2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-24386MEDIUM6.1Stored XSS in SmarterTools SmarterTrack This issue affects: SmarterTools SmarterTrack 100.0.8019.14010.
CVE-2022-24385MEDIUM6.5A Direct Object Access vulnerability in SmarterTools SmarterTrack leads to information disclosure This issue affects: Sm...
CVE-2022-24384MEDIUM6.1Cross-site Scripting (XSS) vulnerability in SmarterTools SmarterTrack This issue affects: SmarterTools SmarterTrack 100....
CVE-2022-0941MEDIUM5.4Stored XSS due to Unrestricted File Upload in GitHub repository star7th/showdoc prior to v2.10.4.
CVE-2022-0940MEDIUM5.4Stored XSS due to Unrestricted File Upload in GitHub repository star7th/showdoc prior to v2.10.4.
CVE-2022-0938MEDIUM5.4Stored XSS via file upload in GitHub repository star7th/showdoc prior to v2.10.4.
CVE-2022-0341MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository vanessa219/vditor prior to 3.8.12.
CVE-2022-0937MEDIUM5.4Stored xss in showdoc through file upload in GitHub repository star7th/showdoc prior to 2.10.4.
CVE-2022-23960MEDIUM5.6Certain Arm Cortex and Neoverse processors through 2022-03-08 do not properly restrict cache speculation, aka Spectre-BH...
CVE-2022-26966MEDIUM5.5An issue was discovered in the Linux kernel before 5.16.12. drivers/net/usb/sr9700.c allows attackers to obtain sensitiv...
CVE-2022-0930MEDIUM4.8File upload filter bypass leading to stored XSS in GitHub repository microweber/microweber prior to 1.2.12.
CVE-2022-0929MEDIUM6.1XSS on dynamic_text module in GitHub repository microweber/microweber prior to 1.2.11.
CVE-2022-0926MEDIUM4.8File upload filter bypass leading to stored XSS in GitHub repository microweber/microweber prior to 1.2.12.
CVE-2022-0880MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository star7th/showdoc prior to 2.10.2.
CVE-2022-26533MEDIUM6.1Alist v2.1.0 and below was discovered to contain a cross-site scripting (XSS) vulnerability via /i/:data/ipa.plist.
CVE-2022-26276MEDIUM5.3An issue in index.php of OneNav v0.9.14 allows attackers to perform directory traversal.
CVE-2022-25839MEDIUM5.3The package url-js before 2.1.0 are vulnerable to Improper Input Validation due to improper parsing, which makes it is p...
CVE-2022-25601MEDIUM6.1Reflected Cross-Site Scripting (XSS) vulnerability affecting parameter &tab discovered in Contact Form X WordPress plugi...
CVE-2022-24090MEDIUM5.5Adobe Photoshop versions 23.1.1 (and earlier) and 22.5.5 (and earlier) are affected by an out-of-bounds read vulnerabili...
CVE-2022-23625MEDIUM6.5Wire-ios is a messaging application using the wire protocol on apple's ios platform. In versions prior to 3.95 malformed...
CVE-2022-0924MEDIUM5.5Out-of-bounds Read error in tiffcp in libtiff 4.3.0 allows attackers to cause a denial-of-service via a crafted tiff fil...
CVE-2022-0921MEDIUM6.7Abusing Backup/Restore feature to achieve Remote Code Execution in GitHub repository microweber/microweber prior to 1.2....
CVE-2022-0909MEDIUM5.5Divide By Zero error in tiffcrop in libtiff 4.3.0 allows attackers to cause a denial-of-service via a crafted tiff file....
CVE-2022-0908MEDIUM5.5Null source pointer passed as an argument to memcpy() function within TIFFFetchNormalTag () in tif_dirread.c in libtiff ...
CVE-2022-0907MEDIUM5.5Unchecked Return Value to NULL Pointer Dereference in tiffcrop in libtiff 4.3.0 allows attackers to cause a denial-of-se...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now