2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-0587 | MEDIUM | 6.5 | 1.0% | Feb 15, 2022 | Improper Authorization in Packagist librenms/librenms prior to 22.2.0. |
| CVE-2022-21818 | MEDIUM | 5.4 | 0.3% | Feb 15, 2022 | NVIDIA License System contains a vulnerability in the installation scripts for the DLS virtual appliance, where a user o... |
| CVE-2022-23638 | MEDIUM | 6.1 | 0.7% | Feb 14, 2022 | svg-sanitizer is a SVG/XML sanitizer written in PHP. A cross-site scripting vulnerability impacts all users of the `svg-... |
| CVE-2022-23637 | MEDIUM | 5.4 | 0.5% | Feb 14, 2022 | K-Box is a web-based application to manage documents, images, videos and geodata. Prior to version 0.33.1, a stored Cros... |
| CVE-2022-23391 | MEDIUM | 6.1 | 0.6% | Feb 14, 2022 | A cross-site scripting (XSS) vulnerability in Pybbs v6.0 allows attackers to execute arbitrary web scripts or HTML via a... |
| CVE-2022-0579 | MEDIUM | 6.5 | 1.0% | Feb 14, 2022 | Missing Authorization in Packagist snipe/snipe-it prior to 5.3.9. |
| CVE-2022-23367 | MEDIUM | 6.1 | 0.8% | Feb 14, 2022 | Fulusso v1.1 was discovered to contain a DOM-based cross-site scripting (XSS) vulnerability in /BindAccount/SuccessTips.... |
| CVE-2022-0512 | MEDIUM | 5.3 | 1.8% | Feb 14, 2022 | Authorization Bypass Through User-Controlled Key in NPM url-parse prior to 1.5.6. |
| CVE-2022-24686 | MEDIUM | 5.9 | 0.9% | Feb 14, 2022 | HashiCorp Nomad and Nomad Enterprise 0.3.0 through 1.0.17, 1.1.11, and 1.2.5 artifact download functionality has a race ... |
| CVE-2022-24110 | MEDIUM | 6.5 | 0.8% | Feb 14, 2022 | Kiteworks MFT 7.5 may allow an unauthorized user to reset other users' passwords. This is fixed in version 7.6 and later... |
| CVE-2022-0576 | MEDIUM | 6.1 | 1.0% | Feb 14, 2022 | Cross-site Scripting (XSS) - Generic in Packagist librenms/librenms prior to 22.1.0. |
| CVE-2022-0575 | MEDIUM | 5.4 | 0.8% | Feb 14, 2022 | Cross-site Scripting (XSS) - Stored in Packagist librenms/librenms prior to 22.2.0. |
| CVE-2022-0571 | MEDIUM | 6.1 | 1.3% | Feb 14, 2022 | Cross-site Scripting (XSS) - Reflected in GitHub repository phoronix-test-suite/phoronix-test-suite prior to 10.8.2. |
| CVE-2022-0569 | MEDIUM | 4.3 | 1.0% | Feb 14, 2022 | Observable Discrepancy in Packagist snipe/snipe-it prior to v5.3.9. |
| CVE-2022-0565 | MEDIUM | 6.4 | 1.1% | Feb 14, 2022 | Cross-site Scripting in Packagist pimcore/pimcore prior to 10.3.1. |
| CVE-2022-0212 | MEDIUM | 6.1 | 2.3% | Feb 14, 2022 | The SpiderCalendar WordPress plugin through 1.5.65 does not sanitise and escape the callback parameter before outputting... |
| CVE-2022-0208 | MEDIUM | 6.1 | 2.0% | Feb 14, 2022 | The MapPress Maps for WordPress plugin before 2.73.4 does not sanitise and escape the mapid parameter before outputting ... |
| CVE-2022-0206 | MEDIUM | 6.1 | 1.5% | Feb 14, 2022 | The NewStatPress WordPress plugin before 1.3.6 does not properly escape the whatX parameters before outputting them back... |
| CVE-2022-0201 | MEDIUM | 6.1 | 3.4% | Feb 14, 2022 | The Permalink Manager Lite WordPress plugin before 2.2.15 and Permalink Manager Pro WordPress plugin before 2.2.15 do no... |
| CVE-2022-0200 | MEDIUM | 5.4 | 0.6% | Feb 14, 2022 | Themify Portfolio Post WordPress plugin before 1.1.7 does not sanitise and escape the num_of_pages parameter before outp... |
| CVE-2022-0193 | MEDIUM | 6.1 | 0.9% | Feb 14, 2022 | The Complianz WordPress plugin before 6.0.0 does not escape the s parameter before outputting it back in an attribute in... |
| CVE-2022-0188 | MEDIUM | 5.3 | 2.4% | Feb 14, 2022 | The CMP WordPress plugin before 4.0.19 allows any user, even not logged in, to arbitrarily change the coming soon page l... |
| CVE-2022-0176 | MEDIUM | 6.1 | 0.9% | Feb 14, 2022 | The PowerPack Lite for Beaver Builder WordPress plugin before 1.2.9.3 does not sanitise and escape the tab parameter bef... |
| CVE-2022-0309 | MEDIUM | 6.5 | 0.6% | Feb 12, 2022 | Inappropriate implementation in Autofill in Google Chrome prior to 97.0.4692.99 allowed a remote attacker to bypass navi... |
| CVE-2022-0305 | MEDIUM | 6.5 | 0.6% | Feb 12, 2022 | Inappropriate implementation in Service Worker API in Google Chrome prior to 97.0.4692.99 allowed a remote attacker who ... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now