2022 CVE Vulnerabilities

27,525 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-46863MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Fullworks Quick Event Manager plugin <= 9.6.4 versions...
CVE-2022-46855MEDIUM5.4Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in WP Darko Responsive Pricing Table plugin <= 5.1....
CVE-2022-46848MEDIUM5.4Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Themeisle Visualizer: Tables and Charts Manager ...
CVE-2022-45831MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in biplob018 Image Hover Effects for Elementor with Lightbox ...
CVE-2022-45825MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in iThemes WPComplete plugin <= 2.9.2 versions.
CVE-2022-48361MEDIUM5.3The Always On Display (AOD) has a path traversal vulnerability in theme files. Successful exploitation of this vulnerabi...
CVE-2022-48355MEDIUM6.5The Bluetooth module has a heap out-of-bounds read vulnerability. Successful exploitation of this vulnerability can caus...
CVE-2022-48354MEDIUM6.5The Bluetooth module has a heap out-of-bounds write vulnerability. Successful exploitation of this vulnerability can cau...
CVE-2022-48291MEDIUM6.5The Bluetooth module has an authentication bypass vulnerability in the pairing process. Successful exploitation of this ...
CVE-2022-2237MEDIUM6.1A flaw was found in the Keycloak Node.js Adapter. This flaw allows an attacker to benefit from an Open Redirect vulnerab...
CVE-2022-46416MEDIUM5.9Parrot Bebop 4.7.1. allows remote attackers to prevent legitimate terminal connections by exhausting the DHCP IP address...
CVE-2022-46415MEDIUM5.9DJI Spark 01.00.0900 allows remote attackers to prevent legitimate terminal connections by exhausting the DHCP IP addres...
CVE-2022-48428MEDIUM5.4In JetBrains TeamCity before 2022.10.3 stored XSS on the SSH keys page was possible
CVE-2022-48427MEDIUM5.4In JetBrains TeamCity before 2022.10.3 stored XSS on “Pending changes” and “Changes” tabs was possible
CVE-2022-48429MEDIUM5.4In JetBrains Hub before 2022.3.15573, 2022.2.15572, 2022.1.15583 reflected XSS in dashboards was possible
CVE-2022-48426MEDIUM5.4In JetBrains TeamCity before 2022.10.3 stored XSS in Perforce connection settings was possible
CVE-2022-47146MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Contempoinc Real Estate 7 WordPress theme <= 3.3.1 version...
CVE-2022-47924MEDIUM6.5An high privileged attacker may pass crafted arguments to the validate function of csaf-validator-lib of a locally insta...
CVE-2022-46843MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Le Van Toan Woocommerce Vietnam Checkout plugin <= 2.0.4 v...
CVE-2022-41354MEDIUM4.3An access control issue in Argo CD v2.4.12 and below allows unauthenticated attackers to enumerate existing applications...
CVE-2022-32199MEDIUM6.5db_convert.php in ScriptCase through 9.9.008 is vulnerable to Arbitrary File Deletion by an admin via a directory traver...
CVE-2022-42528MEDIUM5.5In ffa_mrd_prot of shared_mem.c, there is a possible ID due to a logic error in the code. This could lead to local infor...
CVE-2022-42500MEDIUM6.7In OEM_OnRequest of sced.cpp, there is a possible shell command execution due to improper input validation. This could l...
CVE-2022-40208MEDIUM4.3In Moodle, insufficient limitations in some quiz web services made it possible for students to bypass sequential navigat...
CVE-2022-20499MEDIUM5.5In validateForCommonR1andR2 of PasspointConfiguration.java, uncaught errors in parsing stored configs could lead to loca...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now