2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-28648MEDIUM5.4In JetBrains YouTrack before 2022.1.43563 HTML code from the issue description was being rendered
CVE-2022-22356MEDIUM6.5IBM MQ Appliance 9.2 CD and 9.2 LTS could allow an attacker to enumerate account credentials due to an observable discre...
CVE-2022-22355MEDIUM5.3IBM MQ Appliance 9.2 CD and 9.2 LTS are vulnerable to a denial of service in the Login component of the application whic...
CVE-2022-27463MEDIUM6.1Open redirect vulnerability in objects/login.json.php in WWBN AVideo through 11.6, allows attackers to arbitrarily redir...
CVE-2022-27462MEDIUM6.1Cross Site Scripting (XSS) vulnerability in objects/function.php in function getDeviceID in WWBN AVideo through 11.6, vi...
CVE-2022-0602MEDIUM5.4Cross-site Scripting (XSS) - DOM in GitHub repository tastyigniter/tastyigniter prior to 3.3.0.
CVE-2022-1243MEDIUM6.1CRHTLF can lead to invalid protocol extraction potentially leading to XSS in GitHub repository medialize/uri.js prior to...
CVE-2022-26356MEDIUM5.6Racy interactions between dirty vram tracking and paging log dirty hypercalls Activation of log dirty mode done by XEN_D...
CVE-2022-1236MEDIUM6.5Weak Password Requirements in GitHub repository weseek/growi prior to v5.0.0.
CVE-2022-26615MEDIUM5.4A cross-site scripting (XSS) vulnerability in College Website Content Management System v1.0 allows attackers to execute...
CVE-2022-25356MEDIUM5.3Alt-N MDaemon Security Gateway through 8.5.0 allows SecurityGateway.dll?view=login XML Injection.
CVE-2022-0807MEDIUM6.5Inappropriate implementation in Autofill in Google Chrome prior to 99.0.4844.51 allowed a remote attacker to bypass navi...
CVE-2022-0806MEDIUM6.5Data leak in Canvas in Google Chrome prior to 99.0.4844.51 allowed a remote attacker who convinced a user to engage in s...
CVE-2022-0804MEDIUM6.5Inappropriate implementation in Full screen mode in Google Chrome on Android prior to 99.0.4844.51 allowed a remote atta...
CVE-2022-0803MEDIUM6.5Inappropriate implementation in Permissions in Google Chrome prior to 99.0.4844.51 allowed a remote attacker to tamper w...
CVE-2022-0802MEDIUM6.5Inappropriate implementation in Full screen mode in Google Chrome on Android prior to 99.0.4844.51 allowed a remote atta...
CVE-2022-0792MEDIUM6.5Out of bounds read in ANGLE in Google Chrome prior to 99.0.4844.51 allowed a remote attacker to potentially exploit heap...
CVE-2022-0462MEDIUM6.5Inappropriate implementation in Scroll in Google Chrome prior to 98.0.4758.80 allowed a remote attacker to leak cross-or...
CVE-2022-0461MEDIUM6.5Policy bypass in COOP in Google Chrome prior to 98.0.4758.80 allowed a remote attacker to bypass iframe sandbox via a cr...
CVE-2022-0455MEDIUM6.5Inappropriate implementation in Full Screen Mode in Google Chrome on Android prior to 98.0.4758.80 allowed a remote atta...
CVE-2022-27441MEDIUM4.8A stored cross-site scripting (XSS) vulnerability in TPCMS v3.2 allows attackers to execute arbitrary web scripts or HTM...
CVE-2022-27651MEDIUM6.8A flaw was found in buildah where containers were incorrectly started with non-empty default permissions. A bug was foun...
CVE-2022-27609MEDIUM6Forcepoint One Endpoint prior to version 22.01 installed on Microsoft Windows does not provide sufficient anti-tampering...
CVE-2022-27608MEDIUM6Forcepoint One Endpoint prior to version 22.01 installed on Microsoft Windows is vulnerable to registry key tampering by...
CVE-2022-25618MEDIUM4.8Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in wpDataTables (WordPress plugin) versions <= 2....

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now