2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-22276MEDIUM5.3A vulnerability in SonicOS SNMP service resulting exposure of sensitive information to an unauthorized user.
CVE-2022-1507MEDIUM5.5chafa: NULL Pointer Dereference in function gif_internal_decode_frame at libnsgif.c:599 allows attackers to cause a deni...
CVE-2022-22345MEDIUM4.8IBM QRadar 7.3, 7.4, and 7.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary J...
CVE-2022-22323MEDIUM6.5IBM Security Identity Manager (IBM Security Verify Password Synchronization Plug-in for Windows AD 10.x) is vulnerable t...
CVE-2022-22312MEDIUM6.5IBM Security Identity Manager (IBM Security Verify Password Synchronization Plug-in for Windows AD 10.x) is vulnerable t...
CVE-2022-24889MEDIUM4.3Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform. Prior to versions 21.0....
CVE-2022-24888MEDIUM4.3Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform. Prior to versions 20.0....
CVE-2022-24887MEDIUM6.1Nextcloud Talk is a video and audio conferencing app for Nextcloud, a self-hosted productivity platform. Prior to versio...
CVE-2022-1504MEDIUM6.1XSS in /demo/module/?module=HERE in GitHub repository microweber/microweber prior to 1.2.15. Typical impact of XSS attac...
CVE-2022-1503MEDIUM5.4A vulnerability, which was classified as problematic, has been found in GetSimple CMS. Affected by this issue is the fil...
CVE-2022-29810MEDIUM5.5The Hashicorp go-getter library before 1.5.11 does not redact an SSH key from a URL query parameter.
CVE-2022-27331MEDIUM4.3An access control issue in Zammad v5.0.3 broadcasts administrative configuration changes to all users who have an active...
CVE-2022-27888MEDIUM5.5Foundry Issues service versions 2.244.0 to 2.249.0 was found to be logging in a manner that captured sensitive informati...
CVE-2022-26564MEDIUM6.1HotelDruid Hotel Management Software v3.0.3 contains a cross-site scripting (XSS) vulnerability via the prezzoperiodo4 p...
CVE-2022-28522MEDIUM5.4ZCMS v20170206 was discovered to contain a stored cross-site scripting (XSS) vulnerability via index.php?m=home&c=messag...
CVE-2022-28450MEDIUM5.4nopCommerce 4.50.1 is vulnerable to Cross Site Scripting (XSS) via the "Text" parameter (forums) when creating a new pos...
CVE-2022-28449MEDIUM6.1nopCommerce 4.50.1 is vulnerable to Cross Site Scripting (XSS). At Apply for vendor account feature, an attacker can upl...
CVE-2022-28448MEDIUM5.4nopCommerce 4.50.1 is vulnerable to Cross Site Scripting (XSS). An attacker (role customer) can inject javascript code t...
CVE-2022-27854MEDIUM5.4Stored Cross-Site Scripting (XSS) vulnerability in Alexander Ustimenko's Psychological tests & quizzes plugin <= 0.21.19...
CVE-2022-24866MEDIUM4.3Discourse Assign is a plugin for assigning users to a topic in Discourse, an open-source messaging platform. Prior to ve...
CVE-2022-1466MEDIUM6.5Due to improper authorization, Red Hat Single Sign-On is vulnerable to users performing actions that they should not be ...
CVE-2022-28218MEDIUM5.5An issue was discovered in CipherMail Webmail Messenger 1.1.1 through 4.1.4. A local attacker could access secret keys (...
CVE-2022-1173MEDIUM5.4stored xss in GitHub repository getgrav/grav prior to 1.7.33.
CVE-2022-24880MEDIUM5.3flask-session-captcha is a package which allows users to extend Flask by adding an image based captcha stored in a serve...
CVE-2022-29418MEDIUM4.8Authenticated (admin user role) Persistent Cross-Site Scripting (XSS) in Mark Daniels Night Mode plugin <= 1.0.0 on Word...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now