2022 CVE Vulnerabilities
27,525 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-47930 | MEDIUM | 6.8 | 0.5% | Apr 21, 2023 | An issue was discovered in IO FinNet tss-lib before 2.0.0. The parameter ssid for defining a session id is not used thro... |
| CVE-2022-48150 | MEDIUM | 6.1 | 0.6% | Apr 21, 2023 | Shopware v5.5.10 was discovered to contain a cross-site scripting (XSS) vulnerability via the recovery/install/ URI. |
| CVE-2022-29944 | MEDIUM | 5.3 | 0.8% | Apr 20, 2023 | An issue was discovered in ONOS 2.5.1. There is an incorrect comparison of paths installed by intents. An existing inten... |
| CVE-2022-29609 | MEDIUM | 5.3 | 0.6% | Apr 20, 2023 | An issue was discovered in ONOS 2.5.1. An intent with the same source and destination shows the INSTALLING state, indica... |
| CVE-2022-24109 | MEDIUM | 6.5 | 0.9% | Apr 20, 2023 | An issue was discovered in ONOS 2.5.1. To attack an intent installed by a normal user, a remote attacker can install a d... |
| CVE-2022-4942 | MEDIUM | 6.1 | 0.5% | Apr 20, 2023 | A vulnerability was found in mportuga eslint-detailed-reporter up to 0.9.0 and classified as problematic. Affected by th... |
| CVE-2022-2084 | MEDIUM | 5.5 | 0.2% | Apr 19, 2023 | Sensitive data could be exposed in world readable logs of cloud-init before version 22.3 when schema failures are report... |
| CVE-2022-38125 | MEDIUM | 5.5 | 0.2% | Apr 19, 2023 | Improper Restriction of Communication Channel to Intended Endpoints vulnerability in Secomea SiteManager (FTP Agent modu... |
| CVE-2022-2507 | MEDIUM | 5.3 | 0.4% | Apr 19, 2023 | In affected versions of Octopus Deploy it is possible to render user supplied input into the webpage |
| CVE-2022-43378 | MEDIUM | 6.5 | 0.5% | Apr 18, 2023 | A CWE-1021: Improper Restriction of Rendered UI Layers or Frames vulnerability exists that could cause the user t... |
| CVE-2022-43376 | MEDIUM | 6.1 | 0.4% | Apr 18, 2023 | A CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists t... |
| CVE-2022-34755 | MEDIUM | 6.7 | 0.2% | Apr 18, 2023 | A CWE-427 - Uncontrolled Search Path Element vulnerability exists that could allow an attacker with a local privileged ... |
| CVE-2022-45836 | MEDIUM | 6.1 | 0.7% | Apr 18, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in W3 Eden, Inc. Download Manager plugin <= 3.2.59 versions. |
| CVE-2022-44632 | MEDIUM | 4.8 | 0.4% | Apr 18, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Denis Buka Content Repeater – Custom Posts Simplified ... |
| CVE-2022-45839 | MEDIUM | 5.4 | 0.4% | Apr 18, 2023 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in WHA WHA Puzzle plugin <= 1.0.9 versions. |
| CVE-2022-45838 | MEDIUM | 6.1 | 0.4% | Apr 18, 2023 | Unauth. Stored Cross-Site Scripting (XSS) vulnerability in Repute InfoSystems ARForms Form Builder plugin <= 1.5.5 versi... |
| CVE-2022-44735 | MEDIUM | 4.8 | 0.4% | Apr 18, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Gus Sevilla WP Clictracker plugin <= 1.0.5 versions. |
| CVE-2022-46389 | MEDIUM | 6.1 | 0.6% | Apr 17, 2023 | There exists a reflected XSS within the logout functionality of ServiceNow versions lower than Quebec Patch 10 Hotfix 11... |
| CVE-2022-44726 | MEDIUM | 5.4 | 0.4% | Apr 17, 2023 | The TouchDown Timesheet tracking component 4.1.4 for Jira allows XSS in the calendar view. |
| CVE-2022-45849 | MEDIUM | 5.4 | 0.5% | Apr 16, 2023 | Auth. (subscriber+) Reflected Cross-Site Scripting (XSS) vulnerability in Silkalns Activello theme <= 1.4.4 versions. |
| CVE-2022-44734 | MEDIUM | 4.8 | 0.4% | Apr 16, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in BestWebSoft Car Rental by BestWebSoft plugin <= 1.1.2 ... |
| CVE-2022-43480 | MEDIUM | 4.8 | 0.4% | Apr 16, 2023 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Magneticlab Sàrl Homepage Pop-up plugin <= 1.2.5 versi... |
| CVE-2022-43458 | MEDIUM | 5.4 | 0.4% | Apr 16, 2023 | Auth. (contributor+) Cross-Site Scripting (XSS) vulnerability in Code Tides Advanced Floating Content plugin <= 1.2.1 ve... |
| CVE-2022-48314 | MEDIUM | 6.5 | 0.2% | Apr 16, 2023 | The Bluetooth module has a vulnerability of bypassing the user confirmation in the pairing process. Successful exploitat... |
| CVE-2022-48313 | MEDIUM | 6.5 | 0.2% | Apr 16, 2023 | The Bluetooth module has a vulnerability of bypassing the user confirmation in the pairing process. Successful exploitat... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now