2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-22946MEDIUM5.5In spring cloud gateway versions prior to 3.1.1+ , applications that are configured to enable HTTP2 and no key store or ...
CVE-2022-23397MEDIUM6.1The Cedar Gate EZ-NET portal 6.5.5 6.8.0 Internet portal has a call to display messages to users which does not properly...
CVE-2022-0832MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.3.3.
CVE-2022-0831MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.3.3.
CVE-2022-0752MEDIUM6.1Cross-site Scripting (XSS) - Generic in GitHub repository hestiacp/hestiacp prior to 1.5.9.
CVE-2022-0838MEDIUM6.1Cross-site Scripting (XSS) - Reflected in GitHub repository hestiacp/hestiacp prior to 1.5.10.
CVE-2022-25220MEDIUM4.8PeteReport Version 0.5 allows an authenticated admin user to inject persistent JavaScript code inside the markdown descr...
CVE-2022-24725MEDIUM5.5Shescape is a shell escape package for JavaScript. An issue in versions 1.4.0 to 1.5.1 allows for exposure of the home d...
CVE-2022-23710MEDIUM6.1A cross-site-scripting (XSS) vulnerability was discovered in the Data Preview Pane (previously known as Index Pattern Pr...
CVE-2022-23709MEDIUM4.3A flaw was discovered in Kibana in which users with Read access to the Uptime feature could modify alerting rules. A use...
CVE-2022-23708MEDIUM4.3A flaw was discovered in Elasticsearch 7.17.0’s upgrade assistant, in which upgrading from version 6.x to 7.x would disa...
CVE-2022-23052MEDIUM6.5PeteReport Version 0.5 contains a Cross Site Request Forgery (CSRF) vulnerability allowing an attacker to trick users in...
CVE-2022-23051MEDIUM5.4PeteReport Version 0.5 allows an authenticated admin user to inject persistent JavaScript code while adding an 'Attack T...
CVE-2022-22943MEDIUM6.7VMware Tools for Windows (11.x.y and 10.x.y prior to 12.0.0) contains an uncontrolled search path vulnerability. A malic...
CVE-2022-24723MEDIUM5.3URI.js is a Javascript URL mutation library. Before version 1.19.9, whitespace characters are not removed from the begin...
CVE-2022-22700MEDIUM5.3CyberArk Identity versions up to and including 22.1 in the 'StartAuthentication' resource, exposes the response header '...
CVE-2022-25138MEDIUM5.4Axelor Open Suite v5.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Name paramete...
CVE-2022-0753MEDIUM6.1Cross-site Scripting (XSS) - Reflected in GitHub repository hestiacp/hestiacp prior to 1.5.9.
CVE-2022-23849MEDIUM6.6The biometric lock in Devolutions Password Hub for iOS before 2021.3.4 allows attackers to access the application becaus...
CVE-2022-24573MEDIUM6.1A stored cross-site scripting (XSS) vulnerability in the admin interface in Element-IT HTTP Commander 7.0.0 allows unaut...
CVE-2022-24563MEDIUM5.4In Genixcms v1.1.11, a stored Cross-Site Scripting (XSS) vulnerability exists in /gxadmin/index.php?page=themes&view=opt...
CVE-2022-25146MEDIUM5.3The Remote App module in Liferay Portal Liferay Portal v7.4.3.4 through v7.4.3.8 and Liferay DXP 7.4 before update 5 doe...
CVE-2022-25114MEDIUM6.1Event Management v1.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the full_name p...
CVE-2022-24722MEDIUM6.1VIewComponent is a framework for building view components in Ruby on Rails. Versions prior to 2.31.2 and 2.49.1 contain ...
CVE-2022-23958MEDIUM5.5Potential vulnerabilities have been identified in the BIOS for some HP PC products which may allow denial of service.

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now