2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-21820MEDIUM6.3NVIDIA DCGM contains a vulnerability in nvhostengine, where a network user can cause detection of error conditions witho...
CVE-2022-1058MEDIUM6.1Open Redirect on login in GitHub repository go-gitea/gitea prior to 1.16.5.
CVE-2022-0955MEDIUM4.8Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/data-hub prior to 1.2.4.
CVE-2022-1052MEDIUM5.5Heap Buffer Overflow in iterate_chained_fixups in GitHub repository radareorg/radare2 prior to 5.6.6.
CVE-2022-0145MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository forkcms/forkcms prior to 5.11.1.
CVE-2022-27820MEDIUM4OWASP Zed Attack Proxy (ZAP) through w2022-03-21 does not verify the TLS certificate chain of an HTTPS server.
CVE-2022-25269MEDIUM6.1Passwork On-Premise Edition before 4.6.13 has multiple XSS issues.
CVE-2022-25266MEDIUM4.3Passwork On-Premise Edition before 4.6.13 allows migration/downloadExportFile Directory Traversal (to read files).
CVE-2022-27254MEDIUM5.3The remote keyless system on Honda Civic 2018 vehicles sends the same RF signal for each door-open request, which allows...
CVE-2022-25041MEDIUM4.3OpenEMR v6.0.0 was discovered to contain an incorrect access control issue.
CVE-2022-24731MEDIUM4.9Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Argo CD starting with version 1.5.0 but before...
CVE-2022-24730MEDIUM6.5Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Argo CD starting with version 1.3.0 but before...
CVE-2022-25609MEDIUM5.4Stored Cross-Site Scripting (XSS) in Yoo Slider – Image Slider & Video Slider (WordPress plugin) allows attackers with c...
CVE-2022-25608MEDIUM5.4Cross-Site Request Forgery (CSRF) in Yoo Slider – Image Slider & Video Slider (WordPress plugin) allows attackers to tri...
CVE-2022-25223MEDIUM4.3Money Transfer Management System Version 1.0 allows an authenticated user to inject SQL queries in 'mtms/admin/?page=tra...
CVE-2022-25221MEDIUM6.1Money Transfer Management System Version 1.0 allows an attacker to inject JavaScript code in the URL and then trick a us...
CVE-2022-0996MEDIUM6.5A vulnerability was found in the 389 Directory Server that allows expired passwords to access the database to cause impr...
CVE-2022-0889MEDIUM6.1The Ninja Forms - File Uploads Extension WordPress plugin is vulnerable to reflected cross-site scripting due to missing...
CVE-2022-0854MEDIUM5.5A memory leak flaw was found in the Linux kernel’s DMA subsystem, in the way a user calls DMA_FROM_DEVICE. This flaw all...
CVE-2022-0834MEDIUM5.4The Amelia WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escaping and sanitization of the l...
CVE-2022-0750MEDIUM5.4The Photoswipe Masonry Gallery WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escaping and s...
CVE-2022-22316MEDIUM6.5IBM MQ Appliance 9.2 CD and 9.2 LTS could allow an authenticated and authorized user to cause a denial of service due to...
CVE-2022-23242MEDIUM4.2TeamViewer Linux versions before 15.28 do not properly execute a deletion command for the connection password in case of...
CVE-2022-0862MEDIUM5.3A lack of password change protection vulnerability in a depreciated API of McAfee Enterprise ePolicy Orchestrator (ePO) ...
CVE-2022-0859MEDIUM6.7McAfee Enterprise ePolicy Orchestrator (ePO) prior to 5.10 Update 13 allows a local attacker to point an ePO server to a...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now