2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-42100MEDIUM5.4KLiK SocialMediaWebsite Version 1.0.1 has XSS vulnerabilities that allow attackers to store XSS via location input reply...
CVE-2022-42099MEDIUM5.4KLiK SocialMediaWebsite Version 1.0.1 has XSS vulnerabilities that allow attackers to store XSS via location Forum Subje...
CVE-2022-41676MEDIUM5.4Raiden MAILD Mail Server website mail field has insufficient filtering for user input. A remote attacker with general us...
CVE-2022-41675HIGH8A remote attacker with general user privilege can inject malicious code in the form content of Raiden MAILD Mail Server ...
CVE-2022-36137MEDIUM4.8ChurchCRM Version 4.4.5 has XSS vulnerabilities that allow attackers to store XSS via location input sHeader.
CVE-2022-36136MEDIUM4.8ChurchCRM Version 4.4.5 has XSS vulnerabilities that allow attackers to store XSS via location input Deposit Comment.
CVE-2022-32967LOW2.1RTL8111EP-CG/RTL8111FP-CG DASH function has hard-coded password. An unauthenticated physical attacker can use the hard-c...
CVE-2022-32966MEDIUM6.5RTL8168FP-CG Dash remote management function has missing authorization. An unauthenticated attacker within the adjacent ...
CVE-2022-45307MEDIUM4.3Insecure permissions in Chocolatey PHP package v8.1.12 and below grants all users in the Authenticated Users group write...
CVE-2022-45306MEDIUM4.3Insecure permissions in Chocolatey Azure-Pipelines-Agent package v2.211.1 and below grants all users in the Authenticate...
CVE-2022-45305MEDIUM4.3Insecure permissions in Chocolatey Python3 package v3.11.0 and below grants all users in the Authenticated Users group w...
CVE-2022-45304MEDIUM4.3Insecure permissions in Chocolatey Cmder package v1.3.20 and below grants all users in the Authenticated Users group wri...
CVE-2022-45301MEDIUM4.3Insecure permissions in Chocolatey Ruby package v3.1.2.1 and below grants all users in the Authenticated Users group wri...
CVE-2022-4129MEDIUM5.5A flaw was found in the Linux kernel's Layer 2 Tunneling Protocol (L2TP). A missing lock when clearing sk_user_data can ...
CVE-2022-4128MEDIUM5.5A NULL pointer dereference issue was discovered in the Linux kernel in the MPTCP protocol when traversing the subflow li...
CVE-2022-4127MEDIUM5.5A NULL pointer dereference issue was discovered in the Linux kernel in io_files_update_with_index_alloc. A local user co...
CVE-2022-45224MEDIUM4.8Web-Based Student Clearance System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in Admin/ad...
CVE-2022-45223MEDIUM4.8Web-Based Student Clearance System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in /Admin/a...
CVE-2022-45221MEDIUM4.8Web-Based Student Clearance System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in changepa...
CVE-2022-45214MEDIUM6.1A cross-site scripting (XSS) vulnerability in Sanitization Management System v1.0.0 allows attackers to execute arbitrar...
CVE-2022-3088HIGH7.8UC-8100A-ME-T System Image: Versions v1.0 to v1.6, UC-2100 System Image: Versions v1.0 to v1.12, UC-2100-W System Image:...
CVE-2022-38753MEDIUM6.3This update resolves a multi-factor authentication bypass attack
CVE-2022-24190HIGH7.5The /device/acceptBind end-point for Ourphoto App version 1.4.1 does not require authentication or authorization. The us...
CVE-2022-24189MEDIUM6.5The user_token authorization header on the Ourphoto App version 1.4.1 /apiv1/* end-points is not implemented properly. R...
CVE-2022-24188HIGH7.5The /device/signin end-point for the Ourphoto App version 1.4.1 discloses clear-text password information for functional...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now