2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-20789MEDIUM6.5A vulnerability in the software upgrade process of Cisco Unified Communications Manager (Unified CM) and Cisco Unified C...
CVE-2022-20788MEDIUM6.1A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM), Cisco Unifie...
CVE-2022-20787MEDIUM6.8A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) Software and ...
CVE-2022-20778MEDIUM6.1A vulnerability in the authentication component of Cisco Webex Meetings could allow an unauthenticated, remote attacker ...
CVE-2022-24870MEDIUM5.4Combodo iTop is a web based IT Service Management tool. In 3.0.0 beta releases prior to 3.0.0 beta3 a malicious script c...
CVE-2022-24869MEDIUM5.4GLPI is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and...
CVE-2022-24868MEDIUM5.4GLPI is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and...
CVE-2022-22436MEDIUM5.4IBM Maximo Asset Management 7.6.1.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbi...
CVE-2022-22435MEDIUM5.4IBM Maximo Asset Management 7.6.1.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbi...
CVE-2022-1022MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository chatwoot/chatwoot prior to 2.5.0.
CVE-2022-24272MEDIUM6.5An authenticated user may trigger an invariant assertion during command dispatch due to incorrect validation on the $ext...
CVE-2022-1420MEDIUM5.5Use of Out-of-range Pointer Offset in GitHub repository vim/vim prior to 8.2.4774.
CVE-2022-27237MEDIUM6.1There is a cross-site scripting (XSS) vulnerability in an NI Web Server component installed with several NI products. De...
CVE-2022-29548MEDIUM6.1A reflected XSS issue exists in the Management Console of several WSO2 products. This affects API Manager 2.2.0, 2.5.0, ...
CVE-2022-27926MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability in the /public/launchNewWindow.jsp component of Zimbra Collaboratio...
CVE-2022-29537MEDIUM5.5gp_rtp_builder_do_hevc in ietf/rtp_pck_mpeg4.c in GPAC 2.0.0 has a heap-based buffer over-read, as demonstrated by MP4Bo...
CVE-2022-29533MEDIUM6.1An issue was discovered in MISP before 2.4.158. There is XSS in app/Controller/OrganisationsController.php in a situatio...
CVE-2022-29532MEDIUM4.8An issue was discovered in MISP before 2.4.158. There is XSS in the cerebrate view if one administrator puts a javascrip...
CVE-2022-29531MEDIUM5.4An issue was discovered in MISP before 2.4.158. There is stored XSS in the event graph via a tag name.
CVE-2022-29530MEDIUM5.4An issue was discovered in MISP before 2.4.158. There is stored XSS in the galaxy clusters.
CVE-2022-29529MEDIUM5.4An issue was discovered in MISP before 2.4.158. There is stored XSS via the LinOTP login field.
CVE-2022-24865MEDIUM6.5HumHub is an Open Source Enterprise Social Network. In affected versions users who are forced to change their password b...
CVE-2022-24871MEDIUM5.5Shopware is an open commerce platform based on Symfony Framework and Vue. In affected versions an attacker can abuse the...
CVE-2022-24864MEDIUM5.4Origin Protocol is a blockchain based project. The Origin Protocol project website allows for malicious users to inject ...
CVE-2022-24799MEDIUM6.1wire-webapp is the web application interface for the wire messaging service. Insufficient escaping in markdown “code hig...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now