2022 CVE Vulnerabilities

27,553 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-26197MEDIUM5.4Joget DX 7 was discovered to contain a cross-site scripting (XSS) vulnerability via the Datalist table.
CVE-2022-25523HIGH8.8TypesetterCMS v5.1 was discovered to contain a Cross-Site Request Forgery (CSRF) which is exploited via a crafted POST r...
CVE-2022-24643MEDIUM5.4A stored cross-site scripting (XSS) issue was discovered in the OpenEMR Hospital Information Management System version 6...
CVE-2022-27920MEDIUM6.1libkiwix 10.0.0 and 10.0.1 allows XSS in the built-in webserver functionality via the search suggestions URL parameter. ...
CVE-2022-27919CRITICAL9.8Gradle Enterprise before 2022.1 allows remote code execution if the installation process did not specify an initial conf...
CVE-2022-27906MEDIUM5.9Mendelson OFTP2 before 1.1 b43 is affected by directory traversal. To access the vulnerable code path, the attacker has ...
CVE-2022-27887MEDIUM6.1Maccms v10 was discovered to contain a reflected cross-site scripting (XSS) vulnerability in /admin.php/admin/vod/data.h...
CVE-2022-27886MEDIUM6.1Maccms v10 was discovered to contain a reflected cross-site scripting (XSS) vulnerability in /admin.php/admin/ulog/index...
CVE-2022-27885MEDIUM6.1Maccms v10 was discovered to contain multiple reflected cross-site scripting (XSS) vulnerabilities in /admin.php/admin/w...
CVE-2022-27884MEDIUM6.1Maccms v10 was discovered to contain a reflected cross-site scripting (XSS) vulnerability in /admin.php/admin/plog/index...
CVE-2022-26573MEDIUM6.1Maccms v10 was discovered to contain multiple reflected cross-site scripting (XSS) vulnerabilities in /admin.php/admin/a...
CVE-2022-25612MEDIUM5.4Multiple Authenticated Persistent Cross-Site Scripting (XSS) vulnerabilities in Simple Event Planner WordPress plugin <=...
CVE-2022-25611MEDIUM5.4Authenticated Stored Cross-Site Scripting (XSS) in Simple Event Planner plugin <= 1.5.4 allows attackers with contributo...
CVE-2022-25610MEDIUM6.1Unauthenticated Stored Cross-Site Scripting (XSS) in Simple Ajax Chat <= 20220115 allows an attacker to store the malici...
CVE-2022-25606MEDIUM5.4Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities discovered in WP-DownloadManager WordPress plug...
CVE-2022-25590MEDIUM6.5SurveyKing v0.2.0 was discovered to retain users' session cookies after logout, allowing attackers to login to the syste...
CVE-2022-1049HIGH8.8A flaw was found in the Pacemaker configuration tool (pcs). The pcs daemon was allowing expired accounts, and accounts w...
CVE-2022-0995HIGH7.8An out-of-bounds (OOB) memory write flaw was found in the Linux kernel’s watch_queue event notification subsystem. This ...
CVE-2022-0988HIGH7.5Delta Electronics DIAEnergie (Version 1.7.5 and prior) is vulnerable to cleartext transmission as the web application ru...
CVE-2022-0983HIGH8.8An SQL injection risk was identified in Badges code relating to configuring criteria. Access to the relevant capability ...
CVE-2022-0897MEDIUM4.3A flaw was found in the libvirt nwfilter driver. The virNWFilterObjListNumOfNWFilters method failed to acquire the drive...
CVE-2022-0759HIGH8.1A flaw was found in all versions of kubeclient up to (but not including) v4.9.3, the Ruby client for Kubernetes REST API...
CVE-2022-0500HIGH7.8A flaw was found in unrestricted eBPF usage by the BPF_BTF_LOAD, leading to a possible out-of-bounds memory write in the...
CVE-2022-0494MEDIUM4.4A kernel information leak flaw was identified in the scsi_ioctl function in drivers/scsi/scsi_ioctl.c in the Linux kerne...
CVE-2022-0435HIGH8.8A stack overflow flaw was found in the Linux kernel's TIPC protocol functionality in the way a user sends a packet with ...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now