2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-0858MEDIUM4.7A cross-site scripting (XSS) vulnerability in McAfee Enterprise ePolicy Orchestrator (ePO) prior to 5.10 Update 13 allow...
CVE-2022-0857MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability in McAfee Enterprise ePolicy Orchestrator (ePO) prior to 5.10 Updat...
CVE-2022-0842MEDIUM4.9A blind SQL injection vulnerability in McAfee Enterprise ePolicy Orchestrator (ePO) prior to 5.10 Update 13 allows a rem...
CVE-2022-0396MEDIUM5.3BIND 9.16.11 -> 9.16.26, 9.17.0 -> 9.18.0 and versions 9.16.11-S1 -> 9.16.26-S1 of the BIND Supported Preview Edition. S...
CVE-2022-25518MEDIUM6.5In CMDBuild from version 3.0 to 3.3.2 payload requests are saved in a temporary log table, which allows attackers with d...
CVE-2022-25484MEDIUM5.5tcpprep v4.4.1 has a reachable assertion (assert(l2len > 0)) in packet2tree() at tree.c in tcpprep v4.4.1.
CVE-2022-21718MEDIUM5Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. A vulnerability ...
CVE-2022-27090MEDIUM5.4Cscms Music Portal System v4.2 was discovered to contain a redirection vulnerability via the backurl parameter.
CVE-2022-23350MEDIUM5.4BigAnt Software BigAnt Server v5.6.06 was discovered to contain a cross-site scripting (XSS) vulnerability.
CVE-2022-23348MEDIUM5.3BigAnt Software BigAnt Server v5.6.06 was discovered to utilize weak password hashes.
CVE-2022-0681MEDIUM6.5The Simple Membership WordPress plugin before 4.1.0 does not have CSRF check in place when deleting Transactions, which ...
CVE-2022-0640MEDIUM6.1The Pricing Table Builder WordPress plugin before 1.1.5 does not sanitize and escape the postid parameter before outputt...
CVE-2022-0628MEDIUM6.1The Mega Menu WordPress plugin before 3.0.8 does not sanitize and escape the _wpnonce parameter before outputting it bac...
CVE-2022-0627MEDIUM6.1The Amelia WordPress plugin before 1.0.47 does not sanitize and escape the code parameter before outputting it back in a...
CVE-2022-0616MEDIUM4.3The Amelia WordPress plugin before 1.0.47 does not have CSRF check in place when deleting customers, which could allow a...
CVE-2022-0590MEDIUM4.8The BulletProof Security WordPress plugin before 5.8 does not sanitise and escape some of its settings, which could allo...
CVE-2022-0515MEDIUM4.3Cross-Site Request Forgery (CSRF) in GitHub repository crater-invoice/crater prior to 6.0.4.
CVE-2022-0514MEDIUM6.5Business Logic Errors in GitHub repository crater-invoice/crater prior to 6.0.5.
CVE-2022-0423MEDIUM5.4The 3D FlipBook WordPress plugin before 1.12.1 does not have authorisation and CSRF checks when updating its settings, a...
CVE-2022-0364MEDIUM5.4The Modern Events Calendar Lite WordPress plugin before 6.4.0 does not sanitize and escape some of the Hourly Schedule p...
CVE-2022-26494MEDIUM4.8An XSS was identified in the Admin Web interface of PrimeKey SignServer before 5.8.1. JavaScript code must be used in a ...
CVE-2022-25570MEDIUM6.5In Click Studios (SA) Pty Ltd Passwordstate 9435, users with access to a passwordlist can gain access to additional pass...
CVE-2022-1035MEDIUM5.5Segmentation Fault caused by MP4Box -lsr in GitHub repository gpac/gpac prior to 2.1.0-DEV.
CVE-2022-24656MEDIUM6.1HexoEditor 1.1.8 is affected by Cross Site Scripting (XSS). By putting a common XSS payload in a markdown file, if opene...
CVE-2022-1004MEDIUM4.3Accounted time is shown in the Ticket Detail View (External Interface), even if ExternalFrontend::TicketDetailView###Acc...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now