2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-21230 | MEDIUM | 5.5 | 0.3% | May 1, 2022 | This affects all versions of package org.nanohttpd:nanohttpd. Whenever an HTTP Session is parsing the body of an HTTP re... |
| CVE-2022-23061 | MEDIUM | 6.5 | 1.1% | May 1, 2022 | In Shopizer versions 2.0 to 2.17.0 a regular admin can permanently delete a superadmin (although this cannot happen acco... |
| CVE-2022-23060 | MEDIUM | 4.8 | 0.6% | May 1, 2022 | A Stored Cross Site Scripting (XSS) vulnerability exists in Shopizer versions 2.0 through 2.17.0, where a privileged use... |
| CVE-2022-29947 | MEDIUM | 6.1 | 0.6% | Apr 29, 2022 | Woodpecker before 0.15.1 allows XSS via build logs because web/src/components/repo/build/BuildLog.vue lacks escaping. |
| CVE-2022-28198 | MEDIUM | 6.8 | 0.3% | Apr 29, 2022 | NVIDIA Omniverse Nucleus and Cache contain a vulnerability in its configuration of OpenSSL, where an attacker with physi... |
| CVE-2022-25854 | MEDIUM | 5.4 | 0.9% | Apr 29, 2022 | This affects the package @yaireo/tagify before 4.9.8. The package is used for rendering UI components inside the input o... |
| CVE-2022-29414 | MEDIUM | 5.4 | 0.4% | Apr 29, 2022 | Multiple (13x) Cross-Site Request Forgery (CSRF) vulnerabilities in WPKube's Subscribe To Comments Reloaded plugin <= 21... |
| CVE-2022-0984 | MEDIUM | 4.3 | 0.5% | Apr 29, 2022 | Users with the capability to configure badge criteria (teachers and managers by default) were able to configure course b... |
| CVE-2022-1195 | MEDIUM | 5.5 | 0.2% | Apr 29, 2022 | A use-after-free vulnerability was found in the Linux kernel in drivers/net/hamradio. This flaw allows a local attacker ... |
| CVE-2022-1015 | MEDIUM | 6.6 | 1.5% | Apr 29, 2022 | A flaw was found in the Linux kernel in linux/net/netfilter/nf_tables_api.c of the netfilter subsystem. This flaw allows... |
| CVE-2022-0985 | MEDIUM | 4.3 | 0.5% | Apr 29, 2022 | Insufficient capability checks could allow users with the moodle/site:uploadusers capability to delete users, without ha... |
| CVE-2022-1536 | MEDIUM | 5.4 | 0.6% | Apr 29, 2022 | A vulnerability has been found in automad up to 1.10.9 and classified as problematic. This vulnerability affects the Das... |
| CVE-2022-1530 | MEDIUM | 6.1 | 0.6% | Apr 29, 2022 | Cross-site Scripting (XSS) in GitHub repository livehelperchat/livehelperchat prior to 3.99v. The attacker can execute m... |
| CVE-2022-1526 | MEDIUM | 5.4 | 0.6% | Apr 29, 2022 | A vulnerability, which was classified as problematic, was found in Emlog Pro up to 1.2.2. This affects the POST paramete... |
| CVE-2022-29907 | MEDIUM | 6.1 | 0.6% | Apr 29, 2022 | The Nimbus skin for MediaWiki through 1.37.2 (before 6f9c8fb868345701d9544a54d9752515aace39df) allows XSS in Advertise l... |
| CVE-2022-29905 | MEDIUM | 4.3 | 0.4% | Apr 29, 2022 | The FanBoxes extension for MediaWiki through 1.37.2 (before 027ffb0b9d6fe0d823810cf03f5b562a212162d4) allows Special:Use... |
| CVE-2022-29903 | MEDIUM | 4.3 | 0.3% | Apr 29, 2022 | The Private Domains extension for MediaWiki through 1.37.2 (before 1ad65d4c1c199b375ea80988d99ab51ae068f766) allows CSRF... |
| CVE-2022-28477 | MEDIUM | 6.1 | 0.9% | Apr 28, 2022 | WBCE CMS 1.5.2 is vulnerable to Cross Site Scripting (XSS). |
| CVE-2022-28454 | MEDIUM | 6.1 | 1.1% | Apr 28, 2022 | Limbas 4.3.36.1319 is vulnerable to Cross Site Scripting (XSS). |
| CVE-2022-24898 | MEDIUM | 4.9 | 1.4% | Apr 28, 2022 | org.xwiki.commons:xwiki-commons-xml is a common module used by other XWiki top level projects. Starting in version 2.7 a... |
| CVE-2022-29413 | MEDIUM | 6.1 | 0.4% | Apr 28, 2022 | Cross-Site Request Forgery (CSRF) leading to Stored Cross-Site Scripting (XSS) in Mufeng's Hermit 音乐播放器 plugin <= 3.1.6 ... |
| CVE-2022-29412 | MEDIUM | 5.4 | 0.4% | Apr 28, 2022 | Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in Hermit 音乐播放器 plugin <= 3.1.6 on WordPress allow attackers ... |
| CVE-2022-29584 | MEDIUM | 5.4 | 0.5% | Apr 28, 2022 | Mahara before 20.10.5, 21.04.4, 21.10.2, and 22.04.0 allows stored XSS when a particular Cascading Style Sheets (CSS) cl... |
| CVE-2022-29415 | MEDIUM | 6.1 | 0.7% | Apr 28, 2022 | Unauthenticated Reflected Cross-Site Scripting (XSS) vulnerability in Mati Skiba @ Rav Messer's Ravpage plugin <= 2.16 a... |
| CVE-2022-27860 | MEDIUM | 6.1 | 0.4% | Apr 28, 2022 | Cross-Site Request Forgery (CSRF) leading to Cross-Site Scripting (XSS) in Shea Bunge's Footer Text plugin <= 2.0.3 on W... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now