2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-28364MEDIUM5.4Reprise License Manager 14.2 is affected by a reflected cross-site scripting vulnerability (XSS) in the /goform/rlmswitc...
CVE-2022-28363MEDIUM6.1Reprise License Manager 14.2 is affected by a reflected cross-site scripting vulnerability (XSS) in the /goform/login_pr...
CVE-2022-26877MEDIUM6.5Asana Desktop before 1.6.0 allows remote attackers to exfiltrate local files if they can trick the Asana desktop app int...
CVE-2022-26588MEDIUM6.5A Cross-Site Request Forgery (CSRF) in IceHrm 31.0.0.OS allows attackers to delete arbitrary users or achieve account ta...
CVE-2022-26855MEDIUM5.5Dell PowerScale OneFS, versions 8.2.x-9.3.0.x, contains an incorrect default permissions vulnerability. A local maliciou...
CVE-2022-24820MEDIUM5.3XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. A guest user wi...
CVE-2022-24819MEDIUM5.3XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. A guest user wi...
CVE-2022-22563MEDIUM4.4Dell EMC Powerscale OneFS 8.2.x - 9.2.x omit security-relevant information in /etc/master.passwd. A high-privileged user...
CVE-2022-1284MEDIUM5.5heap-use-after-free in GitHub repository radareorg/radare2 prior to 5.6.8. This vulnerability is capable of inducing den...
CVE-2022-27152MEDIUM5.7Roku devices running RokuOS v9.4.0 build 4200 or earlier that uses a Realtek WiFi chip is vulnerable to Arbitrary file m...
CVE-2022-1283MEDIUM5.5NULL Pointer Dereference in r_bin_ne_get_entrypoints function in GitHub repository radareorg/radare2 prior to 5.6.8. Thi...
CVE-2022-27148MEDIUM5.5GPAC mp4box 1.1.0-DEV-rev1663-g881c6a94a-master is vulnerable to Integer Overflow.
CVE-2022-27147MEDIUM5.5GPAC mp4box 1.1.0-DEV-rev1727-g8be34973d-master has a use-after-free vulnerability in function gf_node_get_attribute_by_...
CVE-2022-27146MEDIUM5.5GPAC mp4box 1.1.0-DEV-rev1759-geb2d1e6dd-has a heap-buffer-overflow vulnerability in function gf_isom_apple_enum_tag.
CVE-2022-27145MEDIUM5.5GPAC mp4box 1.1.0-DEV-rev1727-g8be34973d-master has a stack-overflow vulnerability in function gf_isom_get_sample_for_mo...
CVE-2022-24229MEDIUM6.1A cross-site scripting (XSS) vulnerability in ONLYOFFICE Document Server Example before v7.0.0 allows remote attackers i...
CVE-2022-27991MEDIUM6.5Online Banking System in PHP v1 was discovered to contain multiple SQL injection vulnerabilities at /staff_login.php via...
CVE-2022-27348MEDIUM4.8Social Codia SMS v1 was discovered to contain a stored cross-site scripting (XSS) vulnerability via add_post.php. This v...
CVE-2022-27063MEDIUM6.1AeroCMS v0.0.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability via view_all_comments.php. Th...
CVE-2022-27062MEDIUM4.8AeroCMS v0.0.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability via add_post.php. This vulner...
CVE-2022-26624MEDIUM6.1Bootstrap v3.1.11 and v3.3.7 was discovered to contain a cross-site scripting (XSS) vulnerability via the Title paramete...
CVE-2022-24681MEDIUM6.1Zoho ManageEngine ADSelfService Plus before 6121 allows XSS via the welcome name attribute to the Reset Password, Unlock...
CVE-2022-25595MEDIUM6.5ASUS RT-AC86U has improper user request handling, which allows an unauthenticated LAN attacker to cause a denial of serv...
CVE-2022-25594MEDIUM5.3Microprogram’s parking lot management system is vulnerable to sensitive information exposure. An unauthorized remote att...
CVE-2022-22518MEDIUM6.5A bug in CmpUserMgr component can lead to only partially applied security policies. This can result in enabled, anonymou...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now