2022 CVE Vulnerabilities

27,525 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-43485MEDIUM6.5 Use of Insufficiently Random Values in Honeywell OneWireless. This vulnerability may allow attacker to manipulate claim...
CVE-2022-45853MEDIUM6.7The privilege escalation vulnerability in the Zyxel GS1900-8 firmware version V2.70(AAHH.3) and the GS1900-8HP firmwar...
CVE-2022-4676MEDIUM5.4The OSM WordPress plugin through 6.01 does not validate and escape some of its shortcode attributes, which could allow u...
CVE-2022-41766MEDIUM4.3An issue was discovered in MediaWiki before 1.35.8, 1.36.x and 1.37.x before 1.37.5, and 1.38.x before 1.38.3. Upon an a...
CVE-2022-24632MEDIUM5.3An issue was discovered in AudioCodes Device Manager Express through 7.8.20002.47752. It is directory traversal during f...
CVE-2022-24631MEDIUM5.4An issue was discovered in AudioCodes Device Manager Express through 7.8.20002.47752. It is stored XSS via the ajaxTenan...
CVE-2022-46945MEDIUM6.5Nagvis before 1.9.34 was discovered to contain an arbitrary file read vulnerability via the component /core/classes/NagV...
CVE-2022-39374MEDIUM6.5Synapse is an open-source Matrix homeserver written and maintained by the Matrix.org Foundation. If Synapse and a malici...
CVE-2022-39335MEDIUM5Synapse is an open-source Matrix homeserver written and maintained by the Matrix.org Foundation. The Matrix Federation A...
CVE-2022-45366MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Jason Crouse, VeronaLabs Slimstat Analytics plugin <= 5.0....
CVE-2022-46907MEDIUM6.1A carefully crafted request on several JSPWiki plugins could trigger an XSS vulnerability on Apache JSPWiki, which could...
CVE-2022-30025MEDIUM6.5SQL injection in "/Framewrk/Home.jsp" file (POST method) in tCredence Analytics iDEAL Wealth and Funds - 1.0 iallows aut...
CVE-2022-42225MEDIUM5.4Jumpserver 2.10.0 <= version <= 2.26.0 contains multiple stored XSS vulnerabilities because of improper filtering of use...
CVE-2022-4945MEDIUM6.5The Dataprobe cloud usernames and passwords are stored in plain text in a specific file. Any user able to read this spec...
CVE-2022-0010MEDIUM5.5Insertion of Sensitive Information into Log File vulnerability in ABB QCS 800xA, ABB QCS AC450, ABB Platform Engineering...
CVE-2022-36328MEDIUM4.9Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could allow an attacke...
CVE-2022-36326MEDIUM4.9An uncontrolled resource consumption vulnerability issue that could arise by sending crafted requests to a service to co...
CVE-2022-47157MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Don Benjamin WP Custom Fields Search plugin <= 1.2.34 ...
CVE-2022-4870MEDIUM5.3In affected versions of Octopus Deploy it is possible to discover network details via error message
CVE-2022-45144MEDIUM6.1Algoo Tracim before 4.4.2 allows XSS via HTML file upload.
CVE-2022-47393MEDIUM6.5An authenticated, remote attacker may use a Improper Restriction of Operations within the Bounds of a Memory Buffer vuln...
CVE-2022-47392MEDIUM6.5An authenticated, remote attacker may use a improper input validation vulnerability in the CmpApp/CmpAppBP/CmpAppForce C...
CVE-2022-47378MEDIUM6.5Multiple CODESYS products in multiple versions are prone to a improper input validation vulnerability. An authenticated ...
CVE-2022-22508MEDIUM4.3Improper Input Validation vulnerability in multiple CODESYS V3 products allows an authenticated remote attacker to block...
CVE-2022-48020MEDIUM6.1Vinteo VCC v2.36.4 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the conference par...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now