2022 CVE Vulnerabilities

27,525 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-35950MEDIUM4.8OroCommerce is an open-source Business to Business Commerce application. In versions 4.1.0 through 4.1.13, 4.2.0 through...
CVE-2022-34355MEDIUM5.5IBM Jazz Foundation (IBM Engineering Lifecycle Management 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2) could disclose sensitiv...
CVE-2022-4145MEDIUM5.3A content spoofing flaw was found in OpenShift's OAuth endpoint. This flaw allows a remote, unauthenticated attacker to ...
CVE-2022-36277MEDIUM6.1The 'sReferencia', 'sDescripcion', 'txtCodigo' and 'txtDescripcion' parameters, in the frmGestionStock.aspx and frmEditS...
CVE-2022-43906MEDIUM5.3IBM Security Guardium 11.5 could disclose sensitive information due to a missing or insecure SameSite attribute for a se...
CVE-2022-4132MEDIUM5.9A flaw was found in JSS. A memory leak in JSS requires non-standard configuration but is a low-effort DoS vector if conf...
CVE-2022-47187MEDIUM6.1There is a file upload XSS vulnerability in Generex CS141 below 2.06 version. The web application allows file uploading,...
CVE-2022-4245MEDIUM4.3A flaw was found in codehaus-plexus. The org.codehaus.plexus.util.xml.XmlWriterUtil#writeComment fails to sanitize comme...
CVE-2022-4137MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability was found in the 'oob' OAuth endpoint due to incorrect null-byte ha...
CVE-2022-3962MEDIUM4.3A content spoofing vulnerability was found in Kiali. It was discovered that Kiali does not implement error handling when...
CVE-2022-3916MEDIUM6.8A flaw was found in the offline_access scope in Keycloak. This issue would affect users of shared computers more (especi...
CVE-2022-1438MEDIUM4.8A flaw was found in Keycloak. Under specific circumstances, HTML entities are not sanitized during user impersonation, r...
CVE-2022-45448MEDIUM6.1M4 PDF plugin for Prestashop sites, in its 3.2.3 version and before, is vulnerable to an arbitrary HTML Document craftin...
CVE-2022-45447MEDIUM6.5M4 PDF plugin for Prestashop sites, in its 3.2.3 version and before, is vulnerable to a directory traversal vulnerabilit...
CVE-2022-47561MEDIUM5.5The web application stores credentials in clear text in the "admin.xml" file, which can be accessed without logging into...
CVE-2022-47560MEDIUM6.5The lack of web request control on ekorCCP and ekorRCI devices allows a potential attacker to create custom requests to ...
CVE-2022-47557MEDIUM6.1Vulnerability in ekorCCP and ekorRCI that could allow an attacker with access to the network where the device is located...
CVE-2022-47556MEDIUM6.5Uncontrolled resource consumption in ekorRCI, allowing an attacker with low-privileged access to the web server to send ...
CVE-2022-3466MEDIUM5.3The version of cri-o as released for Red Hat OpenShift Container Platform 4.9.48, 4.10.31, and 4.11.6 via RHBA-2022:6316...
CVE-2022-20917MEDIUM4.3A vulnerability in the Extensible Messaging and Presence Protocol (XMPP) message processing feature of Cisco Jabber coul...
CVE-2022-47637MEDIUM6.7The installer in XAMPP through 8.1.12 allows local users to write to the C:\xampp directory. Common use cases execute fi...
CVE-2022-34238MEDIUM5.5Acrobat Reader versions 22.001.20142 (and earlier), 20.005.30334 (and earlier) and 20.005.30334 (and earlier) are affect...
CVE-2022-22409MEDIUM5.3IBM Aspera Faspex 5.0.5 could allow a remote attacker to gather sensitive information about the web application, caused ...
CVE-2022-22402MEDIUM5.4IBM Aspera Faspex 5.0.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaSc...
CVE-2022-22405MEDIUM5.9IBM Aspera Faspex 5.0.5 could allow a remote attacker to obtain sensitive information, caused by the failure to properly...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now