2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-0475 | MEDIUM | 5.4 | 0.4% | Mar 21, 2022 | Malicious translator is able to inject JavaScript code in few translatable strings (where HTML is allowed). The code cou... |
| CVE-2022-26555 | MEDIUM | 5.4 | 0.4% | Mar 20, 2022 | A stored cross-site scripting (XSS) vulnerability in the Add a Button function of Eova v1.6.0 allows attackers to execut... |
| CVE-2022-26247 | MEDIUM | 5.9 | 0.7% | Mar 20, 2022 | TMS v2.28.0 contains an insecure permissions vulnerability via the component /TMS/admin/user/Update2. This vulnerability... |
| CVE-2022-26246 | MEDIUM | 6.1 | 0.6% | Mar 20, 2022 | TMS v2.28.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /TMS/admin/setting/mai... |
| CVE-2022-25464 | MEDIUM | 4.8 | 0.4% | Mar 20, 2022 | A stored cross-site scripting (XSS) vulnerability in the component /admin/contenttemp of DoraCMS v2.1.8 allows attackers... |
| CVE-2022-27246 | MEDIUM | 6.1 | 0.6% | Mar 18, 2022 | An issue was discovered in MISP before 2.4.156. An SVG org logo (which may contain JavaScript) is not forbidden by defau... |
| CVE-2022-27244 | MEDIUM | 4.8 | 0.5% | Mar 18, 2022 | An issue was discovered in MISP before 2.4.156. A malicious site administrator could store an XSS payload in the custom ... |
| CVE-2022-25605 | MEDIUM | 5.4 | 0.5% | Mar 18, 2022 | Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities discovered in WP-DownloadManager WordPress plug... |
| CVE-2022-25604 | MEDIUM | 5.4 | 0.5% | Mar 18, 2022 | Authenticated (contributor of higher user role) Stored Cross-Site Scripting (XSS) vulnerability discovered in WordPress ... |
| CVE-2022-25603 | MEDIUM | 4.8 | 0.5% | Mar 18, 2022 | Authenticated (author or higher user role) Stored Cross-Site Scripting (XSS) vulnerability discovered in MaxGalleria Wor... |
| CVE-2022-22671 | MEDIUM | 4.6 | 0.3% | Mar 18, 2022 | An authentication issue was addressed with improved state management. This issue is fixed in iOS 15.4 and iPadOS 15.4. A... |
| CVE-2022-22660 | MEDIUM | 5.5 | 0.6% | Mar 18, 2022 | This issue was addressed with a new entitlement. This issue is fixed in macOS Monterey 12.3. An app may be able to spoof... |
| CVE-2022-22659 | MEDIUM | 6.5 | 0.9% | Mar 18, 2022 | A logic issue was addressed with improved state management. This issue is fixed in iOS 15.4 and iPadOS 15.4. An attacker... |
| CVE-2022-22654 | MEDIUM | 4.3 | 0.9% | Mar 18, 2022 | A user interface issue was addressed. This issue is fixed in watchOS 8.5, Safari 15.4. Visiting a malicious website may ... |
| CVE-2022-22652 | MEDIUM | 6.1 | 0.3% | Mar 18, 2022 | The GSMA authentication panel could be presented on the lock screen. The issue was resolved by requiring device unlock t... |
| CVE-2022-22650 | MEDIUM | 5.5 | 0.2% | Mar 18, 2022 | This issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.6.5, macOS Monterey 12.3, Securit... |
| CVE-2022-22648 | MEDIUM | 5.5 | 0.4% | Mar 18, 2022 | This issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.6.5, macOS Monterey 12.3, Securit... |
| CVE-2022-22647 | MEDIUM | 4.6 | 0.3% | Mar 18, 2022 | This issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.6.5, macOS Monterey 12.3, Securit... |
| CVE-2022-22644 | MEDIUM | 5.5 | 0.6% | Mar 18, 2022 | A privacy issue existed in the handling of Contact cards. This was addressed with improved state management. This issue ... |
| CVE-2022-22638 | MEDIUM | 6.5 | 1.9% | Mar 18, 2022 | A null pointer dereference was addressed with improved validation. This issue is fixed in tvOS 15.4, iOS 15.4 and iPadOS... |
| CVE-2022-22622 | MEDIUM | 4.6 | 0.3% | Mar 18, 2022 | This issue was addressed with improved checks. This issue is fixed in iOS 15.4 and iPadOS 15.4. A person with physical a... |
| CVE-2022-22621 | MEDIUM | 4.6 | 0.3% | Mar 18, 2022 | This issue was addressed with improved checks. This issue is fixed in tvOS 15.4, iOS 15.4 and iPadOS 15.4, macOS Montere... |
| CVE-2022-22600 | MEDIUM | 5.5 | 1.6% | Mar 18, 2022 | The issue was addressed with improved permissions logic. This issue is fixed in tvOS 15.4, iOS 15.4 and iPadOS 15.4, mac... |
| CVE-2022-22594 | MEDIUM | 6.5 | 0.8% | Mar 18, 2022 | A cross-origin issue in the IndexDB API was addressed with improved input validation. This issue is fixed in iOS 15.3 an... |
| CVE-2022-22592 | MEDIUM | 6.5 | 1.5% | Mar 18, 2022 | A logic issue was addressed with improved state management. This issue is fixed in iOS 15.3 and iPadOS 15.3, watchOS 8.4... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now