2022 CVE Vulnerabilities

27,531 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-35642MEDIUM5.4"IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed ...
CVE-2022-35279MEDIUM4.3"IBM Business Automation Workflow 18.0.0.0, 18.0.0.1, 18.0.0.2, 19.0.0.1, 19.0.0.2, 19.0.0.3, 20.0.0.1, 20.0.0.2, 21.0.2...
CVE-2022-34339MEDIUM6.5"IBM Cognos Analytics 11.2.1, 11.2.0, 11.1.7 stores user credentials in plain clear text which can be read by an authent...
CVE-2022-30615MEDIUM5.4"IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed ...
CVE-2022-30608HIGH8.8"IBM InfoSphere Information Server 11.7 is vulnerable to cross-site request forgery which could allow an attacker to exe...
CVE-2022-25952HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Keywordrush Content Egg plugin <= 5.4.0 on WordPress.
CVE-2022-22442MEDIUM6.5"IBM InfoSphere Information Server 11.7 could allow an authenticated user to access information restricted to users with...
CVE-2022-22425CRITICAL9.8"IBM InfoSphere Information Server 11.7 is potentially vulnerable to CSV Injection. A remote attacker could execute arbi...
CVE-2022-3258HIGH8.8Incorrect Permission Assignment for Critical Resource vulnerability in HYPR Workforce Access on Windows allows Authentic...
CVE-2022-43372MEDIUM4.8Emlog Pro v1.7.1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability at /admin/store.php.
CVE-2022-42753MEDIUM6.1SalonERP version 3.0.2 allows an external attacker to steal the cookie of arbitrary users. This is possible because the ...
CVE-2022-42751HIGH8.8CandidATS version 3.0.0 allows an external attacker to elevate privileges in the application. This is possible because t...
CVE-2022-42750HIGH8.8CandidATS version 3.0.0 allows an external attacker to steal the cookie of arbitrary users. This is possible because the...
CVE-2022-3852MEDIUM6.5The VR Calendar plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.3.3...
CVE-2022-3675MEDIUM5.5Fedora CoreOS supports setting a GRUB bootloader password using a Butane config. When this feature is enabled, GRUB requ...
CVE-2022-3776HIGH8.8The Restaurant Menu – Food Ordering System – Table Reservation plugin for WordPress is vulnerable to Cross-Site Request ...
CVE-2022-2696MEDIUM6.5The Restaurant Menu – Food Ordering System – Table Reservation plugin for WordPress is vulnerable to authorization bypas...
CVE-2022-39376MEDIUM6.5GLPI stands for Gestionnaire Libre de Parc Informatique. GLPI is a Free Asset and IT Management Software package that pr...
CVE-2022-39375MEDIUM5.4GLPI stands for Gestionnaire Libre de Parc Informatique. GLPI is a Free Asset and IT Management Software package that pr...
CVE-2022-39373MEDIUM4.8GLPI stands for Gestionnaire Libre de Parc Informatique. GLPI is a Free Asset and IT Management Software package that pr...
CVE-2022-39372MEDIUM5.4GLPI stands for Gestionnaire Libre de Parc Informatique. GLPI is a Free Asset and IT Management Software package that pr...
CVE-2022-39371MEDIUM5.4GLPI stands for Gestionnaire Libre de Parc Informatique. GLPI is a Free Asset and IT Management Software package that pr...
CVE-2022-39370MEDIUM4.3GLPI stands for Gestionnaire Libre de Parc Informatique. GLPI is a Free Asset and IT Management Software package that pr...
CVE-2022-39277MEDIUM4.8GLPI stands for Gestionnaire Libre de Parc Informatique. GLPI is a Free Asset and IT Management Software package that pr...
CVE-2022-39323CRITICAL9.8GLPI stands for Gestionnaire Libre de Parc Informatique. GLPI is a Free Asset and IT Management Software package that pr...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now