2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-0968 | MEDIUM | 5.5 | 3.7% | Mar 15, 2022 | The microweber application allows large characters to insert in the input field "fist & last name" which can allow attac... |
| CVE-2022-0967 | MEDIUM | 5.4 | 3.3% | Mar 15, 2022 | Stored XSS via File Upload in star7th/showdoc in star7th/showdoc in GitHub repository star7th/showdoc prior to 2.10.4. |
| CVE-2022-0966 | MEDIUM | 5.4 | 0.5% | Mar 15, 2022 | Stored XSS via File Upload in star7th/showdoc in GitHub repository star7th/showdoc prior to 2.4.10. |
| CVE-2022-0965 | MEDIUM | 5.4 | 0.9% | Mar 15, 2022 | Stored XSS viva .ofd file upload in GitHub repository star7th/showdoc prior to 2.10.4. |
| CVE-2022-0964 | MEDIUM | 5.4 | 0.8% | Mar 15, 2022 | Stored XSS viva .webmv file upload in GitHub repository star7th/showdoc prior to 2.10.4. |
| CVE-2022-0963 | MEDIUM | 5.4 | 1.9% | Mar 15, 2022 | Unrestricted XML Files Leads to Stored XSS in GitHub repository microweber/microweber prior to 1.2.12. |
| CVE-2022-0961 | MEDIUM | 5.5 | 1.0% | Mar 15, 2022 | The microweber application allows large characters to insert in the input field "post title" which can allow attackers t... |
| CVE-2022-0430 | MEDIUM | 5.3 | 1.3% | Mar 15, 2022 | Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository httpie/httpie prior to 3.1.0. |
| CVE-2022-0942 | MEDIUM | 5.4 | 0.7% | Mar 15, 2022 | Stored XSS due to Unrestricted File Upload in GitHub repository star7th/showdoc prior to 2.10.4. |
| CVE-2022-0957 | MEDIUM | 5.4 | 0.8% | Mar 15, 2022 | Stored XSS via File Upload in GitHub repository star7th/showdoc prior to 2.10.4. |
| CVE-2022-0956 | MEDIUM | 5.4 | 0.7% | Mar 15, 2022 | Stored XSS via File Upload in GitHub repository star7th/showdoc prior to v.2.10.4. |
| CVE-2022-0954 | MEDIUM | 5.4 | 3.2% | Mar 15, 2022 | Multiple Stored Cross-site Scripting (XSS) Vulnerabilities in Shop's Other Settings, Shop's Autorespond E-mail Settings ... |
| CVE-2022-0894 | MEDIUM | 5.4 | 0.7% | Mar 15, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.4.0. |
| CVE-2022-0893 | MEDIUM | 5.4 | 0.8% | Mar 15, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.4.0. |
| CVE-2022-0951 | MEDIUM | 6.1 | 0.9% | Mar 15, 2022 | File Upload Restriction Bypass leading to Stored XSS Vulnerability in GitHub repository star7th/showdoc prior to 2.10.4. |
| CVE-2022-0950 | MEDIUM | 5.4 | 0.6% | Mar 15, 2022 | Unrestricted Upload of File with Dangerous Type in GitHub repository star7th/showdoc prior to 2.10.4. |
| CVE-2022-27193 | MEDIUM | 5.5 | 0.7% | Mar 15, 2022 | CVRF-CSAF-Converter before 1.0.0-rc2 resolves XML External Entities (XXE). This leads to the inclusion of arbitrary (loc... |
| CVE-2022-0945 | MEDIUM | 5.4 | 0.8% | Mar 15, 2022 | Stored XSS viva axd and cshtml file upload in star7th/showdoc in GitHub repository star7th/showdoc prior to v2.10.4. |
| CVE-2022-24762 | MEDIUM | 6.5 | 0.7% | Mar 14, 2022 | sysend.js is a library that allows a user to send messages between pages that are open in the same browser. Users that u... |
| CVE-2022-24749 | MEDIUM | 6.1 | 1.1% | Mar 14, 2022 | Sylius is an open source eCommerce platform. In versions prior to 1.9.10, 1.10.11, and 1.11.2, it is possible to upload ... |
| CVE-2022-24742 | MEDIUM | 5.5 | 0.8% | Mar 14, 2022 | Sylius is an open source eCommerce platform. Prior to versions 1.9.10, 1.10.11, and 1.11.2, any other user can view the ... |
| CVE-2022-24733 | MEDIUM | 6.1 | 0.9% | Mar 14, 2022 | Sylius is an open source eCommerce platform. Prior to versions 1.9.10, 1.10.11, and 1.11.2, it is possible for a page co... |
| CVE-2022-22353 | MEDIUM | 6.5 | 0.9% | Mar 14, 2022 | IBM Big SQL on IBM Cloud Pak for Data 7.1.0, 7.1.1, 7.2.0, and 7.2.3 could allow an authenticated user with appropriate ... |
| CVE-2022-22344 | MEDIUM | 6.1 | 0.6% | Mar 14, 2022 | IBM Spectrum Copy Data Management 2.2.0.0 through 2.2.14.3 is vulnerable to HTTP header injection, caused by improper va... |
| CVE-2022-0962 | MEDIUM | 5.4 | 0.9% | Mar 14, 2022 | Stored XSS viva .webma file upload in GitHub repository star7th/showdoc prior to 2.10.4. |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now