2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-25037MEDIUM5.4An issue in wanEditor v4.7.11 and fixed in v.4.7.12 and v.5 was discovered to contain a cross-site scripting (XSS) vulne...
CVE-2022-43841LOW3.3IBM Aspera Console 3.4.0 through 3.4.2 PL9 allows web pages to be stored locally which can be read by another user on th...
CVE-2022-43575MEDIUM5.4IBM Aspera Console 3.4.0 through 3.4.2 PL5 is vulnerable to cross-site scripting. This vulnerability allows users to emb...
CVE-2022-43384MEDIUM5.4IBM Aspera Console 3.4.0 through 3.4.2 PL5 is vulnerable to cross-site scripting. This vulnerability allows users to emb...
CVE-2022-45171HIGH8.8An issue was discovered in LIVEBOX Collaboration vDesk through v018. An Unrestricted Upload of a File with a Dangerous T...
CVE-2022-48681HIGH8.8Some Huawei smart speakers have a memory overflow vulnerability. Successful exploitation of this vulnerability may cause...
CVE-2022-4969MEDIUM5.3A vulnerability, which was classified as critical, has been found in bwoodsend rockhopper up to 0.1.2. Affected by this ...
CVE-2022-48710MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: drm/radeon: fix a possible null pointer dereference...
CVE-2022-48709MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: ice: switch: fix potential memleak in ice_add_adv_r...
CVE-2022-48708MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: pinctrl: single: fix potential NULL dereference Ad...
CVE-2022-48707MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: cxl/region: Fix null pointer dereference for resett...
CVE-2022-48706MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: vdpa: ifcvf: Do proper cleanup if IFCVF init fails ...
CVE-2022-45374MEDIUM6.5Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in YARPP allows PHP Local F...
CVE-2022-45368HIGH7.7Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Lenderd 1003 Mortgage Ap...
CVE-2022-45070MEDIUM5.3Missing Authorization vulnerability in FmeAddons Conditional Checkout Fields for WooCommerce.This issue affects Conditio...
CVE-2022-44581CRITICAL9.8Insecure Storage of Sensitive Information vulnerability in WPMU DEV Defender Security allows : Screen Temporary Files fo...
CVE-2022-37410HIGH7Improper access control for some Intel(R) Thunderbolt driver software before version 89 may allow an authenticated user ...
CVE-2022-37341HIGH7.8Improper access control in some Intel(R) Ethernet Adapters and Intel(R) Ethernet Controller I225 Manageability firmware ...
CVE-2022-28132HIGH7.2The T-Soft E-Commerce 4 web application is susceptible to SQL injection (SQLi) attacks when authenticated as an admin or...
CVE-2022-4967MEDIUM6.5strongSwan versions 5.9.2 through 5.9.5 are affected by authorization bypass through improper validation of certificate ...
CVE-2022-32510HIGH7.1An issue was discovered on certain Nuki Home Solutions devices. The HTTP API exposed by a Bridge used an unencrypted cha...
CVE-2022-32509HIGH8.8An issue was discovered on certain Nuki Home Solutions devices. Lack of certificate validation on HTTP communications al...
CVE-2022-32508HIGH7.5An issue was discovered on certain Nuki Home Solutions devices. By sending a malformed HTTP verb, it is possible to forc...
CVE-2022-32507HIGH8.8An issue was discovered on certain Nuki Home Solutions devices. Some BLE commands, which should have been designed to be...
CVE-2022-32506MEDIUM6.4An issue was discovered on certain Nuki Home Solutions devices. An attacker with physical access to the circuit board co...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now