2022 CVE Vulnerabilities
27,553 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-29410 | HIGH | 8.8 | 0.9% | Apr 28, 2022 | Authenticated SQL Injection (SQLi) vulnerability in Mufeng's Hermit 音乐播放器 plugin <= 3.1.6 on WordPress allows attackers ... |
| CVE-2022-29585 | HIGH | 7.5 | 1.0% | Apr 28, 2022 | In Mahara before 20.10.5, 21.04.4, 21.10.2, and 22.04.0, a site using Isolated Institutions is vulnerable if more than t... |
| CVE-2022-29584 | MEDIUM | 5.4 | 0.5% | Apr 28, 2022 | Mahara before 20.10.5, 21.04.4, 21.10.2, and 22.04.0 allows stored XSS when a particular Cascading Style Sheets (CSS) cl... |
| CVE-2022-29415 | MEDIUM | 6.1 | 0.7% | Apr 28, 2022 | Unauthenticated Reflected Cross-Site Scripting (XSS) vulnerability in Mati Skiba @ Rav Messer's Ravpage plugin <= 2.16 a... |
| CVE-2022-28892 | HIGH | 8.8 | 0.4% | Apr 28, 2022 | Mahara before 20.10.5, 21.04.4, 21.10.2, and 22.04.0 is vulnerable to Cross Site Request Forgery (CSRF) because randomly... |
| CVE-2022-27860 | MEDIUM | 6.1 | 0.4% | Apr 28, 2022 | Cross-Site Request Forgery (CSRF) leading to Cross-Site Scripting (XSS) in Shea Bunge's Footer Text plugin <= 2.0.3 on W... |
| CVE-2022-22443 | MEDIUM | 5.4 | 0.4% | Apr 28, 2022 | IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed a... |
| CVE-2022-22441 | MEDIUM | 6.5 | 0.8% | Apr 28, 2022 | IBM InfoSphere Information Server 11.7 could allow an authenticated user to view information of higher privileged users ... |
| CVE-2022-22427 | MEDIUM | 6.1 | 0.6% | Apr 28, 2022 | IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed a... |
| CVE-2022-22322 | MEDIUM | 5.4 | 0.4% | Apr 28, 2022 | IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed a... |
| CVE-2022-1514 | MEDIUM | 5.4 | 0.7% | Apr 28, 2022 | Stored XSS via upload plugin functionality in zip format in GitHub repository neorazorx/facturascripts prior to 2022.06.... |
| CVE-2022-28117 | MEDIUM | 4.9 | 21.9% | Apr 28, 2022 | A Server-Side Request Forgery (SSRF) in feed_parser class of Navigate CMS v2.9.4 allows remote attackers to force the ap... |
| CVE-2022-28114 | CRITICAL | 9.1 | 1.0% | Apr 28, 2022 | DSCMS v3.0 was discovered to contain an arbitrary file deletion vulnerability via /controller/Adv.php. |
| CVE-2022-24892 | HIGH | 7.5 | 0.8% | Apr 28, 2022 | Shopware is an open source e-commerce software platform. Starting with version 5.0.4 and before version 5.7.9, multiple ... |
| CVE-2022-24879 | HIGH | 7.5 | 0.6% | Apr 28, 2022 | Shopware is an open source e-commerce software platform. Versions prior to 5.7.9 are vulnerable to malfunction of cross-... |
| CVE-2022-22783 | HIGH | 7.5 | 1.0% | Apr 28, 2022 | A vulnerability in Zoom On-Premise Meeting Connector Controller version 4.8.102.20220310 and On-Premise Meeting Connecto... |
| CVE-2022-22782 | HIGH | 7.1 | 0.4% | Apr 28, 2022 | The Zoom Client for Meetings for Windows prior to version 5.9.7, Zoom Rooms for Conference Room for Windows prior to ver... |
| CVE-2022-22781 | HIGH | 7.5 | 0.4% | Apr 28, 2022 | The Zoom Client for Meetings for MacOS (Standard and for IT Admin) prior to version 5.9.6 failed to properly check the p... |
| CVE-2022-1511 | MEDIUM | 6.5 | 1.0% | Apr 28, 2022 | Missing Authorization in GitHub repository snipe/snipe-it prior to 5.4.4. |
| CVE-2022-28102 | MEDIUM | 5.4 | 0.5% | Apr 28, 2022 | A cross-site scripting (XSS) vulnerability in PHP MySQL Admin Panel Generator v1 allows attackers to execute arbitrary w... |
| CVE-2022-28101 | CRITICAL | 9 | 1.0% | Apr 28, 2022 | Turtlapp Turtle Note v0.7.2.6 does not filter the <meta> tag during markdown parsing, allowing attackers to execute HTML... |
| CVE-2022-24873 | MEDIUM | 6.1 | 0.7% | Apr 28, 2022 | Shopware is an open source e-commerce software platform. Prior to version 5.7.9, Shopware is vulnerable to non-stored cr... |
| CVE-2022-29152 | MEDIUM | 6.1 | 0.5% | Apr 28, 2022 | The Ericom PowerTerm WebConnect 6.0 login portal can unsafely write an XSS payload from the AppPortal cookie into the pa... |
| CVE-2022-24935 | HIGH | 7.5 | 0.7% | Apr 28, 2022 | Lexmark products through 2022-02-10 have Incorrect Access Control. |
| CVE-2022-29821 | HIGH | 7.7 | 0.2% | Apr 28, 2022 | In JetBrains Rider before 2022.1 local code execution via links in ReSharper Quick Documentation was possible |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now