2022 CVE Vulnerabilities

27,531 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-43167MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in the Users Alerts feature (/index.php?module=users_alerts/users_aler...
CVE-2022-43166MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in the Global Entities feature (/index.php?module=entities/entities) o...
CVE-2022-43165MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in the Global Variables feature (/index.php?module=global_vars/vars) o...
CVE-2022-43164MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in the Global Lists feature (/index.php?module=global_lists/lists) of ...
CVE-2022-3400MEDIUM6.5The Bricks theme for WordPress is vulnerable to authorization bypass due to a missing capability check on the bricks_sav...
CVE-2022-39366CRITICAL9.8DataHub is an open-source metadata platform. Prior to version 0.8.45, the `StatelessTokenService` of the DataHub metadat...
CVE-2022-2864HIGH8.8The demon image annotation plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inclu...
CVE-2022-3697HIGH7.5A flaw was found in Ansible in the amazon.aws collection when using the tower_callback parameter from the amazon.aws.ec2...
CVE-2022-39367MEDIUM6.5QTIWorks is a software suite for standards-based assessment delivery. Prior to version 1.0-beta15, the QTIWorks Engine a...
CVE-2022-37426HIGH7.5Unrestricted Upload of File with Dangerous Type vulnerability in OpenNebula OpenNebula core on Linux allows File Content...
CVE-2022-37425CRITICAL9.8Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in OpenNebula OpenNebu...
CVE-2022-37424MEDIUM6.5Files or Directories Accessible to External Parties vulnerability in OpenNebula on Linux allows File Discovery.
CVE-2022-3018MEDIUM4.9An information disclosure vulnerability in GitLab CE/EE affecting all versions starting from 9.3 before 15.2.5, all vers...
CVE-2022-2882MEDIUM4.3An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.6 before 15.2.5, all versions start...
CVE-2022-43276HIGH7.2Canteen Management System v1.0 was discovered to contain a SQL injection vulnerability via the productId parameter at /p...
CVE-2022-43275HIGH7.2Canteen Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via /youthappam/php_acti...
CVE-2022-3741CRITICAL9.8Impact varies for each individual vulnerability in the application. For generation of accounts, it may be possible, depe...
CVE-2022-3512HIGH8.8Using warp-cli command "add-trusted-ssid", a user was able to disconnect WARP client and bypass the "Lock WARP switch" f...
CVE-2022-3337HIGH8.5It was possible for a user to delete a VPN profile from WARP mobile client on iOS platform despite the Lock WARP switch...
CVE-2022-3322HIGH7.5Lock Warp switch is a feature of Zero Trust platform which, when enabled, prevents users of enrolled devices from disab...
CVE-2022-3321HIGH8.2It was possible to bypass Lock WARP switch feature https://developers.cloudflare.com/cloudflare-one/connections/connect...
CVE-2022-3320CRITICAL9.8It was possible to bypass policies configured for Zero Trust Secure Web Gateway by using warp-cli 'set-custom-endpoint' ...
CVE-2022-3735CRITICAL9.8A vulnerability was found in seccome Ehoney. It has been rated as critical. This issue affects some unknown processing o...
CVE-2022-3734CRITICAL9.8A vulnerability was found in a port or fork of Redis. It has been declared as critical. This vulnerability affects unkno...
CVE-2022-3733HIGH8.8A vulnerability was found in SourceCodester Web-Based Student Clearance System. It has been classified as critical. This...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now