2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-20629MEDIUM5.4Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could...
CVE-2022-20628MEDIUM5.4Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could...
CVE-2022-20627MEDIUM5.4Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could...
CVE-2022-29824MEDIUM6.5In libxml2 before 2.9.14, several buffer handling functions in buf.c (xmlBuf*) and tree.c (xmlBuffer*) don't check for i...
CVE-2022-24974MEDIUM5.3Links may not be rewritten according to policy in some specially formatted emails.
CVE-2022-23722MEDIUM6.5When a password reset mechanism is configured to use the Authentication API with an Authentication Policy, email One-Tim...
CVE-2022-29444MEDIUM5.4Plugin Settings Change leading to Cross-Site Scripting (XSS) vulnerability in Cloudways Breeze plugin <= 2.0.2 on WordPr...
CVE-2022-26326MEDIUM6.1Potential open redirection vulnerability when URL is crafted in specific format in NetIQ Access Manager prior to 5.0.2
CVE-2022-26325MEDIUM6.1Reflected Cross Site Scripting (XSS) vulnerability in NetIQ Access Manager prior to 5.0.2
CVE-2022-1515MEDIUM5.5A memory leak was discovered in matio 1.5.21 and earlier in Mat_VarReadNextInfo5() in mat5.c via a crafted file. This is...
CVE-2022-1475MEDIUM5.5An integer overflow vulnerability was found in FFmpeg versions before 4.4.2 and before 5.0.1 in g729_parse() in llibavco...
CVE-2022-1282MEDIUM6.1The Photo Gallery by 10Web WordPress plugin before 1.6.3 does not properly sanitize the $_GET['image_url'] variable, whi...
CVE-2022-1269MEDIUM6.1The Fast Flow WordPress plugin before 1.2.12 does not sanitise and escape the page parameter before outputting back in a...
CVE-2022-1255MEDIUM4.8The Import and export users and customers WordPress plugin before 1.19.2.1 does not sanitise and escaped imported CSV da...
CVE-2022-1250MEDIUM6.1The LifterLMS PayPal WordPress plugin before 1.4.0 does not sanitise and escape some parameters from the payment confirm...
CVE-2022-1046MEDIUM4.8The Visual Form Builder WordPress plugin before 3.0.7 does not sanitise and escape the form's 'Email to' field , which c...
CVE-2022-0662MEDIUM4.8The AdRotate WordPress plugin before 5.8.23 does not sanitise and escape Advert Names which could allow high privilege u...
CVE-2022-0649MEDIUM4.8The AdRotate WordPress plugin before 5.8.23 does not escape Group Names, which could allow high privilege users to perfo...
CVE-2022-0428MEDIUM6.1The Content Egg WordPress plugin before 5.3.0 does not sanitise and escape the page parameter before outputting back in ...
CVE-2022-0418MEDIUM4.8The Event List WordPress plugin before 0.8.8 does not sanitise and escape some of its settings, allowing high privilege ...
CVE-2022-0191MEDIUM6.5The Ad Invalid Click Protector (AICP) WordPress plugin before 1.2.7 does not have CSRF check deleting banned users, whic...
CVE-2022-23065MEDIUM5.4In Vendure versions 0.1.0-alpha.2 to 1.5.1 are affected by Stored XSS vulnerability, where an attacker having catalog pe...
CVE-2022-29973MEDIUM4.7relan exFAT 1.3.0 allows local users to obtain sensitive information (data from deleted files in the filesystem) in cert...
CVE-2022-29969MEDIUM6.1The RSS extension before 2022-04-29 for MediaWiki allows XSS via an rss element (if the feed is in $wgRSSUrlWhitelist an...
CVE-2022-25349MEDIUM5.4All versions of package materialize-css are vulnerable to Cross-site Scripting (XSS) due to improper escape of user inpu...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now