2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-31897MEDIUM6.1SourceCodester Zoo Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via public_html/register_visitor?ms...
CVE-2022-31266MEDIUM4.3In ILIAS through 7.10, lack of verification when changing an email address (on the Profile Page) allows remote attackers...
CVE-2022-29272MEDIUM6.1In Nagios XI through 5.8.5, an open redirect vulnerability exists in the login function that could lead to spoofing.
CVE-2022-29271MEDIUM6.5In Nagios XI through 5.8.5, a read-only Nagios user (due to an incorrect permission check) is able to schedule downtime ...
CVE-2022-29270MEDIUM4.3In Nagios XI through 5.8.5, it is possible for a user without password verification to change his e-mail address.
CVE-2022-29269MEDIUM6.5In Nagios XI through 5.8.5, in the schedule report function, an authenticated attacker is able to inject HTML tags that ...
CVE-2022-28803MEDIUM5.4In SilverStripe Framework through 2022-04-07, Stored XSS can occur in javascript link tags added via XMLHttpRequest (XHR...
CVE-2022-31884MEDIUM6.5Marval MSM v14.19.0.12476 has an Improper Access Control vulnerability which allows a low privilege user to delete other...
CVE-2022-29858MEDIUM4.3Silverstripe silverstripe/assets through 1.10 is vulnerable to improper access control that allows protected images to b...
CVE-2022-25238MEDIUM5.4Silverstripe silverstripe/framework through 4.10.0 allows XSS, inside of script tags that can can be added to website co...
CVE-2022-24444MEDIUM6.5Silverstripe silverstripe/framework through 4.10 allows Session Fixation.
CVE-2022-31886MEDIUM6.5Marval MSM v14.19.0.12476 is vulnerable to Cross Site Request Forgery (CSRF). An attacker can disable the 2FA by sending...
CVE-2022-2231MEDIUM5.5NULL Pointer Dereference in GitHub repository vim/vim prior to 8.2.
CVE-2022-31229MEDIUM4.9Dell PowerScale OneFS, 8.2.x through 9.3.0.x, contain an error message with sensitive information. An administrator coul...
CVE-2022-31108MEDIUM6.1Mermaid is a JavaScript based diagramming and charting tool that uses Markdown-inspired text definitions and a renderer ...
CVE-2022-31068MEDIUM5.3GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking an...
CVE-2022-31052MEDIUM6.5Synapse is an open source home server implementation for the Matrix chat network. In versions prior to 1.61.1 URL previe...
CVE-2022-0085MEDIUM5.3Server-Side Request Forgery (SSRF) in GitHub repository dompdf/dompdf prior to 2.0.0.
CVE-2022-30562MEDIUM4.7If the user enables the https function on the device, an attacker can modify the user’s request data packet through a ma...
CVE-2022-30561MEDIUM5.9When an attacker uses a man-in-the-middle attack to sniff the request packets with success logging in, the attacker coul...
CVE-2022-23896MEDIUM5.4Admidio 4.1.2 version is affected by stored cross-site scripting (XSS).
CVE-2022-34133MEDIUM6.1Jorani v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Comment parameter at applicatio...
CVE-2022-31104MEDIUM5.6Wasmtime is a standalone runtime for WebAssembly. In affected versions wasmtime's implementation of the SIMD proposal fo...
CVE-2022-33009MEDIUM4.8A stored cross-site scripting (XSS) vulnerability in LightCMS v1.3.11 allows attackers to execute arbitrary web scripts ...
CVE-2022-31099MEDIUM6.5rulex is a new, portable, regular expression language. When parsing untrusted rulex expressions, the stack may overflow,...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now