2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-31472MEDIUM4.3Browse restriction bypass vulnerability in Cabinet of Cybozu Garoon 4.0.0 to 5.5.1 allows a remote authenticated attacke...
CVE-2022-30943MEDIUM4.3Browsing restriction bypass vulnerability in Bulletin of Cybozu Garoon 4.0.0 to 5.9.1 allows a remote authenticated atta...
CVE-2022-29512MEDIUM6.5Exposure of sensitive information to an unauthorized actor issue in multiple applications of Cybozu Garoon 4.0.0 to 5.9....
CVE-2022-27168MEDIUM6.1Cross-site scripting vulnerability in LiteCart versions prior to 2.4.2 allows a remote attacker to inject an arbitrary s...
CVE-2022-2365MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository zadam/trilium prior to 0.53.3.
CVE-2022-27910MEDIUM6.1In Joomla component 'Joomlatools - DOCman 3.5.13 (and likely most versions below)' are affected to an reflected Cross-Si...
CVE-2022-2353MEDIUM6.1Prior to microweber/microweber v1.2.20, due to improper neutralization of input, an attacker can steal tokens to perform...
CVE-2022-35412MEDIUM5.1Digital Guardian Agent 7.7.4.0042 allows an administrator (who ordinarily does not have a supported way to uninstall the...
CVE-2022-22463MEDIUM6.5IBM Security Access Manager Appliance 10.0.0.0, 10.0.1.0, 10.0.2.0, and 10.0.3.0 is vulnerable to SQL injection. A remot...
CVE-2022-22370MEDIUM5.4IBM Security Verify Access 10.0.0.0, 10.0.1.0, 10.0.2.0, and 10.0.3.0 is vulnerable to cross-site scripting. This vulner...
CVE-2022-34306MEDIUM5.4IBM CICS TX Standard and Advanced 11.1 is vulnerable to HTTP header injection, caused by improper validation of input by...
CVE-2022-34167MEDIUM5.4IBM CICS TX Standard and Advanced 11.1 is vulnerable to stored cross-site scripting. This vulnerability allows users to ...
CVE-2022-34166MEDIUM5.4IBM CICS TX Standard and Advanced 11.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed a...
CVE-2022-34160MEDIUM5.4IBM CICS TX Standard and Advanced 11.1 is vulnerable to HTML injection. A remote attacker could inject malicious HTML co...
CVE-2022-35406MEDIUM4.3A URL disclosure issue was discovered in Burp Suite before 2022.6. If a user views a crafted response in the Repeater or...
CVE-2022-28624MEDIUM4.8A potential security vulnerability has been identified in certain HPE FlexNetwork and FlexFabric switch products. The vu...
CVE-2022-32115MEDIUM6.1An issue in the isSVG() function of Known v1.2.2+2020061101 allows attackers to execute arbitrary code via a crafted SVG...
CVE-2022-31290MEDIUM5.4A cross-site scripting (XSS) vulnerability in Known v1.2.2+2020061101 allows authenticated attackers to execute arbitrar...
CVE-2022-30852MEDIUM4.3Known v1.3.1 was discovered to contain an Insecure Direct Object Reference (IDOR).
CVE-2022-32061MEDIUM4.8An arbitrary file upload vulnerability in the Select User function under the People Menu component of Snipe-IT v6.0.2 al...
CVE-2022-32060MEDIUM4.8An arbitrary file upload vulnerability in the Update Branding Settings component of Snipe-IT v6.0.2 allows attackers to ...
CVE-2022-31029MEDIUM4.8AdminLTE is a Pi-hole Dashboard for stats and configuration. In affected versions inserting code like `<script>alert("XS...
CVE-2022-33098MEDIUM6.1Magnolia CMS v6.2.19 was discovered to contain a cross-site scripting (XSS) vulnerability via the Edit Contact function....
CVE-2022-28889MEDIUM4.3In Apache Druid 0.22.1 and earlier, the server did not set appropriate headers to prevent clickjacking. Druid 0.23.0 and...
CVE-2022-31136MEDIUM6.1Bookwyrm is an open source social reading and reviewing program. Versions of Bookwyrm prior to 0.4.1 did not properly sa...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now