2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-29433MEDIUM5.4Authenticated (contributor or higher role) Cross-Site Scripting (XSS) vulnerability in Donations plugin <= 1.8 on WordPr...
CVE-2022-30408MEDIUM6.5Covid-19 Travel Pass Management System v1.0 is vulnerable to file deletion via /ctpms/classes/Master.php?f=delete_img.
CVE-2022-30381MEDIUM6.5Merchandise Online Store v1.0 is vulnerable to file deletion via /vloggers_merch/classes/Master.php?f=delete_img.
CVE-2022-28830MEDIUM5.5Adobe Framemaker versions 2029u8 (and earlier) and 2020u4 (and earlier) are affected by an out-of-bounds read vulnerabil...
CVE-2022-27247MEDIUM5.3onlinetolls in cdSoft Onlinetools-Smart Winhotel.MX 2021 allows an attacker to download sensitive information about any ...
CVE-2022-30375MEDIUM6.5Sourcecodester Simple Social Networking Site v1.0 is vulnerable to file deletion via /sns/classes/Master.php?f=delete_im...
CVE-2022-30367MEDIUM6.5Air Cargo Management System v1.0 is vulnerable to file deletion via /acms/classes/Master.php?f=delete_img.
CVE-2022-29854MEDIUM6.8A vulnerability in Mitel 6900 Series IP (MiNet) phones excluding 6970, versions 1.8 (1.8.0.12) and earlier, could allow ...
CVE-2022-30489MEDIUM6.1WAVLINK WN535 G3 was discovered to contain a cross-site scripting (XSS) vulnerability via the hostname parameter at /cgi...
CVE-2022-23165MEDIUM6.1Sysaid – Sysaid 14.2.0 Reflected Cross-Site Scripting (XSS) - The parameter "helpPageName" used by the page "/help/treec...
CVE-2022-22971MEDIUM6.5In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, application with a STOMP over WebS...
CVE-2022-22970MEDIUM5.3In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, applications that handle file uplo...
CVE-2022-22797MEDIUM6.1Sysaid – sysaid Open Redirect - An Attacker can change the redirect link at the parameter "redirectURL" from"GET" reques...
CVE-2022-28818MEDIUM6.1ColdFusion versions CF2021U3 (and earlier) and CF2018U13 are affected by a reflected Cross-Site Scripting (XSS) vulnerab...
CVE-2022-26510MEDIUM6.5A firmware update vulnerability exists in the iburn firmware checks functionality of InHand Networks InRouter302 V3.5.37...
CVE-2022-26020MEDIUM6.5An information disclosure vulnerability exists in the router configuration export functionality of InHand Networks InRou...
CVE-2022-25172MEDIUM6.1An information disclosure vulnerability exists in the web interface session cookie functionality of InHand Networks InRo...
CVE-2022-24910MEDIUM6.7A buffer overflow vulnerability exists in the httpd parse_ping_result API functionality of InHand Networks InRouter302 V...
CVE-2022-24382MEDIUM6.7Improper input validation in firmware for some Intel(R) NUCs may allow a privileged user to potentially enable escalatio...
CVE-2022-24297MEDIUM6.7Improper buffer restrictions in firmware for some Intel(R) NUCs may allow a privileged user to potentially enable escala...
CVE-2022-21238MEDIUM6.1A cross-site scripting (xss) vulnerability exists in the info.jsp functionality of InHand Networks InRouter302 V3.5.4. A...
CVE-2022-21237MEDIUM6.7Improper buffer access in firmware for some Intel(R) NUCs may allow a privileged user to potentially enable escalation o...
CVE-2022-21151MEDIUM5.5Processor optimization removal or modification of security-critical code for some Intel(R) Processors may allow an authe...
CVE-2022-21147MEDIUM5.5An out of bounds read vulnerability exists in the malware scan functionality of ESTsoft Alyac 2.5.7.7. A specially-craft...
CVE-2022-21136MEDIUM5.5Improper input validation for some Intel(R) Xeon(R) Processors may allow a privileged user to potentially enable denial ...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now