LiveActive security incident?Get immediate response
CVE archive

2022 CVE Archive

Browse CVE records published in 2022 CVE Archive, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 26421 matching CVEs · Page 4 of 529.

Medium · CVSS 5.3

CVE-2022-37774: There is a broken access control vulnerability in the Maarch RM 2.8.3 solution.

There is a broken access control vulnerability in the Maarch RM 2.8.3 solution. When accessing some specific document (pdf, email) from an archive, a preview is proposed by the application. This preview generates a URL including an md5 hash of the file accessed. The document's URL (https://{url}/tmp/{MD5 hash of the document}) is then accessible without authentication.

Published Nov 22, 2022 · Updated Jul 9, 2026

Critical · CVSS 9

CVE-2022-37720: Orchardproject Orchard CMS 1.10.3 is vulnerable to Cross Site Scripting (XSS).

Orchardproject Orchard CMS 1.10.3 is vulnerable to Cross Site Scripting (XSS). When a low privileged user such as an author or publisher, injects a crafted html and javascript payload in a blog post, leading to full admin account takeover or privilege escalation when the malicious blog post is loaded in the victim's browser.

Published Nov 25, 2022 · Updated Jul 9, 2026

Unknown · CVSS Not scored

CVE-2022-37700: Zentao Demo15 is vulnerable to Directory Traversal.

Zentao Demo15 is vulnerable to Directory Traversal. The impact is: obtain sensitive information (remote). The component is: URL : view-source:https://demo15.zentao.pm/user-login.html/zentao/index.php?mode=getconfig.

Published Sep 19, 2022 · Updated Jul 9, 2026

Unknown · CVSS Not scored

CVE-2022-37146: The PlexTrac platform prior to version 1.28.0 allows for username enumeration via HTTP response times on in...

The PlexTrac platform prior to version 1.28.0 allows for username enumeration via HTTP response times on invalid login attempts for users configured to use the PlexTrac authentication provider. Login attempts for valid, unlocked users configured to use PlexTrac as their authentication provider take significantly longer than those for invalid users, allowing for valid users to be enumerated by an unauthenticated remote attacker. Note that the lockout policy implemented in Plextrac version 1.17.0 makes it impossible to distinguish between valid, locked user accounts and user accounts that do not exist, but does not prevent valid, unlocked users from being enumerated.

Published Sep 8, 2022 · Updated Jul 9, 2026

Unknown · CVSS Not scored

CVE-2022-37145: The PlexTrac platform prior to version 1.17.0 does not restrict excessive authentication attempts for accou...

The PlexTrac platform prior to version 1.17.0 does not restrict excessive authentication attempts for accounts configured to use the PlexTrac authentication provider. An unauthenticated remote attacker could perform a bruteforce attack on the login page with no time or attempt limitation in an attempt to obtain valid credentials for the platform users configured to use the PlexTrac authentication provider.

Published Sep 8, 2022 · Updated Jul 9, 2026

Unknown · CVSS Not scored

CVE-2022-36640: influxData influxDB before v1.8.10 contains no authentication mechanism or controls, allowing unauthenticat...

influxData influxDB before v1.8.10 contains no authentication mechanism or controls, allowing unauthenticated attackers to execute arbitrary commands. NOTE: the CVE ID assignment is disputed because the vendor's documentation states "If InfluxDB is being deployed on a publicly accessible endpoint, we strongly recommend authentication be enabled. Otherwise the data will be publicly available to any unauthenticated user. The default settings do NOT enable authentication and authorization."

Published Sep 2, 2022 · Updated Jul 9, 2026

Unknown · CVSS Not scored

CVE-2022-36551: A Server Side Request Forgery (SSRF) in the Data Import module in Heartex - Label Studio Community Edition...

A Server Side Request Forgery (SSRF) in the Data Import module in Heartex - Label Studio Community Edition versions 1.5.0 and earlier allows an authenticated user to access arbitrary files on the system. Furthermore, self-registration is enabled by default in these versions of Label Studio enabling a remote attacker to create a new account and then exploit the SSRF.

Published Oct 3, 2022 · Updated Jul 9, 2026

Unknown · CVSS Not scored

CVE-2022-36534: Super Flexible Software GmbH & Co.

Super Flexible Software GmbH & Co. KG Syncovery 9 for Linux v9.47x and below was discovered to contain multiple remote code execution (RCE) vulnerabilities via the Job_ExecuteBefore and Job_ExecuteAfter parameters at post_profilesettings.php.

Published Sep 16, 2022 · Updated Jul 9, 2026

Unknown · CVSS Not scored

CVE-2022-36533: Super Flexible Software GmbH & Co.

Super Flexible Software GmbH & Co. KG Syncovery 9 for Linux v9.47x and below was discovered to contain a cross-site scripting (XSS) vulnerability.

Published Sep 16, 2022 · Updated Jul 9, 2026