2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-2137MEDIUM4.9The affected product is vulnerable to two SQL injections that require high privileges for exploitation and may allow an ...
CVE-2022-2136MEDIUM6.5The affected product is vulnerable to multiple SQL injections that require low privileges for exploitation and may allow...
CVE-2022-1655MEDIUM6.5An Incorrect Permission Assignment for Critical Resource flaw was found in Horizon on Red Hat OpenStack. Horizon session...
CVE-2022-36131MEDIUM6.1The Better PDF Exporter add-on 10.0.0 for Atlassian Jira is prone to stored XSS via a crafted description to the PDF Tem...
CVE-2022-2495MEDIUM4.8Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 1.2.21.
CVE-2022-2494MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository openemr/openemr prior to 7.0.0.
CVE-2022-20916MEDIUM6.1A vulnerability in the web-based management interface of Cisco IoT Control Center could allow an unauthenticated, remote...
CVE-2022-20913MEDIUM6.5A vulnerability in Cisco Nexus Dashboard could allow an authenticated, remote attacker to write arbitrary files on an af...
CVE-2022-20909MEDIUM6.7Multiple vulnerabilities in Cisco Nexus Dashboard could allow an authenticated, local attacker to elevate privileges on ...
CVE-2022-20908MEDIUM6.7Multiple vulnerabilities in Cisco Nexus Dashboard could allow an authenticated, local attacker to elevate privileges on ...
CVE-2022-20907MEDIUM6.7Multiple vulnerabilities in Cisco Nexus Dashboard could allow an authenticated, local attacker to elevate privileges on ...
CVE-2022-20906MEDIUM6.7Multiple vulnerabilities in Cisco Nexus Dashboard could allow an authenticated, local attacker to elevate privileges on ...
CVE-2022-34487MEDIUM5.3Unauthenticated Arbitrary Option Update vulnerability in biplob018's Shortcode Addons plugin <= 3.0.2 at WordPress.
CVE-2022-33198MEDIUM5.3Unauthenticated WordPress Options Change vulnerability in Biplob Adhikari's Accordions plugin <= 2.0.2 at WordPress.
CVE-2022-31475MEDIUM4.9Authenticated (custom plugin role) Arbitrary File Read via Export function vulnerability in GiveWP's GiveWP plugin <= 2....
CVE-2022-30536MEDIUM4.8Authenticated Stored Cross-Site Scripting (XSS) vulnerability in Florent Maillefaud's WP Maintenance plugin <= 6.0.7 at ...
CVE-2022-30337MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in JoomUnited WP Meta SEO plugin <= 4.4.8 at WordPress allows an attacke...
CVE-2022-28666MEDIUM5.3Broken Access Control vulnerability in YIKES Inc. Custom Product Tabs for WooCommerce plugin <= 1.7.7 at WordPress leadi...
CVE-2022-36313MEDIUM5.5An issue was discovered in the file-type package before 16.5.4 and 17.x before 17.1.3 for Node.js. A malformed MKV file ...
CVE-2022-32289MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in Sygnoos Popup Builder plugin <= 4.1.0 at WordPress leading to popup s...
CVE-2022-30628MEDIUM5.5It was possible to download all receipts without authentication. Must first access the API https://XXXX.supersmart.me/se...
CVE-2022-28877MEDIUM6.7This vulnerability allows local user to delete arbitrary file in the system and bypassing security protection which can ...
CVE-2022-28861MEDIUM5.9The server in Citilog 8.0 allows an attacker (in a man in the middle position between the server and its smart camera Ax...
CVE-2022-28860MEDIUM5.9An authentication downgrade in the server in Citilog 8.0 allows an attacker (in a man in the middle position between the...
CVE-2022-31151MEDIUM6.5Authorization headers are cleared on cross-origin redirect. However, cookie headers which are sensitive headers and are ...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now