2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-0350MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository vanessa219/vditor prior to 3.8.13.
CVE-2022-27496MEDIUM6.1Cross-site scripting vulnerability in Zero-channel BBS Plus v0.7.4 and earlier allows a remote attacker to inject an arb...
CVE-2022-23183MEDIUM6.5Missing authorization vulnerability in Advanced Custom Fields versions prior to 5.12.1 and Advanced Custom Fields Pro ve...
CVE-2022-26644MEDIUM6.1Online Banking System Protect v1.0 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities via par...
CVE-2022-24135MEDIUM6.1QingScan 1.3.0 is affected by Cross Site Scripting (XSS) vulnerability in all search functions.
CVE-2022-27907MEDIUM4.3Sonatype Nexus Repository Manager 3.x before 3.38.0 allows SSRF.
CVE-2022-23801MEDIUM6.1An issue was discovered in Joomla! 4.0.0 through 4.1.0. Possible XSS atack vector through SVG embedding in com_media.
CVE-2022-23800MEDIUM6.1An issue was discovered in Joomla! 4.0.0 through 4.1.0. Inadequate content filtering leads to XSS vulnerabilities in var...
CVE-2022-23798MEDIUM6.1An issue was discovered in Joomla! 2.5.0 through 3.10.6 & 4.0.0 through 4.1.0. Inadequate validation of URLs could resul...
CVE-2022-23796MEDIUM6.1An issue was discovered in Joomla! 3.7.0 through 3.10.6. Lack of input validation could allow an XSS attack using com_fi...
CVE-2022-23794MEDIUM5.3An issue was discovered in Joomla! 3.0.0 through 3.10.6 & 4.0.0 through 4.1.0. Uploading a file name of an excess length...
CVE-2022-23136MEDIUM5.4There is a stored XSS vulnerability in ZTE home gateway product. An attacker could modify the gateway name by inserting ...
CVE-2022-25619MEDIUM6.7Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in ping tool of Profel...
CVE-2022-24131MEDIUM6.1DouPHP v1.6 Release 20220121 is affected by Cross Site Scripting (XSS) through /admin/login.php in the background, which...
CVE-2022-1181MEDIUM5.4Stored Cross Site Scripting in GitHub repository openemr/openemr prior to 6.0.0.2.
CVE-2022-1179MEDIUM5.4Non-Privilege User Can Created New Rule and Lead to Stored Cross Site Scripting in GitHub repository openemr/openemr pri...
CVE-2022-1178MEDIUM5.4Stored Cross Site Scripting in GitHub repository openemr/openemr prior to 6.0.0.4.
CVE-2022-23869MEDIUM6.5In RuoYi v4.7.2 through the WebUI, user test1 does not have permission to reset the password of user test3, but the pass...
CVE-2022-1177MEDIUM4.3Accounting User Can Download Patient Reports in openemr in GitHub repository openemr/openemr prior to 6.1.0.
CVE-2022-1172MEDIUM5Null Pointer Dereference Caused Segmentation Fault in GitHub repository gpac/gpac prior to 2.1.0-DEV.
CVE-2022-1163MEDIUM4.8Cross-site Scripting (XSS) - Stored in GitHub repository mineweb/minewebcms prior to next.
CVE-2022-28202MEDIUM6.1An XSS issue was discovered in MediaWiki before 1.35.6, 1.36.x before 1.36.4, and 1.37.x before 1.37.2. The widthheight,...
CVE-2022-26951MEDIUM6.1Archer 6.x through 6.10 (6.10.0.0) contains a reflected XSS vulnerability. A remote SAML-unauthenticated malicious Arche...
CVE-2022-26950MEDIUM6.1Archer 6.x through 6.9 P2 (6.9.0.2) is affected by an open redirect vulnerability. A remote unprivileged attacker may po...
CVE-2022-26949MEDIUM6.5Archer 6.x through 6.9 SP2 P1 (6.9.2.1) contains an improper access control vulnerability on attachments. A remote authe...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now