2022 CVE Vulnerabilities

27,525 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-25091MEDIUM5.3Infopop Ultimate Bulletin Board up to v5.47a was discovered to allow all messages posted inside private forums to be dis...
CVE-2022-38730MEDIUM6.3Docker Desktop for Windows before 4.6 allows attackers to overwrite any file through the windowscontainers/start dockerB...
CVE-2022-45876MEDIUM5.5Versions of VISAM VBASE Automation Base prior to 11.7.5 may disclose information if a valid user opens a specially craft...
CVE-2022-27979MEDIUM5.4A cross-site scripting (XSS) vulnerability in ToolJet v1.6.0 allows attackers to execute arbitrary web scripts or HTML v...
CVE-2022-25278MEDIUM6.5Under certain circumstances, the Drupal core form API evaluates form element access incorrectly. This may lead to a user...
CVE-2022-25276MEDIUM6.1The Media oEmbed iframe route does not properly validate the iframe domain setting, which allows embeds to be displayed ...
CVE-2022-25274MEDIUM5.4Drupal 9.3 implemented a generic entity access API for entity revisions. However, this API was not completely integrated...
CVE-2022-40725MEDIUM6.1PingID Desktop prior to the latest released version 1.7.4 contains a vulnerability that can be exploited to bypass the m...
CVE-2022-40723MEDIUM6.5The PingID RADIUS PCV adapter for PingFederate, which supports RADIUS authentication with PingID MFA, is vulnerable to M...
CVE-2022-40722MEDIUM5.8A misconfiguration of RSA padding implemented in the PingID Adapter for PingFederate to support Offline MFA with PingID ...
CVE-2022-40482MEDIUM5.3The authentication method in Laravel 8.x through 9.x before 9.32.0 was discovered to be vulnerable to user enumeration v...
CVE-2022-47608MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Fullworks Quick Contact Form plugin <= 8.0.3.1 version...
CVE-2022-45837MEDIUM6.1Reflected Cross-Site Scripting (XSS) vulnerability in Denis 微信机器人高级版 plugin <= 6.0.1 versions.
CVE-2022-28354MEDIUM6.1In the Active Threads Plugin 1.3.0 for MyBB, the activethreads.php date parameter is vulnerable to XSS when setting a ti...
CVE-2022-41612MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Shareaholic Similar Posts plugin <= 3.1.6 versions.
CVE-2022-47598MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WP Plugins Pro WP Super Popup plugin <= 1.1.2 versions...
CVE-2022-47158MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Pakpobox alfred24 Click & Collect plugin <= 1.1.7 vers...
CVE-2022-45084MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Softaculous Loginizer plugin <= 1.7.5 versions.
CVE-2022-47435MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Olive Design WP-OliveCart plugin <= 1.1.3 versions.
CVE-2022-45361MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Boris Kuzmanov 0mk Shortener plugin <= 0.2 versions.
CVE-2022-44743MEDIUM5.4Auth. (author+) Stored Cross-Site Scripting (XSS) vulnerability in BlueGlass Jobs for WordPress plugin <= 2.5.11.2 versi...
CVE-2022-44594MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Codebangers All in One Time Clock Lite plugin <= 1.3.3...
CVE-2022-44631MEDIUM5.4Auth. (author+) Stored Cross-Site Scripting (XSS) vulnerability in 1app Technologies, Inc 1app Business Forms plugin <= ...
CVE-2022-44582MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Apptivo Apptivo Business Site CRM plugin <= 3.0.12 ver...
CVE-2022-47509MEDIUM6.1The SolarWinds Platform was susceptible to the Incorrect Input Neutralization Vulnerability. This vulnerability allows a...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now