2022 CVE Vulnerabilities

27,553 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-29410HIGH8.8Authenticated SQL Injection (SQLi) vulnerability in Mufeng's Hermit 音乐播放器 plugin <= 3.1.6 on WordPress allows attackers ...
CVE-2022-29585HIGH7.5In Mahara before 20.10.5, 21.04.4, 21.10.2, and 22.04.0, a site using Isolated Institutions is vulnerable if more than t...
CVE-2022-29584MEDIUM5.4Mahara before 20.10.5, 21.04.4, 21.10.2, and 22.04.0 allows stored XSS when a particular Cascading Style Sheets (CSS) cl...
CVE-2022-29415MEDIUM6.1Unauthenticated Reflected Cross-Site Scripting (XSS) vulnerability in Mati Skiba @ Rav Messer's Ravpage plugin <= 2.16 a...
CVE-2022-28892HIGH8.8Mahara before 20.10.5, 21.04.4, 21.10.2, and 22.04.0 is vulnerable to Cross Site Request Forgery (CSRF) because randomly...
CVE-2022-27860MEDIUM6.1Cross-Site Request Forgery (CSRF) leading to Cross-Site Scripting (XSS) in Shea Bunge's Footer Text plugin <= 2.0.3 on W...
CVE-2022-22443MEDIUM5.4IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed a...
CVE-2022-22441MEDIUM6.5IBM InfoSphere Information Server 11.7 could allow an authenticated user to view information of higher privileged users ...
CVE-2022-22427MEDIUM6.1IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed a...
CVE-2022-22322MEDIUM5.4IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed a...
CVE-2022-1514MEDIUM5.4Stored XSS via upload plugin functionality in zip format in GitHub repository neorazorx/facturascripts prior to 2022.06....
CVE-2022-28117MEDIUM4.9A Server-Side Request Forgery (SSRF) in feed_parser class of Navigate CMS v2.9.4 allows remote attackers to force the ap...
CVE-2022-28114CRITICAL9.1DSCMS v3.0 was discovered to contain an arbitrary file deletion vulnerability via /controller/Adv.php.
CVE-2022-24892HIGH7.5Shopware is an open source e-commerce software platform. Starting with version 5.0.4 and before version 5.7.9, multiple ...
CVE-2022-24879HIGH7.5Shopware is an open source e-commerce software platform. Versions prior to 5.7.9 are vulnerable to malfunction of cross-...
CVE-2022-22783HIGH7.5A vulnerability in Zoom On-Premise Meeting Connector Controller version 4.8.102.20220310 and On-Premise Meeting Connecto...
CVE-2022-22782HIGH7.1The Zoom Client for Meetings for Windows prior to version 5.9.7, Zoom Rooms for Conference Room for Windows prior to ver...
CVE-2022-22781HIGH7.5The Zoom Client for Meetings for MacOS (Standard and for IT Admin) prior to version 5.9.6 failed to properly check the p...
CVE-2022-1511MEDIUM6.5Missing Authorization in GitHub repository snipe/snipe-it prior to 5.4.4.
CVE-2022-28102MEDIUM5.4A cross-site scripting (XSS) vulnerability in PHP MySQL Admin Panel Generator v1 allows attackers to execute arbitrary w...
CVE-2022-28101CRITICAL9Turtlapp Turtle Note v0.7.2.6 does not filter the <meta> tag during markdown parsing, allowing attackers to execute HTML...
CVE-2022-24873MEDIUM6.1Shopware is an open source e-commerce software platform. Prior to version 5.7.9, Shopware is vulnerable to non-stored cr...
CVE-2022-29152MEDIUM6.1The Ericom PowerTerm WebConnect 6.0 login portal can unsafely write an XSS payload from the AppPortal cookie into the pa...
CVE-2022-24935HIGH7.5Lexmark products through 2022-02-10 have Incorrect Access Control.
CVE-2022-29821HIGH7.7In JetBrains Rider before 2022.1 local code execution via links in ReSharper Quick Documentation was possible

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now