2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-25413 | MEDIUM | 5.4 | 0.5% | Feb 28, 2022 | Maxsite CMS v108 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the parameter f_tags at... |
| CVE-2022-25410 | MEDIUM | 5.4 | 0.5% | Feb 28, 2022 | Maxsite CMS v180 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the parameter f_file_de... |
| CVE-2022-25409 | MEDIUM | 5.4 | 0.5% | Feb 28, 2022 | Hospital Management System v1.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the dema... |
| CVE-2022-25408 | MEDIUM | 5.4 | 0.5% | Feb 28, 2022 | Hospital Management System v1.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the dpas... |
| CVE-2022-25407 | MEDIUM | 5.4 | 0.5% | Feb 28, 2022 | Hospital Management System v1.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Doct... |
| CVE-2022-25028 | MEDIUM | 6.1 | 0.6% | Feb 28, 2022 | Home Owners Collection Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via t... |
| CVE-2022-23907 | MEDIUM | 6.1 | 0.6% | Feb 28, 2022 | CMS Made Simple v2.2.15 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the parameter... |
| CVE-2022-0743 | MEDIUM | 4.6 | 1.3% | Feb 28, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository getgrav/grav prior to 1.7.31. |
| CVE-2022-26315 | MEDIUM | 5.3 | 1.2% | Feb 28, 2022 | qrcp through 0.8.4, in receive mode, allows ../ Directory Traversal via the file name specified by the uploader. |
| CVE-2022-25015 | MEDIUM | 5.4 | 0.7% | Feb 28, 2022 | A stored cross-site scripting (XSS) vulnerability in Ice Hrm 30.0.0.OS allows attackers to steal cookies via a crafted p... |
| CVE-2022-25014 | MEDIUM | 6.1 | 0.7% | Feb 28, 2022 | Ice Hrm 30.0.0.OS was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the "m" parameter i... |
| CVE-2022-25013 | MEDIUM | 6.1 | 0.7% | Feb 28, 2022 | Ice Hrm 30.0.0.OS was discovered to contain multiple reflected cross-site scripting (XSS) vulnerabilities via the "key" ... |
| CVE-2022-26158 | MEDIUM | 6.1 | 0.7% | Feb 28, 2022 | An issue was discovered in the web application in Cherwell Service Management (CSM) 10.2.3. It accepts and reflects arbi... |
| CVE-2022-26157 | MEDIUM | 5.3 | 0.5% | Feb 28, 2022 | An issue was discovered in the web application in Cherwell Service Management (CSM) 10.2.3. The ASP.NET_Sessionid cookie... |
| CVE-2022-26156 | MEDIUM | 6.1 | 0.7% | Feb 28, 2022 | An issue was discovered in the web application in Cherwell Service Management (CSM) 10.2.3. Injection of a malicious pay... |
| CVE-2022-26155 | MEDIUM | 6.1 | 0.7% | Feb 28, 2022 | An issue was discovered in the web application in Cherwell Service Management (CSM) 10.2.3. XSS can occur via a payload ... |
| CVE-2022-25642 | MEDIUM | 6.1 | 1.4% | Feb 28, 2022 | Obyte (formerly Byteball) Wallet before 3.4.1 allows XSS. A crafted chat message can lead to remote code execution. |
| CVE-2022-24572 | MEDIUM | 6.1 | 0.6% | Feb 28, 2022 | Car Driving School Management System v1.0 is affected by Cross Site Scripting (XSS) in the User Enrollment Form (Usernam... |
| CVE-2022-23988 | MEDIUM | 6.1 | 2.2% | Feb 28, 2022 | The WS Form LITE and Pro WordPress plugins before 1.8.176 do not sanitise and escape submitted form data, allowing unaut... |
| CVE-2022-23987 | MEDIUM | 4.8 | 0.6% | Feb 28, 2022 | The WS Form LITE and Pro WordPress plugins before 1.8.176 do not sanitise and escape their Form Name, which could allow ... |
| CVE-2022-23912 | MEDIUM | 6.1 | 0.9% | Feb 28, 2022 | The Testimonial WordPress Plugin WordPress plugin before 1.4.7 does not sanitise and escape the id parameter before outp... |
| CVE-2022-0385 | MEDIUM | 6.1 | 1.4% | Feb 28, 2022 | The Crazy Bone WordPress plugin through 0.6.0 does not sanitise and escape the username submitted via the login from whe... |
| CVE-2022-0377 | MEDIUM | 4.3 | 3.2% | Feb 28, 2022 | Users of the LearnPress WordPress plugin before 4.1.5 can upload an image as a profile avatar after the registration. A... |
| CVE-2022-0360 | MEDIUM | 4.8 | 0.6% | Feb 28, 2022 | The Easy Drag And drop All Import : WP Ultimate CSV Importer WordPress plugin before 6.4.3 does not sanitise and escaped... |
| CVE-2022-0345 | MEDIUM | 4.3 | 0.4% | Feb 28, 2022 | The Customize WordPress Emails and Alerts WordPress plugin before 1.8.7 does not have authorisation and CSRF check in it... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now