2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-1389MEDIUM4.3On all versions of 16.1.x, 15.1.x, 14.1.x, 13.1.x, 12.1.x, and 11.6.x of F5 BIG-IP (fixed in 17.0.0), a cross-site reque...
CVE-2022-22434MEDIUM4.6IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 could allow a user with physical access to create an API reque...
CVE-2022-22415MEDIUM6.5A vulnerability exists where an IBM Robotic Process Automation 21.0.1 regular user is able to obtain view-only access to...
CVE-2022-1516MEDIUM5.5A NULL pointer dereference flaw was found in the Linux kernel’s X.25 set of standardized network protocols functionality...
CVE-2022-1464MEDIUM5.4Stored xss bug in GitHub repository gogs/gogs prior to 0.12.7. As the repo is public , any user can view the report and ...
CVE-2022-28471MEDIUM6.5In ffjpeg (commit hash: caade60), the function bmp_load() in bmp.c contains an integer overflow vulnerability, which eve...
CVE-2022-29940MEDIUM5.4In LibreHealth EHR 2.0.0, lack of sanitization of the GET parameters formseq and formid in interface\orders\find_order_p...
CVE-2022-29939MEDIUM5.4In LibreHealth EHR 2.0.0, lack of sanitization of the GET parameters debug and InsId in interface\billing\sl_eob_process...
CVE-2022-1411MEDIUM6.1Unrestructed file upload in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0. Attacker can send malicious ...
CVE-2022-1590MEDIUM5.4A vulnerability was found in Bludit 3.13.1. It has been declared as problematic. This vulnerability affects the endpoint...
CVE-2022-30241MEDIUM6.1The jquery.json-viewer library through 1.4.0 for Node.js does not properly escape characters such as < in a JSON object,...
CVE-2022-29943MEDIUM6.5Talend Administration Center has a vulnerability that allows an authenticated user to use XML External Entity (XXE) proc...
CVE-2022-29942MEDIUM6.5Talend Administration Center has a vulnerability that allows an authenticated user to use the Service Registry 'Add' fun...
CVE-2022-25786MEDIUM4.9Unprotected Alternate Channel vulnerability in debug console of GateManager allows system administrator to obtain sensit...
CVE-2022-1584MEDIUM6.1Reflected XSS in GitHub repository microweber/microweber prior to 1.2.16. Executing JavaScript as the victim
CVE-2022-20796MEDIUM5.5On May 4, 2022, the following vulnerability in the ClamAV scanning library versions 0.103.5 and earlier and 0.104.2 and ...
CVE-2022-20794MEDIUM4.7Multiple vulnerabilities in the web engine of Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS S...
CVE-2022-20734MEDIUM4.4A vulnerability in Cisco SD-WAN vManage Software could allow an authenticated, local attacker to view sensitive informat...
CVE-2022-29950MEDIUM4.3Experian Hunter 1.16 allows remote authenticated users to modify assumed-immutable elements via the (1) rule name parame...
CVE-2022-27461MEDIUM6.1In nopCommerce 4.50.1, an open redirect vulnerability can be triggered by luring a user to authenticate to a nopCommerce...
CVE-2022-28508MEDIUM6.1An XSS issue was discovered in browser_search_plugin.php in MantisBT before 2.25.2. Unescaped output of the return param...
CVE-2022-28090MEDIUM6.5Jspxcms v10.2.0 allows attackers to execute a Server-Side Request Forgery (SSRF) via /cmscp/ext/collect/fetch_url.do?url...
CVE-2022-28081MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability in the component Query.php of arPHP v3.6.0 allows attackers to exec...
CVE-2022-25787MEDIUM6.7Information Exposure Through Query Strings in GET Request vulnerability in LMM API of Secomea GateManager allows system ...
CVE-2022-25784MEDIUM4.8Cross-site Scripting (XSS) vulnerability in Web GUI of SiteManager allows logged-in user to inject scripting. This issue...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now