2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-29433 | MEDIUM | 5.4 | 0.5% | May 13, 2022 | Authenticated (contributor or higher role) Cross-Site Scripting (XSS) vulnerability in Donations plugin <= 1.8 on WordPr... |
| CVE-2022-30408 | MEDIUM | 6.5 | 0.9% | May 13, 2022 | Covid-19 Travel Pass Management System v1.0 is vulnerable to file deletion via /ctpms/classes/Master.php?f=delete_img. |
| CVE-2022-30381 | MEDIUM | 6.5 | 0.9% | May 13, 2022 | Merchandise Online Store v1.0 is vulnerable to file deletion via /vloggers_merch/classes/Master.php?f=delete_img. |
| CVE-2022-28830 | MEDIUM | 5.5 | 1.7% | May 13, 2022 | Adobe Framemaker versions 2029u8 (and earlier) and 2020u4 (and earlier) are affected by an out-of-bounds read vulnerabil... |
| CVE-2022-27247 | MEDIUM | 5.3 | 0.9% | May 13, 2022 | onlinetolls in cdSoft Onlinetools-Smart Winhotel.MX 2021 allows an attacker to download sensitive information about any ... |
| CVE-2022-30375 | MEDIUM | 6.5 | 0.8% | May 13, 2022 | Sourcecodester Simple Social Networking Site v1.0 is vulnerable to file deletion via /sns/classes/Master.php?f=delete_im... |
| CVE-2022-30367 | MEDIUM | 6.5 | 0.8% | May 13, 2022 | Air Cargo Management System v1.0 is vulnerable to file deletion via /acms/classes/Master.php?f=delete_img. |
| CVE-2022-29854 | MEDIUM | 6.8 | 0.6% | May 13, 2022 | A vulnerability in Mitel 6900 Series IP (MiNet) phones excluding 6970, versions 1.8 (1.8.0.12) and earlier, could allow ... |
| CVE-2022-30489 | MEDIUM | 6.1 | 3.8% | May 13, 2022 | WAVLINK WN535 G3 was discovered to contain a cross-site scripting (XSS) vulnerability via the hostname parameter at /cgi... |
| CVE-2022-23165 | MEDIUM | 6.1 | 0.4% | May 12, 2022 | Sysaid – Sysaid 14.2.0 Reflected Cross-Site Scripting (XSS) - The parameter "helpPageName" used by the page "/help/treec... |
| CVE-2022-22971 | MEDIUM | 6.5 | 2.9% | May 12, 2022 | In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, application with a STOMP over WebS... |
| CVE-2022-22970 | MEDIUM | 5.3 | 1.9% | May 12, 2022 | In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, applications that handle file uplo... |
| CVE-2022-22797 | MEDIUM | 6.1 | 0.5% | May 12, 2022 | Sysaid – sysaid Open Redirect - An Attacker can change the redirect link at the parameter "redirectURL" from"GET" reques... |
| CVE-2022-28818 | MEDIUM | 6.1 | 41.2% | May 12, 2022 | ColdFusion versions CF2021U3 (and earlier) and CF2018U13 are affected by a reflected Cross-Site Scripting (XSS) vulnerab... |
| CVE-2022-26510 | MEDIUM | 6.5 | 1.2% | May 12, 2022 | A firmware update vulnerability exists in the iburn firmware checks functionality of InHand Networks InRouter302 V3.5.37... |
| CVE-2022-26020 | MEDIUM | 6.5 | 0.6% | May 12, 2022 | An information disclosure vulnerability exists in the router configuration export functionality of InHand Networks InRou... |
| CVE-2022-25172 | MEDIUM | 6.1 | 0.9% | May 12, 2022 | An information disclosure vulnerability exists in the web interface session cookie functionality of InHand Networks InRo... |
| CVE-2022-24910 | MEDIUM | 6.7 | 1.3% | May 12, 2022 | A buffer overflow vulnerability exists in the httpd parse_ping_result API functionality of InHand Networks InRouter302 V... |
| CVE-2022-24382 | MEDIUM | 6.7 | 0.2% | May 12, 2022 | Improper input validation in firmware for some Intel(R) NUCs may allow a privileged user to potentially enable escalatio... |
| CVE-2022-24297 | MEDIUM | 6.7 | 0.2% | May 12, 2022 | Improper buffer restrictions in firmware for some Intel(R) NUCs may allow a privileged user to potentially enable escala... |
| CVE-2022-21238 | MEDIUM | 6.1 | 1.4% | May 12, 2022 | A cross-site scripting (xss) vulnerability exists in the info.jsp functionality of InHand Networks InRouter302 V3.5.4. A... |
| CVE-2022-21237 | MEDIUM | 6.7 | 0.2% | May 12, 2022 | Improper buffer access in firmware for some Intel(R) NUCs may allow a privileged user to potentially enable escalation o... |
| CVE-2022-21151 | MEDIUM | 5.5 | 0.3% | May 12, 2022 | Processor optimization removal or modification of security-critical code for some Intel(R) Processors may allow an authe... |
| CVE-2022-21147 | MEDIUM | 5.5 | 0.6% | May 12, 2022 | An out of bounds read vulnerability exists in the malware scan functionality of ESTsoft Alyac 2.5.7.7. A specially-craft... |
| CVE-2022-21136 | MEDIUM | 5.5 | 0.3% | May 12, 2022 | Improper input validation for some Intel(R) Xeon(R) Processors may allow a privileged user to potentially enable denial ... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now