2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-21763MEDIUM5.5In telecom service, there is a possible information disclosure due to a missing permission check. This could lead to loc...
CVE-2022-24141MEDIUM5.4The iTopVPNmini.exe component of iTop VPN 3.2 will try to connect to datastate_iTopVPN_Pipe_Server on a loop. An attacke...
CVE-2022-24140MEDIUM6.6IOBit Advanced System Care 15, iTop Screen Recorder 2.1, iTop VPN 3.2, Driver Booster 9, and iTop Screenshot sends HTTP ...
CVE-2022-32290MEDIUM4.3The client in Northern.tech Mender 3.2.0, 3.2.1, and 3.2.2 has Incorrect Access Control. It listens on a random, unprivi...
CVE-2022-35230MEDIUM5.4An authenticated user can create a link with reflected Javascript code inside it for the graphs page and send it to othe...
CVE-2022-35229MEDIUM5.4An authenticated user can create a link with reflected Javascript code inside it for the discovery page and send it to o...
CVE-2022-33075MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in the Add Classification function of Zoo Management System v1.0 allow...
CVE-2022-31117MEDIUM5.9UltraJSON is a fast JSON encoder and decoder written in pure C with bindings for Python 3.7+. In versions prior to 5.4.0...
CVE-2022-34879MEDIUM6.1Reflected Cross Site Scripting (XSS) vulnerabilities in AST Agent Time Sheet interface (/vicidial/AST_agent_time_sheet.p...
CVE-2022-31770MEDIUM4.9IBM App Connect Enterprise Certified Container 4.2 could allow a user from the administration console to cause a denial ...
CVE-2022-33744MEDIUM4.7Arm guests can cause Dom0 DoS via PV devices When mapping pages of guests on Arm, dom0 is using an rbtree to keep track ...
CVE-2022-30289MEDIUM5.4A stored Cross-site Scripting (XSS) vulnerability was identified in the Data Import functionality of OpenCTI through 5.2...
CVE-2022-2097MEDIUM5.3AES OCB mode for 32-bit x86 platforms using the AES-NI assembly optimised implementation will not encrypt the entirety o...
CVE-2022-31603MEDIUM6.7NVIDIA DGX A100 contains a vulnerability in SBIOS in the IpSecDxe, where a user with high privileges and preconditioned ...
CVE-2022-31602MEDIUM6.7NVIDIA DGX A100 contains a vulnerability in SBIOS in the IpSecDxe, where a user with elevated privileges and a precondit...
CVE-2022-31601MEDIUM6.7NVIDIA DGX A100 contains a vulnerability in SBIOS in the SmbiosPei, which may allow a highly privileged local attacker t...
CVE-2022-1967MEDIUM6.5The WP Championship WordPress plugin before 9.3 is lacking CSRF checks in various places, allowing attackers to make a l...
CVE-2022-1946MEDIUM6.1The Gallery WordPress plugin before 2.0.0 does not sanitise and escape a parameter before outputting it back in the resp...
CVE-2022-1301MEDIUM4.8The WP Contact Slider WordPress plugin before 2.4.7 does not sanitize and escape the Text to Display settings of sliders...
CVE-2022-0250MEDIUM6.1The Redirection for Contact Form 7 WordPress plugin before 2.5.0 does not escape a link generated before outputting it i...
CVE-2022-2301MEDIUM5.5Buffer Over-read in GitHub repository hpjansson/chafa prior to 1.10.3.
CVE-2022-2300MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 1.2.19.
CVE-2022-29892MEDIUM6.5Improper input validation vulnerability in Space of Cybozu Garoon 4.0.0 to 5.5.1 allows a remote authenticated attacker ...
CVE-2022-29513MEDIUM4.8Cross-site scripting vulnerability in Scheduler of Cybozu Garoon 4.10.0 to 5.5.1 allows a remote authenticated attacker ...
CVE-2022-29471MEDIUM4.3Browse restriction bypass vulnerability in Bulletin of Cybozu Garoon allows a remote authenticated attacker to obtain th...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now