2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-26197MEDIUM5.4Joget DX 7 was discovered to contain a cross-site scripting (XSS) vulnerability via the Datalist table.
CVE-2022-24643MEDIUM5.4A stored cross-site scripting (XSS) issue was discovered in the OpenEMR Hospital Information Management System version 6...
CVE-2022-27920MEDIUM6.1libkiwix 10.0.0 and 10.0.1 allows XSS in the built-in webserver functionality via the search suggestions URL parameter. ...
CVE-2022-27906MEDIUM5.9Mendelson OFTP2 before 1.1 b43 is affected by directory traversal. To access the vulnerable code path, the attacker has ...
CVE-2022-27887MEDIUM6.1Maccms v10 was discovered to contain a reflected cross-site scripting (XSS) vulnerability in /admin.php/admin/vod/data.h...
CVE-2022-27886MEDIUM6.1Maccms v10 was discovered to contain a reflected cross-site scripting (XSS) vulnerability in /admin.php/admin/ulog/index...
CVE-2022-27885MEDIUM6.1Maccms v10 was discovered to contain multiple reflected cross-site scripting (XSS) vulnerabilities in /admin.php/admin/w...
CVE-2022-27884MEDIUM6.1Maccms v10 was discovered to contain a reflected cross-site scripting (XSS) vulnerability in /admin.php/admin/plog/index...
CVE-2022-26573MEDIUM6.1Maccms v10 was discovered to contain multiple reflected cross-site scripting (XSS) vulnerabilities in /admin.php/admin/a...
CVE-2022-25612MEDIUM5.4Multiple Authenticated Persistent Cross-Site Scripting (XSS) vulnerabilities in Simple Event Planner WordPress plugin <=...
CVE-2022-25611MEDIUM5.4Authenticated Stored Cross-Site Scripting (XSS) in Simple Event Planner plugin <= 1.5.4 allows attackers with contributo...
CVE-2022-25610MEDIUM6.1Unauthenticated Stored Cross-Site Scripting (XSS) in Simple Ajax Chat <= 20220115 allows an attacker to store the malici...
CVE-2022-25606MEDIUM5.4Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities discovered in WP-DownloadManager WordPress plug...
CVE-2022-25590MEDIUM6.5SurveyKing v0.2.0 was discovered to retain users' session cookies after logout, allowing attackers to login to the syste...
CVE-2022-0897MEDIUM4.3A flaw was found in the libvirt nwfilter driver. The virNWFilterObjListNumOfNWFilters method failed to acquire the drive...
CVE-2022-0494MEDIUM4.4A kernel information leak flaw was identified in the scsi_ioctl function in drivers/scsi/scsi_ioctl.c in the Linux kerne...
CVE-2022-0322MEDIUM5.5A flaw was found in the sctp_make_strreset_req function in net/sctp/sm_make_chunk.c in the SCTP network protocol in the ...
CVE-2022-26263MEDIUM6.1Yonyou u8 v13.0 was discovered to contain a DOM-based cross-site scripting (XSS) vulnerability via the component /u8sl/W...
CVE-2022-25582MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in the Column module of ClassCMS v2.5 and below allows attackers to ex...
CVE-2022-25574MEDIUM4.8A stored cross-site scripting (XSS) vulnerability in the upload function of /admin/show.php allows attackers to execute ...
CVE-2022-25576MEDIUM4.5Anchor CMS v0.12.7 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component anchor/routes/posts.p...
CVE-2022-25575MEDIUM6.1Multiple cross-site scripting (XSS) vulnerabilities in Parking Management System v1.0 allows attackers to execute arbitr...
CVE-2022-24782MEDIUM4.3Discourse is an open source discussion platform. Versions 2.8.2 and prior in the `stable` branch, 2.9.0.beta3 and prior ...
CVE-2022-24776MEDIUM6.1Flask-AppBuilder is an application development framework, built on top of the Flask web framework. Flask-AppBuilder cont...
CVE-2022-24769MEDIUM5.9Moby is an open-source project created by Docker to enable and accelerate software containerization. A bug was found in ...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now