2022 CVE Vulnerabilities

27,538 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-36254MEDIUM5.4Multiple persistent cross-site scripting (XSS) vulnerabilities in index.php in tramyardg Hotel Management System 1.0 all...
CVE-2022-34110MEDIUM5.5An issue in Micro-Star International MSI Feature Navigator v1.0.1808.0901 allows attackers to download arbitrary files r...
CVE-2022-34109HIGH7.1An issue in Micro-Star International MSI Feature Navigator v1.0.1808.0901 allows attackers to write arbitrary files to t...
CVE-2022-34108HIGH7.1An issue in the Feature Navigator of Micro-Star International MSI Feature Nagivator v1.0.1808.0901 allows attackers to c...
CVE-2022-38972MEDIUM6.1Cross-site scripting vulnerability in Movable Type plugin A-Form versions prior to 4.1.1 (for Movable Type 7 Series) and...
CVE-2022-37796MEDIUM5.4In Simple Online Book Store System 1.0 in /admin_book.php the Title, Author, and Description parameters are vulnerable t...
CVE-2022-37794CRITICAL9.8In Library Management System 1.0 the /card/in-card.php file id_no parameters are vulnerable to SQL injection.
CVE-2022-40325MEDIUM6.1SysAid Help Desk before 22.1.65 allows XSS via the Asset Dashboard, aka FR# 67262.
CVE-2022-40324MEDIUM6.1SysAid Help Desk before 22.1.65 allows XSS via the Linked SRs field, aka FR# 67258.
CVE-2022-40323MEDIUM6.1SysAid Help Desk before 22.1.65 allows XSS in the Password Services module, aka FR# 67241.
CVE-2022-40322MEDIUM6.1SysAid Help Desk before 22.1.65 allows XSS, aka FR# 66542 and 65579.
CVE-2022-26049HIGH8.8This affects the package com.diffplug.gradle:goomph before 3.37.2. It allows a malicious zip file to potentially break o...
CVE-2022-25295MEDIUM5.4This affects the package github.com/gophish/gophish before 0.12.0. The Open Redirect vulnerability exists in the next qu...
CVE-2022-39135CRITICAL9.8Apache Calcite 1.22.0 introduced the SQL operators EXISTS_NODE, EXTRACT_XML, XML_TRANSFORM and EXTRACT_VALUE do not rest...
CVE-2022-38266MEDIUM6.5An issue in the Leptonica linked library (v1.79.0) allows attackers to cause an arithmetic exception leading to a Denial...
CVE-2022-40320HIGH8.8cfg_tilde_expand in confuse.c in libConfuse 3.3 has a heap-based buffer over-read.
CVE-2022-36087MEDIUM6.5OAuthLib is an implementation of the OAuth request-signing logic for Python 3.6+. In OAuthLib versions 3.1.1 until 3.2.1...
CVE-2022-38638CRITICAL9.1Casdoor v1.97.3 was discovered to contain an arbitrary file write vulnerability via the fullFilePath parameter at /api/u...
CVE-2022-36110HIGH8.8Netmaker makes networks with WireGuard. Prior to version 0.15.1, Improper Authorization functions lead to non-privileged...
CVE-2022-38639MEDIUM5.4A cross-site scripting (XSS) vulnerability in Markdown-Nice v1.8.22 allows attackers to execute arbitrary web scripts or...
CVE-2022-31006HIGH7.5indy-node is the server portion of Hyperledger Indy, a distributed ledger purpose-built for decentralized identity. In v...
CVE-2022-3133HIGH7.8OS Command Injection in GitHub repository jgraph/drawio prior to 20.3.0.
CVE-2022-36109MEDIUM6.3Moby is an open-source project created by Docker to enable software containerization. A bug was found in Moby (Docker En...
CVE-2022-40317MEDIUM5.4OpenKM 6.3.11 allows stored XSS related to the javascript: substring in an A element.
CVE-2022-39810MEDIUM6.1An issue was discovered in WSO2 Enterprise Integrator 6.4.0. A Reflected Cross-Site Scripting (XSS) vulnerability has be...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now