2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-22443MEDIUM5.4IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed a...
CVE-2022-22441MEDIUM6.5IBM InfoSphere Information Server 11.7 could allow an authenticated user to view information of higher privileged users ...
CVE-2022-22427MEDIUM6.1IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed a...
CVE-2022-22322MEDIUM5.4IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed a...
CVE-2022-1514MEDIUM5.4Stored XSS via upload plugin functionality in zip format in GitHub repository neorazorx/facturascripts prior to 2022.06....
CVE-2022-28117MEDIUM4.9A Server-Side Request Forgery (SSRF) in feed_parser class of Navigate CMS v2.9.4 allows remote attackers to force the ap...
CVE-2022-1511MEDIUM6.5Missing Authorization in GitHub repository snipe/snipe-it prior to 5.4.4.
CVE-2022-28102MEDIUM5.4A cross-site scripting (XSS) vulnerability in PHP MySQL Admin Panel Generator v1 allows attackers to execute arbitrary w...
CVE-2022-24873MEDIUM6.1Shopware is an open source e-commerce software platform. Prior to version 5.7.9, Shopware is vulnerable to non-stored cr...
CVE-2022-29152MEDIUM6.1The Ericom PowerTerm WebConnect 6.0 login portal can unsafely write an XSS payload from the AppPortal cookie into the pa...
CVE-2022-29817MEDIUM6.1In JetBrains IntelliJ IDEA before 2022.1 reflected XSS via error messages in internal web server was possible
CVE-2022-29815MEDIUM6.7In JetBrains IntelliJ IDEA before 2022.1 local code execution via workspace settings was possible
CVE-2022-29813MEDIUM6.7In JetBrains IntelliJ IDEA before 2022.1 local code execution via custom Pandoc path was possible
CVE-2022-29811MEDIUM4.8In JetBrains Hub before 2022.1.14638 stored XSS via project icon was possible.
CVE-2022-29869MEDIUM5.3cifs-utils through 6.14, with verbose logging, can cause an information leak when a file contains = (equal sign) charact...
CVE-2022-24891MEDIUM6.1ESAPI (The OWASP Enterprise Security API) is a free, open source, web application security control library. Prior to ver...
CVE-2022-24736MEDIUM5.5Redis is an in-memory database that persists on disk. Prior to versions 6.2.7 and 7.0.0, an attacker attempting to load ...
CVE-2022-28197MEDIUM5NVIDIA Jetson Linux Driver Package contains a vulnerability in the Cboot ext4_mount function, where Insufficient validat...
CVE-2022-28196MEDIUM4.6NVIDIA Jetson Linux Driver Package contains a vulnerability in the Cboot blob_decompress function, where insufficient va...
CVE-2022-28195MEDIUM5.7NVIDIA Jetson Linux Driver Package contains a vulnerability in the Cboot ext4_read_file function, where insufficient val...
CVE-2022-28194MEDIUM5.6NVIDIA Jetson Linux Driver Package contains a vulnerability in the Cboot module tegrabl_cbo.c, where, if TFTP is enabled...
CVE-2022-28193MEDIUM5.6NVIDIA Jetson Linux Driver Package contains a vulnerability in the Cboot module tegrabl_cbo.c, where insufficient valida...
CVE-2022-24372MEDIUM4.6Linksys MR9600 devices before 2.0.5 allow attackers to read arbitrary files via a symbolic link to the root directory of...
CVE-2022-23822MEDIUM6.8In this physical attack, an attacker may potentially exploit the Zynq-7000 SoC First Stage Boot Loader (FSBL) by bypassi...
CVE-2022-22277MEDIUM5.3A vulnerability in SonicOS SNMP service resulting exposure of Wireless Access Point sensitive information in cleartext.

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now