2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-41877MEDIUM4.6FreeRDP is a free remote desktop protocol library and clients. Affected versions of FreeRDP are missing input length val...
CVE-2022-39383MEDIUM6.5KubeVela is an open source application delivery platform. Users using the VelaUX APIServer could be affected by this vul...
CVE-2022-39347MEDIUM5.7FreeRDP is a free remote desktop protocol library and clients. Affected versions of FreeRDP are missing path canonicaliz...
CVE-2022-39320MEDIUM4.6FreeRDP is a free remote desktop protocol library and clients. Affected versions of FreeRDP may attempt integer addition...
CVE-2022-39316MEDIUM5.7FreeRDP is a free remote desktop protocol library and clients. In affected versions there is an out of bound read in ZGF...
CVE-2022-34354LOW3.3 IBM Sterling Partner Engagement Manager 2.0 allows encrypted storage of client data to be stored locally which can be r...
CVE-2022-44073MEDIUM5.4Zenario CMS 9.3.57186 is vulnerable to Cross Site Scripting (XSS) via svg,Users & Contacts.
CVE-2022-44071MEDIUM5.4Zenario CMS 9.3.57186 is is vulnerable to Cross Site Scripting (XSS) via profile.
CVE-2022-44070MEDIUM5.4Zenario CMS 9.3.57186 is vulnerable to Cross Site Scripting (XSS) via News articles.
CVE-2022-44069MEDIUM5.4Zenario CMS 9.3.57186 is vulnerable to Cross Site Scripting (XSS) via the Nest library module.
CVE-2022-43264HIGH7.5Arobas Music Guitar Pro for iPad and iPhone before v1.10.2 allows attackers to perform directory traversal and download ...
CVE-2022-43263MEDIUM6.1A cross-site scripting (XSS) vulnerability in Arobas Music Guitar Pro for iPad and iPhone before v1.10.2 allows attacker...
CVE-2022-43262CRITICAL9.8Human Resource Management System v1.0 was discovered to contain a SQL injection vulnerability via the password parameter...
CVE-2022-43256CRITICAL9.8SeaCms before v12.6 was discovered to contain a SQL injection vulnerability via the component /js/player/dmplayer/dmku/i...
CVE-2022-43234CRITICAL9.8An arbitrary file upload vulnerability in the /attachments component of Hoosk v1.8 allows attackers to execute arbitrary...
CVE-2022-4022MEDIUM5.4The SVG Support plugin for WordPress defaults to insecure settings in version 2.5 and 2.5.1. SVG files containing malici...
CVE-2022-4021MEDIUM4.3The Permalink Manager Lite plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inclu...
CVE-2022-4018MEDIUM4.3Missing Authentication for Critical Function in GitHub repository ikus060/rdiffweb prior to 2.5.0a6.
CVE-2022-3980CRITICAL9.8An XML External Entity (XEE) vulnerability allows server-side request forgery (SSRF) and potential code execution in Sop...
CVE-2022-24036HIGH8.6Karmasis Informatics Infraskope SIEM+ has an unauthenticated access vulnerability which could allow an unauthenticated a...
CVE-2022-45047CRITICAL9.8Class org.apache.sshd.server.keyprovider.SimpleGeneratorHostKeyProvider in Apache MINA SSHD <= 2.9.1 uses Java deseriali...
CVE-2022-4015CRITICAL9.8A vulnerability, which was classified as critical, was found in Sports Club Management System 119. This affects an unkno...
CVE-2022-4014MEDIUM4.3A vulnerability, which was classified as problematic, has been found in FeehiCMS. Affected by this issue is some unknown...
CVE-2022-4013HIGH8.8A vulnerability classified as problematic was found in Hospital Management Center. Affected by this vulnerability is an ...
CVE-2022-4012CRITICAL9.8A vulnerability classified as critical has been found in Hospital Management Center. Affected is an unknown function of ...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now