2022 CVE Vulnerabilities

27,543 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-35869CRITICAL9.8This vulnerability allows remote attackers to bypass authentication on affected installations of Inductive Automation Ig...
CVE-2022-34966HIGH7.5OpenTeknik LLC OSSN OPEN SOURCE SOCIAL NETWORK v6.3 LTS was discovered to contain an HTML injection vulnerability via th...
CVE-2022-23000HIGH7.8The Western Digital My Cloud Web App [https://os5.mycloud.com/] uses a weak SSLContext when attempting to configure port...
CVE-2022-22999MEDIUM4.8Western Digital My Cloud devices are vulnerable to a cross side scripting vulnerability that can allow a malicious user ...
CVE-2022-35288MEDIUM6.5IBM Security Verify Information Queue 10.0.2 could allow a user to obtain sensitive information that could be used in fu...
CVE-2022-35287HIGH7.5IBM Security Verify Information Queue 10.0.2 contains hard-coded credentials, such as a password or cryptographic key, w...
CVE-2022-35285HIGH8.8IBM Security Verify Information Queue 10.0.2 is vulnerable to cross-site request forgery which could allow an attacker t...
CVE-2022-35284HIGH7.5IBM Security Verify Information Queue 10.0.2 could disclose sensitive information due to a missing or insecure SameSite ...
CVE-2022-34962MEDIUM5.4OpenTeknik LLC OSSN OPEN SOURCE SOCIAL NETWORK v6.3 LTS was discovered to contain a stored cross-site scripting (XSS) vu...
CVE-2022-33969HIGH7.2Authenticated WordPress Options Change vulnerability in Biplob Adhikari's Flipbox plugin <= 2.6.0 at WordPress.
CVE-2022-2059MEDIUM4.8In Pandora FMS v7.0NG.761 and below, in the agent creation section, the alias parameter is vulnerable to a Stored Cross ...
CVE-2022-2032MEDIUM4.8In Pandora FMS v7.0NG.761 and below, in the file manager section, the dirname parameter is vulnerable to a Stored Cross ...
CVE-2022-24992HIGH7.5A vulnerability in the component process.php of QR Code Generator v5.2.7 allows attackers to perform directory traversal...
CVE-2022-34965HIGH7.2OpenTeknik LLC OSSN OPEN SOURCE SOCIAL NETWORK v6.3 LTS was discovered to contain an arbitrary file upload vulnerability...
CVE-2022-24083CRITICAL9.8Password authentication bypass vulnerability for local accounts can be used to bypass local authentication checks.
CVE-2022-35653MEDIUM6.1A reflected XSS issue was identified in the LTI module of Moodle. The vulnerability exists due to insufficient sanitizat...
CVE-2022-35652MEDIUM6.1An open redirect issue was found in Moodle due to improper sanitization of user-supplied data in mobile auto-login featu...
CVE-2022-35651MEDIUM6.1A stored XSS and blind SSRF vulnerability was found in Moodle, occurs due to insufficient sanitization of user-supplied ...
CVE-2022-35650HIGH7.5The vulnerability was found in Moodle, occurs due to input validation error when importing lesson questions. This insuff...
CVE-2022-35649CRITICAL9.8The vulnerability was found in Moodle, occurs due to improper input validation when parsing PostScript code. An omitted ...
CVE-2022-34964MEDIUM4.8OpenTeknik LLC OSSN OPEN SOURCE SOCIAL NETWORK v6.3 LTS was discovered to contain a stored cross-site scripting (XSS) vu...
CVE-2022-34963MEDIUM5.4OpenTeknik LLC OSSN OPEN SOURCE SOCIAL NETWORK v6.3 LTS was discovered to contain a stored cross-site scripting (XSS) vu...
CVE-2022-34961MEDIUM5.4OpenTeknik LLC OSSN OPEN SOURCE SOCIAL NETWORK v6.3 LTS was discovered to contain a stored cross-site scripting (XSS) vu...
CVE-2022-33965CRITICAL9.8Multiple Unauthenticated SQL Injection (SQLi) vulnerabilities in Osamaesh WP Visitor Statistics plugin <= 5.7 at WordPre...
CVE-2022-2131CRITICAL9.8OpenKM Community Edition in its 6.3.10 version and before was using XMLReader parser in XMLTextExtractor.java file witho...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now