2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-48219MEDIUM6.4Potential vulnerabilities have been identified in certain HP Desktop PC products using the HP TamperLock feature, which ...
CVE-2022-48623CRITICAL9.1The Cpanel::JSON::XS package before 4.33 for Perl performs out-of-bounds accesses in a way that allows attackers to obta...
CVE-2022-22506MEDIUM4.6IBM Robotic Process Automation 21.0.2 contains a vulnerability that could allow user ids may be exposed across tenants. ...
CVE-2022-34311MEDIUM4.3IBM CICS TX Standard and Advanced 11.1 could allow a user with physical access to the web browser to gain access to the ...
CVE-2022-34309HIGH7.5IBM CICS TX Standard and Advanced 11.1 uses weaker than expected cryptographic algorithms that could allow an attacker t...
CVE-2022-38714MEDIUM4.9IBM DataStage on Cloud Pak for Data 4.0.6 to 4.5.2 stores sensitive credential information that can be read by a privile...
CVE-2022-34310HIGH7.5IBM CICS TX Standard and Advanced 11.1 uses weaker than expected cryptographic algorithms that could allow an attacker t...
CVE-2022-0931Rejected reason: Red Hat Product Security does not consider this to be a vulnerability. Upstream has not acknowledged th...
CVE-2022-34381CRITICAL9.8 Dell BSAFE SSL-J version 7.0 and all versions prior to 6.5, and Dell BSAFE Crypto-J versions prior to 6.2.6.1 contain a...
CVE-2022-40744MEDIUM5.4IBM Aspera Faspex 5.0.6 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary...
CVE-2022-47072CRITICAL9.8SQL injection vulnerability in Enterprise Architect 16.0.1605 32-bit allows attackers to run arbitrary SQL commands via ...
CVE-2022-48622HIGH7.8In GNOME GdkPixbuf (aka gdk-pixbuf) through 2.42.10, the ANI (Windows animated cursor) decoder encounters heap memory co...
CVE-2022-4964MEDIUM5.5Ubuntu's pipewire-pulse in snap grants microphone access even when the snap interface for audio-record is not set.
CVE-2022-45795Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2022-45792HIGH7.8Project files may contain malicious contents which the software will use to create files on the filesystem. This allows ...
CVE-2022-45791Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2022-45790CRITICAL9.1The Omron FINS protocol has an authenticated feature to prevent access to memory regions. Authentication is susceptible ...
CVE-2022-47160MEDIUM6.5Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wpmet Wp Social Login and Register Social Co...
CVE-2022-45845HIGH8.8Deserialization of Untrusted Data vulnerability in Nextend Smart Slider 3.This issue affects Smart Slider 3: from n/a th...
CVE-2022-45083HIGH7.2Deserialization of Untrusted Data vulnerability in ProfilePress Membership Team Paid Membership Plugin, Ecommerce, User ...
CVE-2022-40700CRITICAL9.8Server-Side Request Forgery (SSRF) vulnerability in Montonio Montonio for WooCommerce, Wpopal Wpopal Core Features, AMO ...
CVE-2022-42884HIGH8.8Missing Authorization vulnerability in ThemeinProgress WIP Custom Login.This issue affects WIP Custom Login: from n/a th...
CVE-2022-41790HIGH8.8Missing Authorization vulnerability in CodePeople WP Time Slots Booking Form.This issue affects WP Time Slots Booking Fo...
CVE-2022-41786CRITICAL9.8Missing Authorization vulnerability in WP Job Portal WP Job Portal – A Complete Job Board.This issue affects WP Job Port...
CVE-2022-41990HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Vinoj Cardoza 3D Tag Cloud allows Stored XSS.This issue affects 3D Ta...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now