2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-25323MEDIUM6.1ZEROF Web Server 2.0 allows /admin.back XSS.
CVE-2022-23647MEDIUM6.1Prism is a syntax highlighting library. Starting with version 1.14.0 and prior to version 1.27.0, Prism's command line p...
CVE-2022-0451MEDIUM6.5Dart SDK contains the HTTPClient in dart:io library whcih includes authorization headers when handling cross origin redi...
CVE-2022-25321MEDIUM6.1An issue was discovered in Cerebrate through 1.4. XSS could occur in the bookmarks component.
CVE-2022-25320MEDIUM5.3An issue was discovered in Cerebrate through 1.4. Username enumeration could occur.
CVE-2022-25319MEDIUM5.3An issue was discovered in Cerebrate through 1.4. Endpoints could be open even when not enabled.
CVE-2022-25318MEDIUM4.3An issue was discovered in Cerebrate through 1.4. An incorrect sharing group ACL allowed an unprivileged user to edit an...
CVE-2022-25317MEDIUM6.1An issue was discovered in Cerebrate through 1.4. genericForm allows reflected XSS in form descriptions via a user-contr...
CVE-2022-25313MEDIUM6.5In Expat (aka libexpat) before 2.4.5, an attacker can trigger stack exhaustion in build_model via a large nesting depth ...
CVE-2022-0633MEDIUM6.5The UpdraftPlus WordPress plugin Free before 1.22.3 and Premium before 2.22.3 do not properly validate a user has the re...
CVE-2022-0639MEDIUM5.3Authorization Bypass Through User-Controlled Key in NPM url-parse prior to 1.5.7.
CVE-2022-0638MEDIUM4.3Cross-Site Request Forgery (CSRF) in Packagist microweber/microweber prior to 1.2.11.
CVE-2022-20659MEDIUM6.1A vulnerability in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Netwo...
CVE-2022-23319MEDIUM5.5A segmentation fault during PCF file parsing in pcf2bdf versions >=1.05 allows an attacker to trigger a program crash vi...
CVE-2022-22899MEDIUM5.5Core FTP / SFTP Server v2 Build 725 was discovered to allow unauthenticated attackers to cause a Denial of Service (DoS)...
CVE-2022-24953MEDIUM5.3The Crypt_GPG extension before 1.6.7 for PHP does not prevent additional options in GPG calls, which presents a risk for...
CVE-2022-22901MEDIUM5.5There is an Assertion in 'context_p->next_scanner_info_p->type == SCANNER_TYPE_FUNCTION' failed at parser_parse_function...
CVE-2022-0622MEDIUM5.3Generation of Error Message Containing Sensitive Information in Packagist snipe/snipe-it prior to 5.3.11.
CVE-2022-25270MEDIUM6.5The Quick Edit module does not properly check entity access in some circumstances. This could result in users with the "...
CVE-2022-24982MEDIUM6.5Forms generated by JQueryForm.com before 2022-02-05 allows a remote authenticated attacker to access the cleartext crede...
CVE-2022-24981MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability in forms generated by JQueryForm.com before 2022-02-05 allows remot...
CVE-2022-25258MEDIUM4.6An issue was discovered in drivers/usb/gadget/composite.c in the Linux kernel before 5.16.10. The USB Gadget subsystem l...
CVE-2022-22853MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in Hospital Patient Record Management System v1.0 allows attackers to ...
CVE-2022-23204MEDIUM5.5Adobe Premiere Rush versions 2.0 and earlier are affected by an out-of-bounds read vulnerability that could lead to disc...
CVE-2022-23199MEDIUM5.5Adobe Illustrator versions 25.4.3 (and earlier) and 26.0.2 (and earlier) are affected by a Null pointer dereference vuln...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now