2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-29779MEDIUM5.5Nginx NJS v0.7.2 was discovered to contain a segmentation violation in the function njs_value_own_enumerate at src/njs_v...
CVE-2022-29734MEDIUM5.4A cross-site scripting (XSS) vulnerability in ICT Protege GX/WX v2.08 allows authenticated attackers to execute arbitrar...
CVE-2022-29733MEDIUM5.9Delta Controls enteliTOUCH 3.40.3935, 3.40.3706, and 3.33.4005 was discovered to transmit and store sensitive informatio...
CVE-2022-29732MEDIUM6.1Delta Controls enteliTOUCH 3.40.3935, 3.40.3706, and 3.33.4005 was discovered to contain a cross-site scripting (XSS) vu...
CVE-2022-29731MEDIUM4.3An access control issue in ICT Protege GX/WX 2.08 allows attackers to leak SHA1 password hashes of other users.
CVE-2022-29711MEDIUM6.1LibreNMS v22.3.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /Table/GraylogCo...
CVE-2022-29653MEDIUM6.1OFCMS v1.1.4 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /admin/comn/service/...
CVE-2022-29648MEDIUM5.4A cross-site scripting (XSS) vulnerability in Jfinal CMS v5.1.0 allows attackers to execute arbitrary web scripts or HTM...
CVE-2022-29628MEDIUM5.4A cross-site scripting (XSS) vulnerability in /omps/seller of Online Market Place Site v1.0 allows attackers to execute ...
CVE-2022-29627MEDIUM4.3An insecure direct object reference (IDOR) in Online Market Place Site v1.0 allows attackers to modify products that are...
CVE-2022-29598MEDIUM6.1Solutions Atlantic Regulatory Reporting System (RRS) v500 is vulnerable to an reflected Cross-Site Scripting (XSS) vulne...
CVE-2022-29540MEDIUM6.1resi-calltrace in RESI Gemini-Net 4.2 is affected by Multiple XSS issues. Unauthenticated remote attackers can inject ar...
CVE-2022-28702MEDIUM5.5Incorrect Default Permissions vulnerability in ABB e-Design allows attacker to install malicious software executing with...
CVE-2022-27779MEDIUM5.3libcurl wrongly allows cookies to be set for Top Level Domains (TLDs) if thehost name is provided with a trailing dot.cu...
CVE-2022-27776MEDIUM6.5A insufficiently protected credentials vulnerability in fixed in curl 7.83.0 might leak authentication or cookie header ...
CVE-2022-27774MEDIUM5.7An insufficiently protected credentials vulnerability exists in curl 4.9 to and include curl 7.82.0 are affected that co...
CVE-2022-26978MEDIUM6.1Barco Control Room Management Suite web application, which is part of TransForm N before 3.14, is exposing a URL /checkl...
CVE-2022-26977MEDIUM6.1Barco Control Room Management Suite web application, which is part of TransForm N before 3.14, is exposing a license fil...
CVE-2022-26976MEDIUM5.4Barco Control Room Management Suite web application, which is part of TransForm N before 3.14, is exposing a license fil...
CVE-2022-26974MEDIUM6.1Barco Control Room Management Suite web application, which is part of TransForm N before 3.14, is exposing a file upload...
CVE-2022-26973MEDIUM5.3Barco Control Room Management Suite web application, which is part of TransForm N before 3.14, is exposing a license fil...
CVE-2022-26972MEDIUM6.1Barco Control Room Management Suite web application, which is part of TransForm N before 3.14, is exposing a URL /cgi-bi...
CVE-2022-26971MEDIUM5.3Barco Control Room Management Suite web application, which is part of TransForm N before 3.14, is exposing a license fil...
CVE-2022-26491MEDIUM5.9An issue was discovered in Pidgin before 2.14.9. A remote attacker who can spoof DNS responses can redirect a client con...
CVE-2022-24967MEDIUM5.4Black Rainbow NIMBUS before 3.7.0 allows stored Cross-site Scripting (XSS).

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now