2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-21230MEDIUM5.5This affects all versions of package org.nanohttpd:nanohttpd. Whenever an HTTP Session is parsing the body of an HTTP re...
CVE-2022-23061MEDIUM6.5In Shopizer versions 2.0 to 2.17.0 a regular admin can permanently delete a superadmin (although this cannot happen acco...
CVE-2022-23060MEDIUM4.8A Stored Cross Site Scripting (XSS) vulnerability exists in Shopizer versions 2.0 through 2.17.0, where a privileged use...
CVE-2022-29947MEDIUM6.1Woodpecker before 0.15.1 allows XSS via build logs because web/src/components/repo/build/BuildLog.vue lacks escaping.
CVE-2022-28198MEDIUM6.8NVIDIA Omniverse Nucleus and Cache contain a vulnerability in its configuration of OpenSSL, where an attacker with physi...
CVE-2022-25854MEDIUM5.4This affects the package @yaireo/tagify before 4.9.8. The package is used for rendering UI components inside the input o...
CVE-2022-29414MEDIUM5.4Multiple (13x) Cross-Site Request Forgery (CSRF) vulnerabilities in WPKube's Subscribe To Comments Reloaded plugin <= 21...
CVE-2022-0984MEDIUM4.3Users with the capability to configure badge criteria (teachers and managers by default) were able to configure course b...
CVE-2022-1195MEDIUM5.5A use-after-free vulnerability was found in the Linux kernel in drivers/net/hamradio. This flaw allows a local attacker ...
CVE-2022-1015MEDIUM6.6A flaw was found in the Linux kernel in linux/net/netfilter/nf_tables_api.c of the netfilter subsystem. This flaw allows...
CVE-2022-0985MEDIUM4.3Insufficient capability checks could allow users with the moodle/site:uploadusers capability to delete users, without ha...
CVE-2022-1536MEDIUM5.4A vulnerability has been found in automad up to 1.10.9 and classified as problematic. This vulnerability affects the Das...
CVE-2022-1530MEDIUM6.1Cross-site Scripting (XSS) in GitHub repository livehelperchat/livehelperchat prior to 3.99v. The attacker can execute m...
CVE-2022-1526MEDIUM5.4A vulnerability, which was classified as problematic, was found in Emlog Pro up to 1.2.2. This affects the POST paramete...
CVE-2022-29907MEDIUM6.1The Nimbus skin for MediaWiki through 1.37.2 (before 6f9c8fb868345701d9544a54d9752515aace39df) allows XSS in Advertise l...
CVE-2022-29905MEDIUM4.3The FanBoxes extension for MediaWiki through 1.37.2 (before 027ffb0b9d6fe0d823810cf03f5b562a212162d4) allows Special:Use...
CVE-2022-29903MEDIUM4.3The Private Domains extension for MediaWiki through 1.37.2 (before 1ad65d4c1c199b375ea80988d99ab51ae068f766) allows CSRF...
CVE-2022-28477MEDIUM6.1WBCE CMS 1.5.2 is vulnerable to Cross Site Scripting (XSS).
CVE-2022-28454MEDIUM6.1Limbas 4.3.36.1319 is vulnerable to Cross Site Scripting (XSS).
CVE-2022-24898MEDIUM4.9org.xwiki.commons:xwiki-commons-xml is a common module used by other XWiki top level projects. Starting in version 2.7 a...
CVE-2022-29413MEDIUM6.1Cross-Site Request Forgery (CSRF) leading to Stored Cross-Site Scripting (XSS) in Mufeng's Hermit 音乐播放器 plugin <= 3.1.6 ...
CVE-2022-29412MEDIUM5.4Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in Hermit 音乐播放器 plugin <= 3.1.6 on WordPress allow attackers ...
CVE-2022-29584MEDIUM5.4Mahara before 20.10.5, 21.04.4, 21.10.2, and 22.04.0 allows stored XSS when a particular Cascading Style Sheets (CSS) cl...
CVE-2022-29415MEDIUM6.1Unauthenticated Reflected Cross-Site Scripting (XSS) vulnerability in Mati Skiba @ Rav Messer's Ravpage plugin <= 2.16 a...
CVE-2022-27860MEDIUM6.1Cross-Site Request Forgery (CSRF) leading to Cross-Site Scripting (XSS) in Shea Bunge's Footer Text plugin <= 2.0.3 on W...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now