2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-21131MEDIUM5.5Improper access control for some Intel(R) Xeon(R) Processors may allow an authenticated user to potentially enable infor...
CVE-2022-0004MEDIUM6.8Hardware debug modes and processor INIT setting that allow override of locks for some Intel(R) Processors in Intel(R) Bo...
CVE-2022-29302MEDIUM5.5SolarView Compact ver.6.00 was discovered to contain a local file disclosure via /html/Solar_Ftp.php.
CVE-2022-28920MEDIUM4.8Tieba-Cloud-Sign v4.9 was discovered to contain a cross-site scripting (XSS) vulnerability via the function strip_tags.
CVE-2022-28919MEDIUM6.1HTMLCreator release_stable_2020-07-29 was discovered to contain a cross-site scripting (XSS) vulnerability via the funct...
CVE-2022-29538MEDIUM5.3RESI Gemini-Net Web 4.2 is affected by Improper Access Control in authorization logic. An unauthenticated user is able t...
CVE-2022-28873MEDIUM4.3A vulnerability affecting F-Secure SAFE browser was discovered. An attacker can potentially exploit Javascript window.op...
CVE-2022-1674MEDIUM5.5NULL Pointer Dereference in function vim_regexec_string at regexp.c:2733 in GitHub repository vim/vim prior to 8.2.4938....
CVE-2022-29930MEDIUM4.9SHA1 implementation in JetBrains Ktor Native 2.0.0 was returning the same value. The issue was fixed in Ktor version 2.0...
CVE-2022-29929MEDIUM6.1In JetBrains TeamCity before 2022.04 potential XSS via Referrer header was possible
CVE-2022-29928MEDIUM4.9In JetBrains TeamCity before 2022.04 leak of secrets in TeamCity agent logs was possible
CVE-2022-29927MEDIUM6.1In JetBrains TeamCity before 2022.04 reflected XSS on the Build Chain Status page was possible
CVE-2022-1682MEDIUM6.1Reflected Xss using url based payload in GitHub repository neorazorx/facturascripts prior to 2022.07. Xss can use to ste...
CVE-2022-1044MEDIUM6.5Sensitive Data Exposure Due To Insecure Storage Of Profile Image in GitHub repository polonel/trudesk prior to v1.2.1.
CVE-2022-29855MEDIUM6.8Mitel 6800 and 6900 Series SIP phone devices through 2022-04-27 have "undocumented functionality." A vulnerability in Mi...
CVE-2022-30062MEDIUM6.5ftcms <=2.1 was discovered to be vulnerable to Arbitrary File Read via tp.php
CVE-2022-30061MEDIUM6.5ftcms <=2.1 was discovered to be vulnerable to directory traversal attacks via the parameter tp.
CVE-2022-30059MEDIUM6.5Shopwind <=v3.4.2 was discovered to contain a Arbitrary File Delete vulnerability via the neirong parameter at \backend\...
CVE-2022-30058MEDIUM5.3Shopwind <=v3.4.2 was discovered to contain a Arbitrary File Download vulnerability via the neirong parameter at \backen...
CVE-2022-30057MEDIUM5.4Shopwind <=v3.4.2 was discovered to contain a stored cross-site scripting (XSS) vulnerability.
CVE-2022-29848MEDIUM6.5In Progress Ipswitch WhatsUp Gold 17.0.0 through 21.1.1, and 22.0.0, it is possible for an authenticated user to invoke ...
CVE-2022-29846MEDIUM5.3In Progress Ipswitch WhatsUp Gold 16.1 through 21.1.1, and 22.0.0, it is possible for an unauthenticated attacker to obt...
CVE-2022-29845MEDIUM6.5In Progress Ipswitch WhatsUp Gold 21.1.0 through 21.1.1, and 22.0.0, it is possible for an authenticated user to invoke ...
CVE-2022-28837MEDIUM5.5Acrobat Pro DC version 22.001.2011x (and earlier), 20.005.3033x (and earlier) and 17.012.3022x (and earlier) are affecte...
CVE-2022-28267MEDIUM5.5Acrobat Reader DC version 22.001.2011x (and earlier), 20.005.3033x (and earlier) and 17.012.3022x (and earlier) are affe...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now