2022 CVE Vulnerabilities

27,525 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-20467MEDIUM5.5In isBluetoothShareUri of BluetoothOppUtility.java, there is a possible incorrect file read due to a confused deputy. Th...
CVE-2022-3146MEDIUM5.5A flaw was found in tripleo-ansible. Due to an insecure default configuration, the permissions of a sensitive file are n...
CVE-2022-3101MEDIUM5.5A flaw was found in tripleo-ansible. Due to an insecure default configuration, the permissions of a sensitive file are n...
CVE-2022-47145MEDIUM6.1Reflected Cross-Site Scripting (XSS) vulnerability in Blockonomics WordPress Bitcoin Payments – Blockonomics plugin <= 3...
CVE-2022-47173MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in nasirahmed Connect Contact Form 7, WooCommerce To Goog...
CVE-2022-47589MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in this.Functional CTT Expresso para WooCommerce plugin <...
CVE-2022-47431MEDIUM6.1Reflected Cross-Site Scripting (XSS) vulnerability in Tussendoor internet & marketing Open RDW kenteken voertuiginformat...
CVE-2022-45843MEDIUM5.4Auth. (contributor+) Stored Cross-Site Scripting vulnerability in Nextend Smart Slider 3 plugin <= 3.5.1.9 versions.
CVE-2022-44742MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting vulnerability in Yannick Lefebvre Community Events plugin <= 1.4.8 versions.
CVE-2022-45004MEDIUM6.1Gophish through 0.12.1 was discovered to contain a cross-site scripting (XSS) vulnerability via a crafted landing page.
CVE-2022-37940MEDIUM6.1Potential security vulnerabilities have been identified in the HPE FlexFabric 5700 Switch Series. These vulnerabilities ...
CVE-2022-45634MEDIUM4.3An issue discovered in MEGAFEIS, BOFEI DBD+ Application for IOS & Android v1.4.4 allows authenticated attacker to gain a...
CVE-2022-46300MEDIUM5.5Versions of VISAM VBASE Automation Base prior to 11.7.5 may disclose information if a valid user opens a specially craft...
CVE-2022-46286MEDIUM5.5Versions of VISAM VBASE Automation Base prior to 11.7.5 may disclose information if a valid user opens a specially craft...
CVE-2022-45468MEDIUM5.5Versions of VISAM VBASE Automation Base prior to 11.7.5 may disclose information if a valid user opens a specially craft...
CVE-2022-45121MEDIUM5.5Versions of VISAM VBASE Automation Base prior to 11.7.5 may disclose information if a valid user opens a specially craft...
CVE-2022-43512MEDIUM5.5Versions of VISAM VBASE Automation Base prior to 11.7.5 may disclose information if a valid user opens a specially craft...
CVE-2022-41696MEDIUM5.5Versions of VISAM VBASE Automation Base prior to 11.7.5 may disclose information if a valid user opens a specially craft...
CVE-2022-38458MEDIUM5.9A cleartext transmission vulnerability exists in the Remote Management functionality of Netgear Orbi Router RBR750 4.6.8...
CVE-2022-42334MEDIUM6.5x86/HVM pinned cache attributes mis-handling T[his CNA information record relates to multiple CVEs; the text explains wh...
CVE-2022-42331MEDIUM5.5x86: speculative vulnerability in 32bit SYSCALL path Due to an oversight in the very original Spectre/Meltdown security ...
CVE-2022-42485MEDIUM5.4Auth. (contributor+) Cross-Site Scripting (XSS) vulnerability in Galaxy Weblinks Gallery with thumbnail slider plugin <=...
CVE-2022-41831MEDIUM5.4Auth. (contributor+) Cross-Site Scripting vulnerability in TCBarrett WP Glossary plugin <= 3.1.2 versions.
CVE-2022-41785MEDIUM5.4Auth. (contributor+) Stored Cross-Site Scripting vulnerability in Galleryape Gallery Images Ape plugin <= 2.2.8 versions...
CVE-2022-4148MEDIUM4.3The WP OAuth Server (OAuth Authentication) WordPress plugin before 4.3.0 has a flawed CSRF and authorisation check when ...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now