2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-1610MEDIUM6.5The Seamless Donations WordPress plugin before 5.1.9 does not have CSRF check in place when updating its settings, which...
CVE-2022-1603MEDIUM4.3The Mail Subscribe List WordPress plugin before 2.1.4 does not have CSRF check in place when deleting subscribed users, ...
CVE-2022-1266MEDIUM4.8The Post Grid, Slider & Carousel Ultimate WordPress plugin before 1.5.0 does not sanitise and escape the Header Title, w...
CVE-2022-0663MEDIUM4.8The Print, PDF, Email by PrintFriendly WordPress plugin before 5.2.3 does not sanitise and escape the Custom Button Text...
CVE-2022-31734MEDIUM6.1Cisco Catalyst 2940 Series Switches provided by Cisco Systems, Inc. contain a reflected cross-site scripting vulnerabili...
CVE-2022-2130MEDIUM6.1Cross-site Scripting (XSS) - Reflected in GitHub repository microweber/microweber prior to 1.2.17.
CVE-2022-26669MEDIUM6.5ASUS Control Center is vulnerable to SQL injection. An authenticated remote attacker with general user privilege can inj...
CVE-2022-26668MEDIUM6.5ASUS Control Center API has a broken access control vulnerability. An unauthenticated remote attacker can call privilege...
CVE-2022-21742MEDIUM6.5Realtek USB driver has a buffer overflow vulnerability due to insufficient parameter length verification in the API func...
CVE-2022-34000MEDIUM6.5libjxl 0.6.1 has an assertion failure in LowMemoryRenderPipeline::Init() in render_pipeline/low_memory_render_pipeline.c...
CVE-2022-23071MEDIUM6.5In Recipes, versions 0.9.1 through 1.2.5 are vulnerable to Server Side Request Forgery (SSRF), in the “Import Recipe” fu...
CVE-2022-33987MEDIUM5.3The got package before 12.1.0 (also fixed in 11.8.5) for Node.js allows a redirect to a UNIX socket.
CVE-2022-21503MEDIUM4.9Vulnerability in the Oracle Cloud Infrastructure product of Oracle Cloud Services. Easily exploitable vulnerability allo...
CVE-2022-31876MEDIUM5.3netgear wnap320 router WNAP320_V2.0.3_firmware is vulnerable to Incorrect Access Control via /recreate.php, which can le...
CVE-2022-31875MEDIUM6.1Trendnet IP-110wn camera fw_tv-ip110wn_v2(1.2.2.68) has an xss vulnerability via the proname parameter in /admin/schepro...
CVE-2022-31873MEDIUM6.1Trendnet IP-110wn camera fw_tv-ip110wn_v2(1.2.2.68) has an XSS vulnerability via the prefix parameter in /admin/general....
CVE-2022-25872MEDIUM5.3All versions of package fast-string-search are vulnerable to Out-of-bounds Read due to incorrect memory freeing and leng...
CVE-2022-21184MEDIUM5.9An information disclosure vulnerability exists in the License registration functionality of Bachmann Visutec GmbH Atvise...
CVE-2022-32444MEDIUM6.1An issue was discovered in u5cms verion 8.3.5 There is a URL redirection vulnerability that can cause a user's browser t...
CVE-2022-32442MEDIUM6.1u5cms version 8.3.5 is vulnerable to Cross Site Scripting (XSS). When a user accesses the default home page if the param...
CVE-2022-30607MEDIUM6.5IBM Robotic Process Automation 20.10.0, 20.12.5, 21.0.0, 21.0.1, and 21.0.2 contains a vulnerability that could allow a ...
CVE-2022-31246MEDIUM5.5paymentrequest.py in Electrum before 4.2.2 allows a file:// URL in the r parameter of a payment request (e.g., within QR...
CVE-2022-2113MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository inventree/inventree prior to 0.7.2.
CVE-2022-30328MEDIUM6.5An issue was found on TRENDnet TEW-831DR 1.0 601.130.1.1356 devices. The username and password setup for the web interfa...
CVE-2022-30327MEDIUM6.5An issue was found on TRENDnet TEW-831DR 1.0 601.130.1.1356 devices. The web interface is vulnerable to CSRF. An attacke...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now