2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-24329MEDIUM5.3In JetBrains Kotlin before 1.6.0, it was not possible to lock dependencies for Multiplatform Gradle Projects.
CVE-2022-24328MEDIUM6.5In JetBrains Hub before 2021.1.13956, an unprivileged user could perform DoS.
CVE-2022-24612MEDIUM5.4An authenticated user can upload an XML file containing an XSS via the ITSM module of EyesOfNetwork 5.3.11, resulting in...
CVE-2022-24594MEDIUM5.3In waline 1.6.1, an attacker can submit messages using X-Forwarded-For to forge any IP address.
CVE-2022-25327MEDIUM5.5The PAM module for fscrypt doesn't adequately validate fscrypt metadata files, allowing users to create malicious metada...
CVE-2022-25326MEDIUM5.5fscrypt through v0.3.2 creates a world-writable directory by default when setting up a filesystem, allowing unprivileged...
CVE-2022-0247MEDIUM5.5An issue exists in Fuchsia where VMO data can be modified through access to copy-on-write snapshots. A local attacker co...
CVE-2022-24948MEDIUM6.1A carefully crafted user preferences for submission could trigger an XSS vulnerability on Apache JSPWiki, related to the...
CVE-2022-0746MEDIUM4.3Business Logic Errors in GitHub repository dolibarr/dolibarr prior to 16.0.
CVE-2022-23701MEDIUM5.3A potential remote host header injection security vulnerability has been identified in HPE Integrated Lights-Out 4 (iLO ...
CVE-2022-24709MEDIUM6.1@awsui/components-react is the main AWS UI package which contains React components, with TypeScript definitions designed...
CVE-2022-25307MEDIUM6.1The WP Statistics WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escaping and sanitization o...
CVE-2022-25306MEDIUM6.1The WP Statistics WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escaping and sanitization o...
CVE-2022-25305MEDIUM6.1The WP Statistics WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escaping and sanitization o...
CVE-2022-23135MEDIUM6.5There is a directory traversal vulnerability in some home gateway products of ZTE. Due to the lack of verification of us...
CVE-2022-0710MEDIUM6.1The Header Footer Code Manager plugin <= 1.1.16 for WordPress is vulnerable to Reflected Cross-Site Scripting (XSS) via ...
CVE-2022-0683MEDIUM6.1The Essential Addons for Elementor Lite WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escap...
CVE-2022-0653MEDIUM6.1The Profile Builder – User Profile & User Registration Forms WordPress plugin is vulnerable to Cross-Site Scripting due ...
CVE-2022-0544MEDIUM5.5An integer underflow in the DDS loader of Blender leads to an out-of-bounds read, possibly allowing an attacker to read ...
CVE-2022-22349MEDIUM4.3IBM Sterling External Authentication Server 3.4.3.2, 6.0.2.0, and 6.0.3.0 is vulnerable to path traversals, due to not p...
CVE-2022-24708MEDIUM5.4Anuko Time Tracker is an open source, web-based time tracking application written in PHP. ttUser.class.php in Time Track...
CVE-2022-24687MEDIUM6.5HashiCorp Consul and Consul Enterprise 1.9.0 through 1.9.14, 1.10.7, and 1.11.2 clusters with at least one Ingress Gatew...
CVE-2022-25638MEDIUM6.5In wolfSSL before 5.2.0, certificate validation may be bypassed during attempted authentication by a TLS 1.3 client to a...
CVE-2022-25363MEDIUM6.5WatchGuard Firebox and XTM appliances allow an authenticated remote attacker with unprivileged credentials to modify pri...
CVE-2022-25355MEDIUM5.3EC-CUBE 3.0.0 to 3.0.18-p3 and EC-CUBE 4.0.0 to 4.1.1 improperly handle HTTP Host header values, which may lead a remote...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now