2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-27135MEDIUM5.5xpdf 4.03 has heap buffer overflow in the function readXRefTable located in XRef.cc. An attacker can exploit this bug to...
CVE-2022-27103MEDIUM6.1element-plus 2.0.5 is vulnerable to Cross Site Scripting (XSS) via el-table-column.
CVE-2022-1461MEDIUM6.5Non Privilege User can Enable or Disable Registered in GitHub repository openemr/openemr prior to 6.1.0.1.
CVE-2022-1458MEDIUM5.4Stored XSS Leads To Session Hijacking in GitHub repository openemr/openemr prior to 6.1.0.1.
CVE-2022-1457MEDIUM5.4Store XSS in title parameter executing at EditUser Page & EditProducto page in GitHub repository neorazorx/facturascript...
CVE-2022-1445MEDIUM5.4Stored Cross Site Scripting vulnerability in the checked_out_to parameter in GitHub repository snipe/snipe-it prior to 5...
CVE-2022-1444MEDIUM5.5heap-use-after-free in GitHub repository radareorg/radare2 prior to 5.7.0. This vulnerability is capable of inducing den...
CVE-2022-1108MEDIUM6.7A potential vulnerability due to improper buffer validation in the SMI handler LenovoFlashDeviceInterface in Thinkpad X1...
CVE-2022-1107MEDIUM6.7During an internal product security audit a potential vulnerability due to use of Boot Services in the SmmOEMInt15 SMI h...
CVE-2022-0636MEDIUM5.5A denial of service vulnerability was reported in Lenovo Thin Installer prior to version 1.3.0039 that could trigger a s...
CVE-2022-29589MEDIUM6.1Crypt Server before 3.3.0 allows XSS in the index view. This is related to serial, computername, and username.
CVE-2022-1439MEDIUM6.1Reflected XSS on demo.microweber.org/demo/module/ in GitHub repository microweber/microweber prior to 1.2.15. Execute Ar...
CVE-2022-28074MEDIUM4.8Halo-1.5.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via \admin\index.html#/system/too...
CVE-2022-26673MEDIUM5.4ASUS RT-AX88U has insufficient filtering for special characters in the HTTP header parameter. A remote attacker with gen...
CVE-2022-29577MEDIUM6.1OWASP AntiSamy before 1.6.7 allows XSS via HTML tag smuggling on STYLE content with crafted input. The output serializer...
CVE-2022-28367MEDIUM6.1OWASP AntiSamy before 1.6.6 allows XSS via HTML tag smuggling on STYLE content with crafted input. The output serializer...
CVE-2022-22558MEDIUM6Dell PowerEdge Server BIOS and Dell Precision Workstation 7910 and 7920 Rack BIOS contain an Improper SMM communication ...
CVE-2022-28445MEDIUM6.5KiteCMS v1.1.1 was discovered to contain an arbitrary file read vulnerability via the background management module.
CVE-2022-28820MEDIUM6.1ACS Commons version 5.1.x (and earlier) suffers from a Reflected Cross-site Scripting (XSS) vulnerability in /apps/acs-c...
CVE-2022-28743MEDIUM6.6Time-of-check Time-of-use (TOCTOU) Race Condition vulerability in Foscam R2C IP camera running System FW <= 1.13.1.6, an...
CVE-2022-23711MEDIUM5.3A vulnerability in Kibana could expose sensitive information related to Elastic Stack monitoring in the Kibana page sour...
CVE-2022-22969MEDIUM6.5<Issue Description> Spring Security OAuth versions 2.5.x prior to 2.5.2 and older unsupported versions are susceptible t...
CVE-2022-20805MEDIUM4.1A vulnerability in the automatic decryption process in Cisco Umbrella Secure Web Gateway (SWG) could allow an authentica...
CVE-2022-20804MEDIUM6.5A vulnerability in the Cisco Discovery Protocol of Cisco Unified Communications Manager (Unified CM) and Cisco Unified C...
CVE-2022-20790MEDIUM6.5A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) and Cisco Uni...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now