2022 CVE Vulnerabilities
27,525 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-32595 | MEDIUM | 4.4 | 0.1% | Feb 6, 2023 | In widevine, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local informati... |
| CVE-2022-4902 | MEDIUM | 6.1 | 0.6% | Feb 6, 2023 | A vulnerability classified as problematic has been found in eXo Chat Application. Affected is an unknown function of the... |
| CVE-2022-2933 | MEDIUM | 5.4 | 0.5% | Feb 6, 2023 | The 0mk Shortener plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 0.2... |
| CVE-2022-48085 | MEDIUM | 5.4 | 0.6% | Feb 6, 2023 | Softr v2.0 was discovered to contain a HTML injection vulnerability via the Work Space Name parameter. |
| CVE-2022-45722 | MEDIUM | 6.1 | 0.4% | Feb 6, 2023 | ezEIP v5.3.0(0649) was discovered to contain a cross-site scripting (XSS) vulnerability. |
| CVE-2022-29416 | MEDIUM | 6.1 | 0.4% | Feb 6, 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Afterpay Gateway for WooCommerce <= 3.5.0 versions. |
| CVE-2022-27628 | MEDIUM | 6.5 | 0.2% | Feb 6, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in AA-Team WZone – Lite Version plugin 3.1 Lite versions. |
| CVE-2022-42909 | MEDIUM | 5.4 | 0.4% | Feb 3, 2023 | WEPA Print Away does not verify that a user has authorization to access documents before generating print orders and ass... |
| CVE-2022-42908 | MEDIUM | 5.4 | 0.4% | Feb 3, 2023 | WEPA Print Away is vulnerable to a stored XSS. It does not properly sanitize uploaded filenames, allowing an attacker to... |
| CVE-2022-48074 | MEDIUM | 5.3 | 0.2% | Feb 3, 2023 | An issue in NoMachine before v8.2.3 allows attackers to execute arbitrary commands via a crafted .nxs file. |
| CVE-2022-48023 | MEDIUM | 4.3 | 0.4% | Feb 3, 2023 | Insufficient privilege verification in Zammad v5.3.0 allows an authenticated attacker to perform changes on the tags of ... |
| CVE-2022-48022 | MEDIUM | 4.3 | 0.5% | Feb 3, 2023 | An issue in the component /api/v1/mentions of Zammad v5.3.0 allows authenticated attackers with agent permissions to vie... |
| CVE-2022-47131 | MEDIUM | 4.8 | 0.4% | Feb 3, 2023 | A Cross-Site Request Forgery (CSRF) in Academy LMS before v5.10 allows an attacker to arbitrarily create a page. |
| CVE-2022-47130 | MEDIUM | 4.3 | 0.6% | Feb 3, 2023 | A Cross-Site Request Forgery (CSRF) in Academy LMS before v5.10 allows a discount coupon to be arbitrarily created if an... |
| CVE-2022-48140 | MEDIUM | 5.4 | 0.4% | Feb 2, 2023 | DedeCMS v5.7.97 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /file_manage_view.... |
| CVE-2022-3560 | MEDIUM | 5.5 | 0.2% | Feb 2, 2023 | A flaw was found in pesign. The pesign package provides a systemd service used to start the pesign daemon. This service ... |
| CVE-2022-43665 | MEDIUM | 5.5 | 0.3% | Feb 2, 2023 | A denial of service vulnerability exists in the malware scan functionality of ESTsoft Alyac 2.5.8.645. A specially-craft... |
| CVE-2022-2546 | MEDIUM | 4.7 | 1.2% | Feb 2, 2023 | The All-in-One WP Migration WordPress plugin before 7.63 uses the wrong content type, and does not properly escape the r... |
| CVE-2022-40268 | MEDIUM | 4.7 | 0.5% | Feb 2, 2023 | Improper Restriction of Rendered UI Layers or Frames vulnerability in Mitsubishi Electric Corporation GOT2000 Series GT2... |
| CVE-2022-37034 | MEDIUM | 5.3 | 0.9% | Feb 1, 2023 | In dotCMS 5.x-22.06, it is possible to call the TempResource multiple times, each time requesting the dotCMS server to d... |
| CVE-2022-45783 | MEDIUM | 6.5 | 8.5% | Feb 1, 2023 | An issue was discovered in dotCMS core 4.x through 22.10.2. An authenticated directory traversal vulnerability in the do... |
| CVE-2022-3913 | MEDIUM | 5.3 | 0.3% | Feb 1, 2023 | Rapid7 Nexpose and InsightVM versions 6.6.82 through 6.6.177 fail to validate the certificate of the update server when ... |
| CVE-2022-37033 | MEDIUM | 6.5 | 0.8% | Feb 1, 2023 | In dotCMS 5.x-22.06, TempFileAPI allows a user to create a temporary file based on a passed in URL, while attempting to ... |
| CVE-2022-3083 | MEDIUM | 5.4 | 0.4% | Feb 1, 2023 | All versions of Landis+Gyr E850 (ZMQ200) are vulnerable to CWE-784: Reliance on Cookies Without Validation and Integrity... |
| CVE-2022-46934 | MEDIUM | 6.1 | 1.1% | Feb 1, 2023 | kkFileView v4.1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the url parameter at /control... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now