2022 CVE Vulnerabilities

27,525 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-34125MEDIUM6.5front/icon.send.php in the CMDB plugin before 3.0.3 for GLPI allows attackers to gain read access to sensitive informati...
CVE-2022-30076MEDIUM5.3ENTAB ERP 1.0 allows attackers to discover users' full names via a brute force attack with a series of student usernames...
CVE-2022-28353MEDIUM6.1In the External Redirect Warning Plugin 1.3 for MyBB, the redirect URL (aka external.php?url=) is vulnerable to XSS.
CVE-2022-37306MEDIUM6.1OX App Suite before 7.10.6-rev30 allows XSS via an upsell trigger.
CVE-2022-37186MEDIUM5.9In LemonLDAP::NG before 2.0.15. some sessions are not deleted when they are supposed to be deleted according to the time...
CVE-2022-37705MEDIUM6.7A privilege escalation flaw was found in Amanda 3.5.1 in which the backup user can acquire root privileges. The vulnerab...
CVE-2022-37704MEDIUM6.7Amanda 3.5.1 allows privilege escalation from the regular user backup to root. The SUID binary located at /lib/amanda/ru...
CVE-2022-43699MEDIUM4.3OX App Suite before 7.10.6-rev30 allows SSRF because e-mail account discovery disregards the deny-list and thus can be a...
CVE-2022-43698MEDIUM4.3OX App Suite before 7.10.6-rev30 allows SSRF because changing a POP3 account disregards the deny-list.
CVE-2022-43697MEDIUM6.1OX App Suite before 7.10.6-rev30 allows XSS via an activity tracking adapter defined by jslob.
CVE-2022-43696MEDIUM6.1OX App Suite before 7.10.6-rev20 allows XSS via upsell ads.
CVE-2022-48178MEDIUM5.4X2CRM Open Source Sales CRM 6.6 and 6.9 was discovered to contain a stored cross-site scripting (XSS) vulnerability via ...
CVE-2022-48177MEDIUM5.4X2CRM Open Source Sales CRM 6.6 and 6.9 was discovered to contain a reflected cross-site scripting (XSS) vulnerability v...
CVE-2022-46886MEDIUM6.1There exists an open redirect within the response list update functionality of ServiceNow. This allows attackers to redi...
CVE-2022-45180MEDIUM6.5An issue was discovered in LIVEBOX Collaboration vDesk through v018. Broken Access Control exists under the /api/v1/vdes...
CVE-2022-45175MEDIUM6.5An issue was discovered in LIVEBOX Collaboration vDesk through v018. An Insecure Direct Object Reference can occur under...
CVE-2022-45170MEDIUM6.5An issue was discovered in LIVEBOX Collaboration vDesk through v018. A Cryptographic Issue can occur under the /api/v1/v...
CVE-2022-48468MEDIUM5.5protobuf-c before 1.4.1 has an unsigned integer overflow in parse_required_member.
CVE-2022-45358MEDIUM5.4Auth. (subscriber+) Reflected Cross-Site Scripting (XSS) vulnerability in Silkalns Activello theme <= 1.4.4 versions.
CVE-2022-44625MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting') vulnerability in Zephilou Cyklodev WP Notify plugin <= 1.2.1 versions.
CVE-2022-33297MEDIUM5.5Information disclosure due to buffer overread in Linux sensors
CVE-2022-33289MEDIUM6.8Memory corruption occurs in Modem due to improper validation of array index when malformed APDU is sent from card.
CVE-2022-33270MEDIUM5.9Transient DOS due to time-of-check time-of-use race condition in Modem while processing RRC Reconfiguration message.
CVE-2022-47053MEDIUM5.4An arbitrary file upload vulnerability in the Digital Assets Manager module of DNN Corp DotNetNuke v7.0.0 to v9.10.2 all...
CVE-2022-24350MEDIUM5.5An issue was discovered in IhisiSmm in Insyde InsydeH2O with kernel 5.0 through 5.5. IHISI function 0x17 verifies that t...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now