2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-25413MEDIUM5.4Maxsite CMS v108 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the parameter f_tags at...
CVE-2022-25410MEDIUM5.4Maxsite CMS v180 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the parameter f_file_de...
CVE-2022-25409MEDIUM5.4Hospital Management System v1.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the dema...
CVE-2022-25408MEDIUM5.4Hospital Management System v1.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the dpas...
CVE-2022-25407MEDIUM5.4Hospital Management System v1.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Doct...
CVE-2022-25028MEDIUM6.1Home Owners Collection Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via t...
CVE-2022-23907MEDIUM6.1CMS Made Simple v2.2.15 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the parameter...
CVE-2022-0743MEDIUM4.6Cross-site Scripting (XSS) - Stored in GitHub repository getgrav/grav prior to 1.7.31.
CVE-2022-26315MEDIUM5.3qrcp through 0.8.4, in receive mode, allows ../ Directory Traversal via the file name specified by the uploader.
CVE-2022-25015MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in Ice Hrm 30.0.0.OS allows attackers to steal cookies via a crafted p...
CVE-2022-25014MEDIUM6.1Ice Hrm 30.0.0.OS was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the "m" parameter i...
CVE-2022-25013MEDIUM6.1Ice Hrm 30.0.0.OS was discovered to contain multiple reflected cross-site scripting (XSS) vulnerabilities via the "key" ...
CVE-2022-26158MEDIUM6.1An issue was discovered in the web application in Cherwell Service Management (CSM) 10.2.3. It accepts and reflects arbi...
CVE-2022-26157MEDIUM5.3An issue was discovered in the web application in Cherwell Service Management (CSM) 10.2.3. The ASP.NET_Sessionid cookie...
CVE-2022-26156MEDIUM6.1An issue was discovered in the web application in Cherwell Service Management (CSM) 10.2.3. Injection of a malicious pay...
CVE-2022-26155MEDIUM6.1An issue was discovered in the web application in Cherwell Service Management (CSM) 10.2.3. XSS can occur via a payload ...
CVE-2022-25642MEDIUM6.1Obyte (formerly Byteball) Wallet before 3.4.1 allows XSS. A crafted chat message can lead to remote code execution.
CVE-2022-24572MEDIUM6.1Car Driving School Management System v1.0 is affected by Cross Site Scripting (XSS) in the User Enrollment Form (Usernam...
CVE-2022-23988MEDIUM6.1The WS Form LITE and Pro WordPress plugins before 1.8.176 do not sanitise and escape submitted form data, allowing unaut...
CVE-2022-23987MEDIUM4.8The WS Form LITE and Pro WordPress plugins before 1.8.176 do not sanitise and escape their Form Name, which could allow ...
CVE-2022-23912MEDIUM6.1The Testimonial WordPress Plugin WordPress plugin before 1.4.7 does not sanitise and escape the id parameter before outp...
CVE-2022-0385MEDIUM6.1The Crazy Bone WordPress plugin through 0.6.0 does not sanitise and escape the username submitted via the login from whe...
CVE-2022-0377MEDIUM4.3Users of the LearnPress WordPress plugin before 4.1.5 can upload an image as a profile avatar after the registration. A...
CVE-2022-0360MEDIUM4.8The Easy Drag And drop All Import : WP Ultimate CSV Importer WordPress plugin before 6.4.3 does not sanitise and escaped...
CVE-2022-0345MEDIUM4.3The Customize WordPress Emails and Alerts WordPress plugin before 1.8.7 does not have authorisation and CSRF check in it...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now