2022 CVE Vulnerabilities

27,528 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-21799MEDIUM5.2Cross-site scripting vulnerability in ELECOM LAN router WRC-300FEBK-R firmware v1.13 and earlier allows an attacker on t...
CVE-2022-0508MEDIUM5.3Server-Side Request Forgery (SSRF) in GitHub repository chocobozzz/peertube prior to f33e515991a32885622b217bf2ed1d1b0d9...
CVE-2022-0506MEDIUM5.4Cross-site Scripting (XSS) - Stored in Packagist microweber/microweber prior to 1.2.11.
CVE-2022-0505MEDIUM6.5Cross-Site Request Forgery (CSRF) in Packagist microweber/microweber prior to 1.2.11.
CVE-2022-0504MEDIUM6.5Generation of Error Message Containing Sensitive Information in Packagist microweber/microweber prior to 1.2.11.
CVE-2022-21816MEDIUM5.5NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (nvidia.ko), where a user in the guest OS can c...
CVE-2022-21815MEDIUM5.5NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for priva...
CVE-2022-21814MEDIUM6.1NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel driver package, where improper handling of in...
CVE-2022-21813MEDIUM6.1NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel driver, where improper handling of insufficie...
CVE-2022-22931MEDIUM4.3Fix of CVE-2021-40525 do not prepend delimiters upon valid directory validations. Affected implementations include: - ma...
CVE-2022-23262MEDIUM6.3Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
CVE-2022-23261MEDIUM5.3Microsoft Edge (Chromium-based) Tampering Vulnerability
CVE-2022-0149MEDIUM6.1The WooCommerce Stored Exporter WordPress plugin before 2.7.1 was affected by a Reflected Cross-Site Scripting (XSS) vul...
CVE-2022-0148MEDIUM5.4The All-in-one Floating Contact Form, Call, Chat, and 50+ Social Icon Tabs WordPress plugin before 2.0.4 was vulnerable ...
CVE-2022-0473MEDIUM4.8OTRS administrators can configure dynamic field and inject malicious JavaScript code in the error message of the regular...
CVE-2022-23184MEDIUM6.1In affected Octopus Server versions when the server HTTP and HTTPS bindings are configured to localhost, Octopus Server ...
CVE-2022-22679MEDIUM4.9Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in support service manageme...
CVE-2022-0502MEDIUM5.4Cross-site Scripting (XSS) - Stored in Packagist remdex/livehelperchat prior to 3.93v.
CVE-2022-0501MEDIUM6.1Cross-site Scripting (XSS) - Reflected in Packagist ptrofimov/beanstalk_console prior to 1.7.12.
CVE-2022-0437MEDIUM6.1Cross-site Scripting (XSS) - DOM in NPM karma prior to 6.3.14.
CVE-2022-23980MEDIUM6.1Cross-Site Scripting (XSS) vulnerability discovered in Yasr – Yet Another Stars Rating WordPress plugin (versions <= 2.9...
CVE-2022-23600MEDIUM6.5fleet is an open source device management, built on osquery. Versions prior to 4.9.1 expose a limited ability to spoof S...
CVE-2022-23595MEDIUM6.5Tensorflow is an Open Source Machine Learning Framework. When building an XLA compilation cache, if default settings are...
CVE-2022-23594MEDIUM5.5Tensorflow is an Open Source Machine Learning Framework. The TFG dialect of TensorFlow (MLIR) makes several assumptions ...
CVE-2022-23589MEDIUM6.5Tensorflow is an Open Source Machine Learning Framework. Under certain scenarios, Grappler component of TensorFlow can t...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now