2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-0724MEDIUM6.5Insecure Storage of Sensitive Information in GitHub repository microweber/microweber prior to 1.3.
CVE-2022-0721MEDIUM6.5Insertion of Sensitive Information Into Debugging Code in GitHub repository microweber/microweber prior to 1.3.
CVE-2022-0719MEDIUM5.4Cross-site Scripting (XSS) - Reflected in GitHub repository microweber/microweber prior to 1.3.
CVE-2022-23606MEDIUM6.5Envoy is an open source edge and service proxy, designed for cloud-native applications. When a cluster is deleted via Cl...
CVE-2022-21657MEDIUM6.5Envoy is an open source edge and service proxy, designed for cloud-native applications. In affected versions Envoy does ...
CVE-2022-21656MEDIUM5.9Envoy is an open source edge and service proxy, designed for cloud-native applications. The default_validator.cc impleme...
CVE-2022-23654MEDIUM6.5Wiki.js is a wiki app built on Node.js. In affected versions an authenticated user with write access on a restricted set...
CVE-2022-0714MEDIUM5.5Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.4436.
CVE-2022-0712MEDIUM5.5NULL Pointer Dereference in GitHub repository radareorg/radare2 prior to 5.6.4.
CVE-2022-0665MEDIUM6.5Path Traversal in GitHub repository pimcore/pimcore prior to 10.3.2.
CVE-2022-24564MEDIUM6.1Checkmk <=2.0.0p19 contains a Cross Site Scripting (XSS) vulnerability. While creating or editing a user attribute, the ...
CVE-2022-0696MEDIUM5.5NULL Pointer Dereference in GitHub repository vim/vim prior to 8.2.4428.
CVE-2022-0563MEDIUM5.5A flaw was found in the util-linux chfn and chsh utilities when compiled with Readline support. The Readline library use...
CVE-2022-25599MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability leading to event deletion was discovered in Spiffy Calendar WordPress pl...
CVE-2022-0708MEDIUM6.5Mattermost 6.3.0 and earlier fails to protect email addresses of the creator of the team via one of the APIs, which allo...
CVE-2022-0564MEDIUM5.3A vulnerability in Qlik Sense Enterprise on Windows could allow an remote attacker to enumerate domain user accounts. An...
CVE-2022-0692MEDIUM6.1Open Redirect on Rudloff/alltube in Packagist rudloff/alltube prior to 3.0.1.
CVE-2022-0313MEDIUM4.3The Float menu WordPress plugin before 4.3.1 does not have CSRF check in place when deleting menu, which could allow att...
CVE-2022-0288MEDIUM6.1The Ad Inserter WordPress plugin before 2.7.10, Ad Inserter Pro WordPress plugin before 2.7.10 do not sanitise and escap...
CVE-2022-0252MEDIUM6.1The GiveWP WordPress plugin before 2.17.3 does not escape the json parameter before outputting it back in an attribute i...
CVE-2022-0234MEDIUM6.1The WOOCS WordPress plugin before 1.3.7.5 does not sanitise and escape the woocs_in_order_currency parameter of the wooc...
CVE-2022-0211MEDIUM4.8The Shield Security WordPress plugin before 13.0.6 does not sanitise and escape admin notes, which could allow high priv...
CVE-2022-0199MEDIUM4.3The Coming soon and Maintenance mode WordPress plugin before 3.6.8 does not have CSRF check in its coming_soon_send_mail...
CVE-2022-0186MEDIUM5.4The Image Photo Gallery Final Tiles Grid WordPress plugin before 3.5.3 does not sanitise and escape the Description fiel...
CVE-2022-0164MEDIUM4.3The Coming soon and Maintenance mode WordPress plugin before 3.5.3 does not have authorisation and CSRF checks in its co...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now