2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-30760MEDIUM4.3An Insecure Direct Object Reference (IDOR) issue in fn2Web in ihb eG FlexNow before 2.04.09.016 allows remote authentica...
CVE-2022-2020MEDIUM4.8A vulnerability, which was classified as problematic, has been found in SourceCodester Prison Management System 1.0. Aff...
CVE-2022-2016MEDIUM5.4Cross-site Scripting (XSS) - Reflected in GitHub repository neorazorx/facturascripts prior to 2022.1.
CVE-2022-24969MEDIUM6.1bypass CVE-2021-25640 > In Apache Dubbo prior to 2.6.12 and 2.7.15, the usage of parseURL method will lead to the bypass...
CVE-2022-0823MEDIUM6.2An improper control of interaction frequency vulnerability in Zyxel GS1200 series switches could allow a local attacker ...
CVE-2022-2035MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability exists in the playerConfUrl parameter in the /defaultui/player/mode...
CVE-2022-31030MEDIUM5.5containerd is an open source container runtime. A bug was found in the containerd's CRI implementation where programs in...
CVE-2022-31027MEDIUM6.5OAuthenticator is an OAuth token library for the JupyerHub login handler. CILogonOAuthenticator is provided by the OAuth...
CVE-2022-29254MEDIUM6.5silverstripe-omnipay is a SilverStripe integration with Omnipay PHP payments library. For a subset of Omnipay gateways (...
CVE-2022-24896MEDIUM4.3Tuleap is a Free & Open Source Suite to manage software developments and collaboration. In versions prior to 13.7.99.239...
CVE-2022-32195MEDIUM6.1Open edX platform before 2022-06-06 allows XSS via the "next" parameter in the logout URL.
CVE-2022-25807MEDIUM5.5An issue was discovered in the IGEL Universal Management Suite (UMS) 6.07.100. A hardcoded DES key in the LDAPDesPWEncry...
CVE-2022-25805MEDIUM6.5An issue was discovered in the IGEL Universal Management Suite (UMS) 6.07.100. The transmission of cleartext LDAP bind c...
CVE-2022-25804MEDIUM5.5An issue was discovered in the IGEL Universal Management Suite (UMS) 6.07.100. Insecure permissions for the serverconfig...
CVE-2022-30875MEDIUM6.1Dolibarr 12.0.5 is vulnerable to Cross Site Scripting (XSS) via Sql Error Page.
CVE-2022-28386MEDIUM4.6An issue was discovered in certain Verbatim drives through 2022-03-31. The security feature for lockout (e.g., requiring...
CVE-2022-32273MEDIUM4.3As a result of an observable discrepancy in returned messages, OPSWAT MetaDefender Core (MDCore) before 5.1.2 could allo...
CVE-2022-30899MEDIUM4.8A Cross Site Scripting vulnerabilty exists in PartKeepr 1.4.0 via the 'name' field in /api/part_categories.
CVE-2022-28387MEDIUM4.6An issue was discovered in certain Verbatim drives through 2022-03-31. Due to an insecure design, they can be unlocked b...
CVE-2022-28385MEDIUM4.6An issue was discovered in certain Verbatim drives through 2022-03-31. Due to missing integrity checks, an attacker can ...
CVE-2022-28384MEDIUM5.5An issue was discovered in certain Verbatim drives through 2022-03-31. Due to an insecure design, they allow an offline ...
CVE-2022-28383MEDIUM6.8An issue was discovered in certain Verbatim drives through 2022-03-31. Due to insufficient firmware validation, an attac...
CVE-2022-1997MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository francoisjacquet/rosariosis prior to 9.0.
CVE-2022-30552MEDIUM5.5Das U-Boot 2022.01 has a Buffer Overflow.
CVE-2022-31497MEDIUM6.1LibreHealth EHR Base 2.0.0 allows interface/main/finder/finder_navigation.php patient XSS.

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now