2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-32128MEDIUM6.174cmsSE v3.5.1 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the path /company/ser...
CVE-2022-32127MEDIUM6.174cmsSE v3.5.1 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the path /company/vie...
CVE-2022-32126MEDIUM6.174cmsSE v3.5.1 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the path /company.
CVE-2022-32125MEDIUM6.174cmsSE v3.5.1 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the path /job.
CVE-2022-32124MEDIUM6.174cmsSE v3.5.1 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the component /index/...
CVE-2022-29526MEDIUM5.3Go before 1.17.10 and 1.18.x before 1.18.2 has Incorrect Privilege Assignment. When called with a non-zero flags paramet...
CVE-2022-34305MEDIUM6.1In Apache Tomcat 10.1.0-M1 to 10.1.0-M16, 10.0.0-M1 to 10.0.22, 9.0.30 to 9.0.64 and 8.5.50 to 8.5.81 the Form authentic...
CVE-2022-31009MEDIUM6.5wire-ios is an iOS client for the Wire secure messaging application. Invalid accent colors of Wire communication partner...
CVE-2022-23080MEDIUM5In directus versions v9.0.0-beta.2 through 9.6.0 are vulnerable to server-side request forgery (SSRF) in the media uploa...
CVE-2022-32549MEDIUM5.3Apache Sling Commons Log <= 5.4.0 and Apache Sling API <= 2.25.0 are vulnerable to log injection. The ability to forge l...
CVE-2022-20651MEDIUM5.5A vulnerability in the logging component of Cisco Adaptive Security Device Manager (ASDM) could allow an authenticated, ...
CVE-2022-2174MEDIUM6.1Cross-site Scripting (XSS) - Reflected in GitHub repository microweber/microweber prior to 1.2.18.
CVE-2022-23077MEDIUM6.1In habitica versions v4.119.0 through v4.232.2 are vulnerable to DOM XSS via the login page.
CVE-2022-31248MEDIUM5.3A Observable Response Discrepancy vulnerability in spacewalk-java of SUSE Manager Server 4.1, SUSE Manager Server 4.2 al...
CVE-2022-23057MEDIUM5.4In ERPNext, versions v12.0.9--v13.0.3 are vulnerable to Stored Cross-Site-Scripting (XSS), due to user input not being v...
CVE-2022-31095MEDIUM6.5discourse-chat is a chat plugin for the Discourse application. Versions prior to 0.4 are vulnerable to an exposure of se...
CVE-2022-32974MEDIUM6.5An authenticated attacker could read arbitrary files from the underlying operating system of the scanner using a custom ...
CVE-2022-31786MEDIUM6.1IdeaLMS 2022 allows reflected Cross Site Scripting (XSS) via the IdeaLMS/Class/Assessment/ PATH_INFO.
CVE-2022-30874MEDIUM5.4There is a Cross Site Scripting Stored (XSS) vulnerability in NukeViet CMS before 4.5.02.
CVE-2022-1596MEDIUM6.5Incorrect Permission Assignment for Critical Resource vulnerability in ABB REX640 PCL1, REX640 PCL2, REX640 PCL3 allows ...
CVE-2022-31478MEDIUM4.3The UserTakeOver plugin before 4.0.1 for ILIAS allows an attacker to list all users via the search function.
CVE-2022-25585MEDIUM5.4Unioncms v1.0.13 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Default settings.
CVE-2022-23342MEDIUM5.3The Hyland Onbase Application Server releases prior to 20.3.58.1000 and OnBase releases 21.1.1.1000 through 21.1.15.1000...
CVE-2022-33119MEDIUM6.1NUUO Network Video Recorder NVRsolo v03.06.02 was discovered to contain a reflected cross-site scripting (XSS) vulnerabi...
CVE-2022-32414MEDIUM5.5Nginx NJS v0.7.2 was discovered to contain a segmentation violation in the function njs_vmcode_interpreter at src/njs_vm...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now