privile... |
| CVE-2022-2299 | MEDIUM | 5.4 | 0.5% | Jul 25, 2022 | The Allow SVG Files WordPress plugin through 1.1 does not sanitise uploaded SVG files, which could allow users with a ro... |
| CVE-2022-2239 | MEDIUM | 4.8 | 0.5% | Jul 25, 2022 | The Request a Quote WordPress plugin before 2.3.9 does not sanitise and escape some of its settings, allowing high privi... |
| CVE-2022-2189 | MEDIUM | 6.1 | 0.5% | Jul 25, 2022 | The WP Video Lightbox WordPress plugin before 1.9.5 does not escape the $_SERVER['REQUEST_URI'] parameter before outputt... |
| CVE-2022-2115 | MEDIUM | 6.1 | 0.5% | Jul 25, 2022 | The Popup Anything WordPress plugin before 2.1.7 does not sanitise and escape a parameter before outputting it back in a... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now