2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-22191MEDIUM6.5A Denial of Service (DoS) vulnerability in the processing of a flood of specific ARP traffic in Juniper Networks Junos O...
CVE-2022-22186MEDIUM6.5Due to an Improper Initialization vulnerability in Juniper Networks Junos OS on EX4650 devices, packets received on the ...
CVE-2022-22182MEDIUM6.1A Cross-site Scripting (XSS) vulnerability in Juniper Networks Junos OS J-Web allows an attacker to construct a URL that...
CVE-2022-22181MEDIUM5.4A reflected Cross-site Scripting (XSS) vulnerability in J-Web of Juniper Networks Junos OS allows a network-based authen...
CVE-2022-1257MEDIUM5.5Insecure storage of sensitive information vulnerability in MA for Linux, macOS, and Windows prior to 5.7.6 allows a loca...
CVE-2022-1351MEDIUM5.4Stored XSS in Tooltip in GitHub repository pimcore/pimcore prior to 10.4.
CVE-2022-0023MEDIUM5.9An improper handling of exceptional conditions vulnerability exists in the DNS proxy feature of Palo Alto Networks PAN-O...
CVE-2022-27847MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in Yooslider Yoo Slider <= 2.0.0 on WordPress allows attackers to import...
CVE-2022-27846MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in Yooslider Yoo Slider <= 2.0.0 on WordPress allows attackers to create...
CVE-2022-27505MEDIUM6.1Reflected cross site scripting (XSS)
CVE-2022-27503MEDIUM6.1Cross-site Scripting (XSS) vulnerability in Citrix StoreFront affects version 1912 before CU5 and version 3.12 before CU...
CVE-2022-22961MEDIUM5.3VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an information disclosure vulnerability du...
CVE-2022-22959MEDIUM4.3VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a cross site request forgery vulnerability...
CVE-2022-1337MEDIUM6.5The image proxy component in Mattermost version 6.4.1 and earlier allocates memory for multiple copies of a proxied imag...
CVE-2022-1333MEDIUM6.5Mattermost Playbooks plugin v1.24.0 and earlier fails to properly check the limit on the number of webhooks, which allow...
CVE-2022-1332MEDIUM4.3One of the API in Mattermost version 6.4.1 and earlier fails to properly protect the permissions, which allows the authe...
CVE-2022-1280MEDIUM6.3A use-after-free vulnerability was found in drm_lease_held in drivers/gpu/drm/drm_lease.c in the Linux kernel due to a r...
CVE-2022-0221MEDIUM5.5A CWE-611: Improper Restriction of XML External Entity Reference vulnerability exists that could result in information d...
CVE-2022-27256MEDIUM6.1A PHP Local File inclusion vulnerability in the Redbasic theme for Hubzilla before version 7.2 allows remote attackers t...
CVE-2022-26643MEDIUM5.3An issue in EasyIO CPT Graphics v0.8 allows attackers to discover valid users in the application.
CVE-2022-26144MEDIUM6.1An XSS issue was discovered in MantisBT before 2.25.3. Improper escaping of a Plugin name allows execution of arbitrary ...
CVE-2022-24308MEDIUM5.5Automox Agent prior to version 37 on Windows and Linux and Version 36 on OSX could allow for a non privileged user to ob...
CVE-2022-27475MEDIUM6.1Cross site scripting (XSS) vulnerability in tramyardg hotel-mgmt-system, allows attackers to execute arbitrary code when...
CVE-2022-22279MEDIUM4.9A post-authentication arbitrary file read vulnerability impacting end-of-life Secure Remote Access (SRA) products and ol...
CVE-2022-26589MEDIUM6.5A Cross-Site Request Forgery (CSRF) in Pluck CMS v4.7.15 allows attackers to delete arbitrary pages.

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now