2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-0587MEDIUM6.5Improper Authorization in Packagist librenms/librenms prior to 22.2.0.
CVE-2022-21818MEDIUM5.4NVIDIA License System contains a vulnerability in the installation scripts for the DLS virtual appliance, where a user o...
CVE-2022-23638MEDIUM6.1svg-sanitizer is a SVG/XML sanitizer written in PHP. A cross-site scripting vulnerability impacts all users of the `svg-...
CVE-2022-23637MEDIUM5.4K-Box is a web-based application to manage documents, images, videos and geodata. Prior to version 0.33.1, a stored Cros...
CVE-2022-23391MEDIUM6.1A cross-site scripting (XSS) vulnerability in Pybbs v6.0 allows attackers to execute arbitrary web scripts or HTML via a...
CVE-2022-0579MEDIUM6.5Missing Authorization in Packagist snipe/snipe-it prior to 5.3.9.
CVE-2022-23367MEDIUM6.1Fulusso v1.1 was discovered to contain a DOM-based cross-site scripting (XSS) vulnerability in /BindAccount/SuccessTips....
CVE-2022-0512MEDIUM5.3Authorization Bypass Through User-Controlled Key in NPM url-parse prior to 1.5.6.
CVE-2022-24686MEDIUM5.9HashiCorp Nomad and Nomad Enterprise 0.3.0 through 1.0.17, 1.1.11, and 1.2.5 artifact download functionality has a race ...
CVE-2022-24110MEDIUM6.5Kiteworks MFT 7.5 may allow an unauthorized user to reset other users' passwords. This is fixed in version 7.6 and later...
CVE-2022-0576MEDIUM6.1Cross-site Scripting (XSS) - Generic in Packagist librenms/librenms prior to 22.1.0.
CVE-2022-0575MEDIUM5.4Cross-site Scripting (XSS) - Stored in Packagist librenms/librenms prior to 22.2.0.
CVE-2022-0571MEDIUM6.1Cross-site Scripting (XSS) - Reflected in GitHub repository phoronix-test-suite/phoronix-test-suite prior to 10.8.2.
CVE-2022-0569MEDIUM4.3Observable Discrepancy in Packagist snipe/snipe-it prior to v5.3.9.
CVE-2022-0565MEDIUM6.4Cross-site Scripting in Packagist pimcore/pimcore prior to 10.3.1.
CVE-2022-0212MEDIUM6.1The SpiderCalendar WordPress plugin through 1.5.65 does not sanitise and escape the callback parameter before outputting...
CVE-2022-0208MEDIUM6.1The MapPress Maps for WordPress plugin before 2.73.4 does not sanitise and escape the mapid parameter before outputting ...
CVE-2022-0206MEDIUM6.1The NewStatPress WordPress plugin before 1.3.6 does not properly escape the whatX parameters before outputting them back...
CVE-2022-0201MEDIUM6.1The Permalink Manager Lite WordPress plugin before 2.2.15 and Permalink Manager Pro WordPress plugin before 2.2.15 do no...
CVE-2022-0200MEDIUM5.4Themify Portfolio Post WordPress plugin before 1.1.7 does not sanitise and escape the num_of_pages parameter before outp...
CVE-2022-0193MEDIUM6.1The Complianz WordPress plugin before 6.0.0 does not escape the s parameter before outputting it back in an attribute in...
CVE-2022-0188MEDIUM5.3The CMP WordPress plugin before 4.0.19 allows any user, even not logged in, to arbitrarily change the coming soon page l...
CVE-2022-0176MEDIUM6.1The PowerPack Lite for Beaver Builder WordPress plugin before 1.2.9.3 does not sanitise and escape the tab parameter bef...
CVE-2022-0309MEDIUM6.5Inappropriate implementation in Autofill in Google Chrome prior to 97.0.4692.99 allowed a remote attacker to bypass navi...
CVE-2022-0305MEDIUM6.5Inappropriate implementation in Service Worker API in Google Chrome prior to 97.0.4692.99 allowed a remote attacker who ...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now