2022 CVE Vulnerabilities

27,525 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-45065MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Squirrly SEO Plugin by Squirrly SEO plugin <= 12.1.20 vers...
CVE-2022-45812MEDIUM5.4Auth. (subscriber+) Stored Cross-Site Scripting (XSS) vulnerability in Martin Lees Exxp plugin <= 2.6.8 versions.
CVE-2022-46799MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in I Thirteen Web Solution Easy Testimonial Slider and Form p...
CVE-2022-43877MEDIUM5.1IBM UrbanCode Deploy (UCD) versions up to 7.3.0.1 could disclose sensitive password information during a manual edit of ...
CVE-2022-43866MEDIUM5.4IBM Maximo Asset Management 7.6.1.2 and 7.6.1.3 is vulnerable to cross-site scripting. This vulnerability allows users t...
CVE-2022-43919MEDIUM6.5IBM MQ 9.2 CD, 9.2 LTS, 9.3 CD, and 9.3 LTS could allow an authenticated attacker with authorization to craft messages t...
CVE-2022-38707MEDIUM5.5IBM Cognos Command Center 10.2.4.1 could allow a local attacker to obtain sensitive information due to insufficient sess...
CVE-2022-47449MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in RexTheme Cart Lift – Abandoned Cart Recovery for WooCommer...
CVE-2022-47434MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in PB SEO Friendly Images plugin <= 4.0.5 versions.
CVE-2022-45818MEDIUM5.4Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in WP OnlineSupport, Essential Plugin Hero Banner U...
CVE-2022-4376MEDIUM4.3An issue has been discovered in GitLab affecting all versions before 15.9.6, all versions starting from 15.10 before 15....
CVE-2022-45859MEDIUM4.4An insufficiently protected credentials vulnerability [CWE-522] in FortiNAC-F 7.2.0, FortiNAC 9.4.1 and below, 9.2.6 and...
CVE-2022-43950MEDIUM4.7A URL redirection to untrusted site ('Open Redirect') vulnerability [CWE-601] in FortiNAC-F version 7.2.0, FortiNAC vers...
CVE-2022-39161MEDIUM5.3IBM WebSphere Application Server 7.0, 8.0, 8.5, 9.0, and IBM WebSphere Application Server Liberty, when configured to co...
CVE-2022-46852MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WP Table Builder plugin <= 1.4.6 versions.
CVE-2022-43681MEDIUM6.5An out-of-bounds read exists in the BGP daemon of FRRouting FRR through 8.4. When sending a malformed BGP OPEN message t...
CVE-2022-40318MEDIUM6.5An issue was discovered in bgpd in FRRouting (FRR) through 8.4. By crafting a BGP OPEN message with an option of type 0x...
CVE-2022-40302MEDIUM6.5An issue was discovered in bgpd in FRRouting (FRR) through 8.4. By crafting a BGP OPEN message with an option of type 0x...
CVE-2022-47877MEDIUM5.4A Stored cross-site scripting vulnerability in Jedox 2020.2.5 allows remote, authenticated users to inject arbitrary web...
CVE-2022-47874MEDIUM6.5Improper Access Control in /tc/rpc in Jedox GmbH Jedox 2020.2.5 allows remote authenticated users to view details of dat...
CVE-2022-33273MEDIUM5.5Information disclosure due to buffer over-read in Trusted Execution Environment while QRKS report generation.
CVE-2022-48186MEDIUM6.2A certificate validation vulnerability exists in the Baiying Android application which could lead to information disclos...
CVE-2022-45801MEDIUM5.4Apache StreamPark 1.0.0 to 2.0.0 have a LDAP injection vulnerability. LDAP Injection is an attack used to exploit web ba...
CVE-2022-43871MEDIUM5.4IBM Financial Transaction Manager for SWIFT Services 3.2.4 is vulnerable to cross-site scripting. This vulnerability all...
CVE-2022-31643MEDIUM5.5A potential security vulnerability has been identified in the system BIOS for certain HP PC products which may allow los...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now