2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-25290MEDIUM6.5WatchGuard Firebox and XTM appliances allow an authenticated remote attacker with unprivileged credentials to retrieve c...
CVE-2022-24633MEDIUM5.3All versions of FileCloud prior to 21.3 are vulnerable to user enumeration. The vulnerability exists in the parameter "p...
CVE-2022-24620MEDIUM5.4Piwigo version 12.2.0 is vulnerable to stored cross-site scripting (XSS), which can lead to privilege escalation. In thi...
CVE-2022-24615MEDIUM5.5zip4j up to v2.10.0 can throw various uncaught exceptions while parsing a specially crafted ZIP file, which could result...
CVE-2022-24614MEDIUM5.5When reading a specially crafted JPEG file, metadata-extractor up to 2.16.0 can be made to allocate large amounts of mem...
CVE-2022-24613MEDIUM5.5metadata-extractor up to 2.16.0 can throw various uncaught exceptions while parsing a specially crafted JPEG file, which...
CVE-2022-24599MEDIUM6.5In autofile Audio File Library 0.3.6, there exists one memory leak vulnerability in printfileinfo, in printinfo.c, which...
CVE-2022-24582MEDIUM5.4Accounting Journal Management 1.0 is vulnerable to XSS-PHPSESSID-Hijacking. The parameter manage_user from User lists is...
CVE-2022-24566MEDIUM5.4In Checkmk <=2.0.0p19 fixed in 2.0.0p20 and Checkmk <=1.6.0p27 fixed in 1.6.0p28, the title of a Predefined condition is...
CVE-2022-24565MEDIUM5.4Checkmk <=2.0.0p19 Fixed in 2.0.0p20 and Checkmk <=1.6.0p27 Fixed in 1.6.0p28 are affected by a Cross Site Scripting (XS...
CVE-2022-24435MEDIUM6.1Cross-site scripting vulnerability in phpUploader v1.2 and earlier allows a remote unauthenticated attacker to inject an...
CVE-2022-24374MEDIUM6.1Cross-site scripting vulnerability in a-blog cms Ver.2.8.x series versions prior to Ver.2.8.75, Ver.2.9.x series version...
CVE-2022-23916MEDIUM6.1Cross-site scripting vulnerability in a-blog cms Ver.2.8.x series versions prior to Ver.2.8.75, Ver.2.9.x series version...
CVE-2022-23810MEDIUM6.5Template injection (Improper Neutralization of Special Elements Used in a Template Engine) vulnerability in a-blog cms V...
CVE-2022-21179MEDIUM4.3Cross-site request forgery (CSRF) vulnerability in EC-CUBE plugin 'Mail Magazine Management Plugin' ver4.0.0 to 4.1.1 (f...
CVE-2022-0695MEDIUM5.5Denial of Service in GitHub repository radareorg/radare2 prior to 5.6.4.
CVE-2022-23655MEDIUM5.3Octobercms is a self-hosted CMS platform based on the Laravel PHP Framework. Affected versions of OctoberCMS did not val...
CVE-2022-23653MEDIUM4.7B2 Command Line Tool is the official command line tool for the backblaze cloud storage service. Linux and Mac releases o...
CVE-2022-23651MEDIUM4.7b2-sdk-python is a python library to access cloud storage provided by backblaze. Linux and Mac releases of the SDK versi...
CVE-2022-22333MEDIUM6.5IBM Sterling Secure Proxy 6.0.3.0, 6.0.2.0, and 3.4.3.2 and IBM Sterling External Authentication Server are vulnerable a...
CVE-2022-0731MEDIUM6.5Improper Access Control (IDOR) in GitHub repository dolibarr/dolibarr prior to 16.0.
CVE-2022-20625MEDIUM4.3A vulnerability in the Cisco Discovery Protocol service of Cisco FXOS Software and Cisco NX-OS Software could allow an u...
CVE-2022-0476MEDIUM5.5Denial of Service in GitHub repository radareorg/radare2 prior to 5.6.4.
CVE-2022-0727MEDIUM5.4Improper Access Control in GitHub repository chocobozzz/peertube prior to 4.1.0.
CVE-2022-0726MEDIUM5.4Missing Authorization in GitHub repository chocobozzz/peertube prior to 4.1.0.

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now