2022 CVE Vulnerabilities
27,525 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-2837 | MEDIUM | 6.1 | 0.4% | Mar 3, 2023 | A flaw was found in coreDNS. This flaw allows a malicious user to redirect traffic intended for external top-level domai... |
| CVE-2022-2835 | MEDIUM | 4.4 | 0.2% | Mar 3, 2023 | A flaw was found in coreDNS. This flaw allows a malicious user to reroute internal calls to some internal services that ... |
| CVE-2022-40633 | MEDIUM | 4.6 | 0.3% | Mar 2, 2023 | A malicious actor can clone access cards used to open control cabinets secured with Rittal CMC III locks. |
| CVE-2022-35645 | MEDIUM | 5.4 | 0.5% | Mar 2, 2023 | IBM Maximo Asset Management 7.6.1.1, 7.6.1.2, 7.6.1.3 and IBM Maximo Application Suite 8.8 and 8.9 is vulnerable to stor... |
| CVE-2022-4901 | MEDIUM | 6.1 | 0.3% | Mar 1, 2023 | Multiple stored XSS vulnerabilities in Sophos Connect versions older than 2.2.90 allow Javascript code to run in the loc... |
| CVE-2022-48310 | MEDIUM | 5.5 | 0.1% | Mar 1, 2023 | An information disclosure vulnerability allows sensitive key material to be included in technical support archives in So... |
| CVE-2022-48309 | MEDIUM | 4.3 | 0.3% | Mar 1, 2023 | A CSRF vulnerability allows malicious websites to retrieve logs and technical support archives in Sophos Connect version... |
| CVE-2022-3162 | MEDIUM | 6.5 | 1.2% | Mar 1, 2023 | Users authorized to list or watch one type of namespaced custom resource cluster-wide can read custom resources of a dif... |
| CVE-2022-39228 | MEDIUM | 6.5 | 0.6% | Mar 1, 2023 | vantage6 is a privacy preserving federated learning infrastructure for secure insight exchange. vantage6 does not inform... |
| CVE-2022-36021 | MEDIUM | 5.5 | 59.7% | Mar 1, 2023 | Redis is an in-memory database that persists on disk. Authenticated users can use string matching commands (like `SCAN` ... |
| CVE-2022-47148 | MEDIUM | 4.3 | 0.2% | Mar 1, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in WP Overnight PDF Invoices & Packing Slips for WooCommerce plugin <= 3... |
| CVE-2022-46806 | MEDIUM | 4.3 | 0.2% | Mar 1, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in VillaTheme Cart All In One For WooCommerce plugin <= 1.1.10 leading t... |
| CVE-2022-46805 | MEDIUM | 5.4 | 0.2% | Mar 1, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in Lauri Karisola / WP Trio Conditional Shipping for WooCommerce plugin ... |
| CVE-2022-46798 | MEDIUM | 5.4 | 0.2% | Mar 1, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in HasThemes ShopLentor plugin <= 2.5.1 leading to plugin settings chang... |
| CVE-2022-46797 | MEDIUM | 4.3 | 0.2% | Mar 1, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in Conversios All-in-one Google Analytics, Pixels and Product Feed Manag... |
| CVE-2022-45804 | MEDIUM | 5.4 | 0.2% | Mar 1, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in RoboSoft Photo Gallery, Images, Slider in Rbs Image Gallery plugin <=... |
| CVE-2022-40198 | MEDIUM | 4.3 | 0.2% | Mar 1, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in StandaloneTech TeraWallet – For WooCommerce plugin <= 1.3.24 leading ... |
| CVE-2022-38468 | MEDIUM | 4.3 | 0.2% | Mar 1, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in Imagely WordPress Gallery Plugin – NextGEN Gallery plugin <= 3.28 lea... |
| CVE-2022-37935 | MEDIUM | 5.5 | 0.2% | Mar 1, 2023 | HPE OneView for VMware vCenter, in certain circumstances, may disclose the “HPE OneView” Username and Password. |
| CVE-2022-27672 | MEDIUM | 4.7 | 0.3% | Mar 1, 2023 | When SMT is enabled, certain AMD processors may speculatively execute instructions using a target from the sibling threa... |
| CVE-2022-20952 | MEDIUM | 5.3 | 0.7% | Mar 1, 2023 | A vulnerability in the scanning engines of Cisco AsyncOS Software for Cisco Secure Web Appliance, formerly known as Cisc... |
| CVE-2022-38220 | MEDIUM | 6.1 | 0.7% | Mar 1, 2023 | An XSS vulnerability exists within Quest KACE Systems Management Appliance (SMA) through 12.1 that may allow remote inje... |
| CVE-2022-23240 | MEDIUM | 6.5 | 0.4% | Feb 28, 2023 | Active IQ Unified Manager for VMware vSphere, Linux, and Microsoft Windows versions prior to 9.11P1 are susceptible to a... |
| CVE-2022-23239 | MEDIUM | 4.8 | 0.3% | Feb 28, 2023 | Active IQ Unified Manager for VMware vSphere, Linux, and Microsoft Windows versions prior to 9.11P1 are susceptible to a... |
| CVE-2022-41727 | MEDIUM | 5.5 | 0.3% | Feb 28, 2023 | An attacker can craft a malformed TIFF image which will consume a significant amount of memory when passed to DecodeConf... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now