2022 CVE Vulnerabilities

27,538 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-36097MEDIUM6.1XWiki Platform Attachment UI provides a macro to easily upload and select attachments for XWiki Platform, a generic wiki...
CVE-2022-36096CRITICAL9The XWiki Platform Index UI is an Index of all pages, attachments, orphans and deleted pages and attachments for XWiki P...
CVE-2022-36095MEDIUM4.3XWiki Platform is a generic wiki platform. Prior to versions 13.10.5 and 14.3, it is possible to perform a Cross-Site Re...
CVE-2022-36094CRITICAL9XWiki Platform Web Parent POM contains Web resources for the XWiki platform, a generic wiki platform. Starting with vers...
CVE-2022-3167HIGH8.8Improper Restriction of Rendered UI Layers or Frames in GitHub repository ikus060/rdiffweb prior to 2.4.1.
CVE-2022-38258HIGH8.1A local file inclusion (LFI) vulnerability in D-Link DIR 819 v1.06 allows attackers to cause a Denial of Service (DoS) o...
CVE-2022-38256MEDIUM5.4TastyIgniter v3.5.0 was discovered to contain a cross-site scripting (XSS) vulnerability which allows attackers to execu...
CVE-2022-36093HIGH7.1XWiki Platform Web Templates are templates for XWiki Platform, a generic wiki platform. By passing a template of the dis...
CVE-2022-36092HIGH7.5XWiki Platform Old Core is a core package for XWiki Platform, a generic wiki platform. Prior to versions 14.2 and 13.10....
CVE-2022-38260HIGH7.2Interview Management System v1.0 was discovered to contain a SQL injection vulnerability via the component /interview/de...
CVE-2022-38255HIGH7.2Interview Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /interv...
CVE-2022-37857HIGH7.5bilde2910 Hauk v1.6.1 requires a hardcoded password which by default is blank. This hardcoded password is hashed but sto...
CVE-2022-37164CRITICAL9.8Inoda OnTrack v3.4 employs a weak password policy which allows attackers to potentially gain unauthorized access to the ...
CVE-2022-37163CRITICAL9.8Bminusl IHateToBudget v1.5.7 employs a weak password policy which allows attackers to potentially gain unauthorized acce...
CVE-2022-36091HIGH7.5XWiki Platform Web Templates are templates for XWiki Platform, a generic wiki platform. Through the suggestion feature, ...
CVE-2022-27969MEDIUM5.3Cynet 360 Web Portal before v4.5 was discovered to allow attackers to access a list of decoy users via a crafted GET req...
CVE-2022-27968MEDIUM5.3Cynet 360 Web Portal before v4.5 was discovered to allow attackers to access a list of monitored files and profiles via ...
CVE-2022-27967MEDIUM5.3Cynet 360 Web Portal before v4.5 was discovered to allow attackers to access a list of excluded files and profiles via a...
CVE-2022-22314LOW3.3IBM Planning Analytics Local 2.0 allows web pages to be stored locally which can be read by another user on the system. ...
CVE-2022-3153MEDIUM5.5NULL Pointer Dereference in GitHub repository vim/vim prior to 9.0.0404.
CVE-2022-36090HIGH8.1XWiki Platform Old Core is a core package for XWiki Platform, a generic wiki platform. Prior to versions 13.1.0.5 and 14...
CVE-2022-36085CRITICAL9.8Open Policy Agent (OPA) is an open source, general-purpose policy engine. The Rego compiler provides a (deprecated) `Wit...
CVE-2022-36736MEDIUM6.1Jitsi-2.10.5550 was discovered to contain a vulnerability in its web UI which allows attackers to perform a clickjacking...
CVE-2022-20923CRITICAL9.8A vulnerability in the IPSec VPN Server authentication functionality of Cisco Small Business RV110W, RV130, RV130W, and ...
CVE-2022-20863MEDIUM5.3A vulnerability in the messaging interface of Cisco Webex App, formerly Webex Teams, could allow an unauthenticated, rem...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now