2022 CVE Vulnerabilities

27,525 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-4955MEDIUM6.5Inappropriate implementation in DevTools in Google Chrome prior to 108.0.5359.71 allowed an attacker who convinced a use...
CVE-2022-41401MEDIUM6.5OpenRefine <= v3.5.2 contains a Server-Side Request Forgery (SSRF) vulnerability, which permits unauthorized users to ex...
CVE-2022-26838MEDIUM6.5Path traversal vulnerability in Importing Mobile Device Data of Cybozu Remote Service 3.1.2 allows a remote authenticate...
CVE-2022-2416MEDIUM4.3In affected versions of Octopus Deploy it is possible for a low privileged guest user to craft a request that allows enu...
CVE-2022-2346MEDIUM4.3In affected versions of Octopus Deploy it is possible for a low privileged guest user to interact with extension endpoin...
CVE-2022-42182MEDIUM5.3Precisely Spectrum Spatial Analyst 20.01 is vulnerable to Directory Traversal.
CVE-2022-4888MEDIUM6.5The Checkout Fields Manager WordPress plugin before 1.0.2, Abandoned Cart Recovery WordPress plugin before 1.2.5, Custom...
CVE-2022-4926MEDIUM6.5Insufficient policy enforcement in Intents in Google Chrome on Android prior to 109.0.5414.119 allowed a remote attacker...
CVE-2022-4925MEDIUM6.5Insufficient validation of untrusted input in QUIC in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to p...
CVE-2022-4922MEDIUM6.5Inappropriate implementation in Blink in Google Chrome prior to 99.0.4844.51 allowed a remote attacker to perform UI spo...
CVE-2022-4917MEDIUM4.3Incorrect security UI in Notifications in Google Chrome on Android prior to 103.0.5060.53 allowed a remote attacker to o...
CVE-2022-4915MEDIUM6.5Inappropriate implementation in URL Formatting in Google Chrome prior to 103.0.5060.134 allowed a remote attacker to per...
CVE-2022-4913MEDIUM6.5Inappropriate implementation in Extensions in Google Chrome prior to 105.0.5195.52 allowed a remote attacker who had com...
CVE-2022-4911MEDIUM6.5Insufficient data validation in DevTools in Google Chrome prior to 106.0.5249.62 allowed a remote attacker to bypass con...
CVE-2022-4910MEDIUM5.4Inappropriate implementation in Autofill in Google Chrome prior to 107.0.5304.62 allowed a remote attacker to bypass nav...
CVE-2022-4909MEDIUM6.3Inappropriate implementation in XML in Google Chrome prior to 107.0.5304.62 allowed a remote attacker to potentially per...
CVE-2022-4908MEDIUM4.3Inappropriate implementation in iFrame Sandbox in Google Chrome prior to 107.0.5304.62 allowed a remote attacker to leak...
CVE-2022-31454MEDIUM6.1Yii 2 v2.0.45 was discovered to contain a cross-site scripting (XSS) vulnerability via the endpoint /books. NOTE: this i...
CVE-2022-31200MEDIUM6.1Atmail 5.62 allows XSS via the mail/parse.php?file=html/$this-%3ELanguage/help/filexp.html&FirstLoad=1&HelpFile=file.htm...
CVE-2022-31455MEDIUM6.1* A cross-site scripting (XSS) vulnerability in Truedesk v1.2.2 allows attackers to execute arbitrary web scripts or HTM...
CVE-2022-31456MEDIUM6.1A cross-site scripting (XSS) vulnerability in Truedesk v1.2.2 allows attackers to execute arbitrary web scripts or HTML ...
CVE-2022-43712MEDIUM6.5POST requests to /web/mvc in GX Software XperienCentral version 10.36.0 and earlier were not blocked for uses that are n...
CVE-2022-43711MEDIUM6.1Interactive Forms (IAF) in GX Software XperienCentral versions 10.29.1 until 10.33.0 was vulnerable to cross site script...
CVE-2022-46900MEDIUM6.5An issue was discovered in Vocera Report Server and Voice Server 5.x through 5.8. There is Path Traversal in the Task Ex...
CVE-2022-31458MEDIUM6.1RTX TRAP v1.0 was discovered to be vulnerable to host header poisoning.

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now