2022 CVE Vulnerabilities

27,525 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-2837MEDIUM6.1A flaw was found in coreDNS. This flaw allows a malicious user to redirect traffic intended for external top-level domai...
CVE-2022-2835MEDIUM4.4A flaw was found in coreDNS. This flaw allows a malicious user to reroute internal calls to some internal services that ...
CVE-2022-40633MEDIUM4.6A malicious actor can clone access cards used to open control cabinets secured with Rittal CMC III locks.
CVE-2022-35645MEDIUM5.4IBM Maximo Asset Management 7.6.1.1, 7.6.1.2, 7.6.1.3 and IBM Maximo Application Suite 8.8 and 8.9 is vulnerable to stor...
CVE-2022-4901MEDIUM6.1Multiple stored XSS vulnerabilities in Sophos Connect versions older than 2.2.90 allow Javascript code to run in the loc...
CVE-2022-48310MEDIUM5.5An information disclosure vulnerability allows sensitive key material to be included in technical support archives in So...
CVE-2022-48309MEDIUM4.3A CSRF vulnerability allows malicious websites to retrieve logs and technical support archives in Sophos Connect version...
CVE-2022-3162MEDIUM6.5Users authorized to list or watch one type of namespaced custom resource cluster-wide can read custom resources of a dif...
CVE-2022-39228MEDIUM6.5vantage6 is a privacy preserving federated learning infrastructure for secure insight exchange. vantage6 does not inform...
CVE-2022-36021MEDIUM5.5Redis is an in-memory database that persists on disk. Authenticated users can use string matching commands (like `SCAN` ...
CVE-2022-47148MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in WP Overnight PDF Invoices & Packing Slips for WooCommerce plugin <= 3...
CVE-2022-46806MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in VillaTheme Cart All In One For WooCommerce plugin <= 1.1.10 leading t...
CVE-2022-46805MEDIUM5.4Cross-Site Request Forgery (CSRF) vulnerability in Lauri Karisola / WP Trio Conditional Shipping for WooCommerce plugin ...
CVE-2022-46798MEDIUM5.4Cross-Site Request Forgery (CSRF) vulnerability in HasThemes ShopLentor plugin <= 2.5.1 leading to plugin settings chang...
CVE-2022-46797MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in Conversios All-in-one Google Analytics, Pixels and Product Feed Manag...
CVE-2022-45804MEDIUM5.4Cross-Site Request Forgery (CSRF) vulnerability in RoboSoft Photo Gallery, Images, Slider in Rbs Image Gallery plugin <=...
CVE-2022-40198MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in StandaloneTech TeraWallet – For WooCommerce plugin <= 1.3.24 leading ...
CVE-2022-38468MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in Imagely WordPress Gallery Plugin – NextGEN Gallery plugin <= 3.28 lea...
CVE-2022-37935MEDIUM5.5HPE OneView for VMware vCenter, in certain circumstances, may disclose the “HPE OneView” Username and Password.
CVE-2022-27672MEDIUM4.7When SMT is enabled, certain AMD processors may speculatively execute instructions using a target from the sibling threa...
CVE-2022-20952MEDIUM5.3A vulnerability in the scanning engines of Cisco AsyncOS Software for Cisco Secure Web Appliance, formerly known as Cisc...
CVE-2022-38220MEDIUM6.1An XSS vulnerability exists within Quest KACE Systems Management Appliance (SMA) through 12.1 that may allow remote inje...
CVE-2022-23240MEDIUM6.5Active IQ Unified Manager for VMware vSphere, Linux, and Microsoft Windows versions prior to 9.11P1 are susceptible to a...
CVE-2022-23239MEDIUM4.8Active IQ Unified Manager for VMware vSphere, Linux, and Microsoft Windows versions prior to 9.11P1 are susceptible to a...
CVE-2022-41727MEDIUM5.5An attacker can craft a malformed TIFF image which will consume a significant amount of memory when passed to DecodeConf...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now