2022 CVE Vulnerabilities

27,525 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-47930MEDIUM6.8An issue was discovered in IO FinNet tss-lib before 2.0.0. The parameter ssid for defining a session id is not used thro...
CVE-2022-48150MEDIUM6.1Shopware v5.5.10 was discovered to contain a cross-site scripting (XSS) vulnerability via the recovery/install/ URI.
CVE-2022-29944MEDIUM5.3An issue was discovered in ONOS 2.5.1. There is an incorrect comparison of paths installed by intents. An existing inten...
CVE-2022-29609MEDIUM5.3An issue was discovered in ONOS 2.5.1. An intent with the same source and destination shows the INSTALLING state, indica...
CVE-2022-24109MEDIUM6.5An issue was discovered in ONOS 2.5.1. To attack an intent installed by a normal user, a remote attacker can install a d...
CVE-2022-4942MEDIUM6.1A vulnerability was found in mportuga eslint-detailed-reporter up to 0.9.0 and classified as problematic. Affected by th...
CVE-2022-2084MEDIUM5.5Sensitive data could be exposed in world readable logs of cloud-init before version 22.3 when schema failures are report...
CVE-2022-38125MEDIUM5.5Improper Restriction of Communication Channel to Intended Endpoints vulnerability in Secomea SiteManager (FTP Agent modu...
CVE-2022-2507MEDIUM5.3In affected versions of Octopus Deploy it is possible to render user supplied input into the webpage
CVE-2022-43378MEDIUM6.5 A CWE-1021: Improper Restriction of Rendered UI Layers or Frames vulnerability exists that could cause the user t...
CVE-2022-43376MEDIUM6.1 A CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists t...
CVE-2022-34755MEDIUM6.7 A CWE-427 - Uncontrolled Search Path Element vulnerability exists that could allow an attacker with a local privileged ...
CVE-2022-45836MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in W3 Eden, Inc. Download Manager plugin <= 3.2.59 versions.
CVE-2022-44632MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Denis Buka Content Repeater – Custom Posts Simplified ...
CVE-2022-45839MEDIUM5.4Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in WHA WHA Puzzle plugin <= 1.0.9 versions.
CVE-2022-45838MEDIUM6.1Unauth. Stored Cross-Site Scripting (XSS) vulnerability in Repute InfoSystems ARForms Form Builder plugin <= 1.5.5 versi...
CVE-2022-44735MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Gus Sevilla WP Clictracker plugin <= 1.0.5 versions.
CVE-2022-46389MEDIUM6.1There exists a reflected XSS within the logout functionality of ServiceNow versions lower than Quebec Patch 10 Hotfix 11...
CVE-2022-44726MEDIUM5.4The TouchDown Timesheet tracking component 4.1.4 for Jira allows XSS in the calendar view.
CVE-2022-45849MEDIUM5.4Auth. (subscriber+) Reflected Cross-Site Scripting (XSS) vulnerability in Silkalns Activello theme <= 1.4.4 versions.
CVE-2022-44734MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in BestWebSoft Car Rental by BestWebSoft plugin <= 1.1.2 ...
CVE-2022-43480MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Magneticlab Sàrl Homepage Pop-up plugin <= 1.2.5 versi...
CVE-2022-43458MEDIUM5.4Auth. (contributor+) Cross-Site Scripting (XSS) vulnerability in Code Tides Advanced Floating Content plugin <= 1.2.1 ve...
CVE-2022-48314MEDIUM6.5The Bluetooth module has a vulnerability of bypassing the user confirmation in the pairing process. Successful exploitat...
CVE-2022-48313MEDIUM6.5The Bluetooth module has a vulnerability of bypassing the user confirmation in the pairing process. Successful exploitat...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now