2022 CVE Vulnerabilities

27,525 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-43928MEDIUM6.5The IBM Toolbox for Java (Db2 Mirror for i 7.4 and 7.5) could allow a user to obtain sensitive information, caused by ut...
CVE-2022-43914MEDIUM5.4IBM TRIRIGA Application Platform 4.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arb...
CVE-2022-32599MEDIUM6.7In rpmb, there is a possible out of bounds write due to a logic error. This could lead to local escalation of privilege ...
CVE-2022-31889MEDIUM6.1Cross Site Scripting (XSS) vulnerability in audit/templates/auditlogs.tmpl.php in osTicket osTicket-plugins before commi...
CVE-2022-3513MEDIUM6.1An issue has been discovered in GitLab affecting all versions starting from 12.8 before 15.8.5, all versions starting fr...
CVE-2022-4940MEDIUM6.5The WCFM Membership plugin for WordPress is vulnerable to unauthorized modification and access of data in versions up to...
CVE-2022-48223MEDIUM6.7An issue was discovered in Acuant AcuFill SDK before 10.22.02.03. During SDK repair, certutil.exe is called by the Acuan...
CVE-2022-48228MEDIUM5.5An issue was discovered in Acuant AsureID Sentinel before 5.2.149. It uses the root of the C: drive for the i-Dentify an...
CVE-2022-47870MEDIUM6.1A Cross Site Scripting (XSS) vulnerability in the web SQL monitor login page in Redgate SQL Monitor 12.1.31.893 allows r...
CVE-2022-4771MEDIUM6.1 Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.1 and 9.3.0.2, including 8.3.x allow a malici...
CVE-2022-4770MEDIUM4.3 Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.0 and 9.3.0.2, including 8.3.x display the fu...
CVE-2022-4769MEDIUM4.3 Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.0 and 9.3.0.2, including 8.3.x display the ta...
CVE-2022-43941MEDIUM6.5 Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.1 and 9.3.0.2, including 8.3.x do not correctly...
CVE-2022-43772MEDIUM6.5 Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.0 and 9.3.0.1, including 8.3.x with the Big Dat...
CVE-2022-43771MEDIUM6.5 Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.0 and 9.3.0.1, including 8.3.x, using the Penta...
CVE-2022-3960MEDIUM6.3 Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.1 and 9.3.0.2, including 8.3.x cannot allow a...
CVE-2022-27665MEDIUM6.1Reflected XSS (via AngularJS sandbox escape expressions) exists in Progress Ipswitch WS_FTP Server 8.6.0. This can lead ...
CVE-2022-42452MEDIUM5.4HCL Launch is vulnerable to HTML injection.  HTML code is stored and included without being sanitized. This can lead to ...
CVE-2022-3192MEDIUM5.3Improper Input Validation vulnerability in ABB AC500 V2 PM5xx allows Client-Server Protocol Manipulation.This issue affe...
CVE-2022-43473MEDIUM5.4A blind XML External Entity (XXE) vulnerability exists in the Add UCS Device functionality of ManageEngine OpManager 12....
CVE-2022-1274MEDIUM5.4A flaw was found in Keycloak in the execute-actions-email endpoint. This issue allows arbitrary HTML to be injected into...
CVE-2022-47602MEDIUM5.4Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in JoomUnited WP Table Manager plugin <= 3.5.2 vers...
CVE-2022-44369MEDIUM5.5NASM 2.16 (development) is vulnerable to 476: Null Pointer Dereference via output/outaout.c.
CVE-2022-44368MEDIUM5.5NASM v2.16 was discovered to contain a null pointer deference in the NASM component
CVE-2022-47613MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in QuantumCloud AI ChatBot plugin <= 4.3.0 versions.

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now