2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-21749MEDIUM5.5In telephony, there is a possible information disclosure due to a missing permission check. This could lead to local inf...
CVE-2022-21748MEDIUM5.5In telephony, there is a possible information disclosure due to a missing permission check. This could lead to local inf...
CVE-2022-21747MEDIUM4.4In imgsensor, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of s...
CVE-2022-21746MEDIUM4.4In imgsensor, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of s...
CVE-2022-31485MEDIUM5.3An unauthenticated attacker can send a specially crafted packets to update the “notes” section of the home page of the w...
CVE-2022-1940MEDIUM5.4A Stored Cross-Site Scripting vulnerability in Jira integration in GitLab EE affecting all versions from 13.11 prior to ...
CVE-2022-1936MEDIUM6.5Incorrect authorization in GitLab EE affecting all versions from 12.0 before 14.9.5, all versions starting from 14.10 be...
CVE-2022-1935MEDIUM6.5Incorrect authorization in GitLab EE affecting all versions from 12.0 before 14.9.5, all versions starting from 14.10 be...
CVE-2022-1821MEDIUM4.3An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.8 before 14.9.5, all versions start...
CVE-2022-30863MEDIUM4.8FUDForum 3.1.2 is vulnerable to Cross Site Scripting (XSS) via page_title param in Page Manager in the Admin Control Pan...
CVE-2022-30861MEDIUM4.8FUDforum 3.1.2 is vulnerable to Stored XSS via Forum Name field in Forum Manager Feature.
CVE-2022-29784MEDIUM5.3PublicCMS V4.0.202204.a and below contains an information leak via the component /views/directive/sys/SysConfigDataDirec...
CVE-2022-29773MEDIUM6.5An access control issue in aleksis/core/util/auth_helpers.py: ClientProtectedResourceMixin of AlekSIS-Core v2.8.1 and be...
CVE-2022-29770MEDIUM5.4XXL-Job v2.3.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via /xxl-job-admin/jobinfo.
CVE-2022-1988MEDIUM6.1Cross-site Scripting (XSS) - Generic in GitHub repository neorazorx/facturascripts prior to 2022.09.
CVE-2022-32265MEDIUM5.3qDecoder before 12.1.0 does not ensure that the percent character is followed by two hex digits for URL decoding.
CVE-2022-29767MEDIUM6.5adbyby v2.7 allows external users to make connections via port 8118. This can cause a program logic error and lead to a ...
CVE-2022-30233MEDIUM6.5A CWE-20: Improper Input Validation vulnerability exists that could allow the product to be maliciously manipulated when...
CVE-2022-31461MEDIUM6.5Owl Labs Meeting Owl 5.2.0.15 allows attackers to deactivate the passcode protection mechanism via a certain c 11 messag...
CVE-2022-31459MEDIUM6.5Owl Labs Meeting Owl 5.2.0.15 allows attackers to retrieve the passcode hash via a certain c 10 value over Bluetooth.
CVE-2022-29718MEDIUM6.1Caddy v2.4 was discovered to contain an open redirect vulnerability. A remote unauthenticated attacker may exploit this ...
CVE-2022-29085MEDIUM6.7Dell Unity, Dell UnityVSA, and Dell Unity XT versions prior to 5.2.0.0.5.173 contain a plain-text password storage vulne...
CVE-2022-26866MEDIUM5.5Dell PowerStore Versions before v2.1.1.0. contains a Stored Cross-Site Scripting vulnerability. A high privileged networ...
CVE-2022-31024MEDIUM6.5richdocuments is the repository for NextCloud Collabra, the app for Nextcloud Office collaboration. Prior to versions 6....
CVE-2022-30429MEDIUM5.4Multiple cross-site scripting (XSS) vulnerabilities in Neos CMS allow attackers with the editor role or higher to inject...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now