2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-28975 | MEDIUM | 5.4 | 0.4% | Jan 9, 2024 | A stored cross-site scripting (XSS) vulnerability in Infoblox NIOS v8.5.2-409296 allows attackers to execute arbitrary w... |
| CVE-2022-40696 | HIGH | 7.5 | 0.5% | Jan 8, 2024 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in WP Engine Advanced Custom Fields (ACF).This ... |
| CVE-2022-36352 | HIGH | 8.8 | 0.4% | Jan 8, 2024 | Missing Authorization vulnerability in Profilegrid ProfileGrid – User Profiles, Memberships, Groups and Communities.This... |
| CVE-2022-34344 | HIGH | 8.8 | 0.5% | Jan 8, 2024 | Missing Authorization vulnerability in Rymera Web Co Wholesale Suite – WooCommerce Wholesale Prices, B2B, Catalog Mode, ... |
| CVE-2022-29409 | — | — | — | Jan 8, 2024 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2022-45354 | HIGH | 7.5 | 38.1% | Jan 8, 2024 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in WPChill Download Monitor.This issue affects ... |
| CVE-2022-3328 | HIGH | 7 | 0.4% | Jan 8, 2024 | Race condition in snap-confine's must_mkdir_and_open_with_perms() |
| CVE-2022-2602 | HIGH | 7 | 1.3% | Jan 8, 2024 | io_uring UAF, Unix SCM garbage collection |
| CVE-2022-2588 | HIGH | 7.8 | 5.9% | Jan 8, 2024 | It was discovered that the cls_route filter implementation in the Linux kernel would not remove an old filter from the h... |
| CVE-2022-2586 | HIGH | 7.8 | 10.5% | Jan 8, 2024 | It was discovered that a nft object or expression could reference a nft set on a different nft table, leading to a use-a... |
| CVE-2022-2585 | HIGH | 7.8 | 1.3% | Jan 8, 2024 | It was discovered that when exec'ing from a non-leader thread, armed POSIX CPU timers would be left on a list but freed,... |
| CVE-2022-46839 | CRITICAL | 9.8 | 0.8% | Jan 5, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in JS Help Desk JS Help Desk – Best Help Desk & Support Pl... |
| CVE-2022-3864 | MEDIUM | 4.5 | 0.4% | Jan 4, 2024 | A vulnerability exists in the Relion update package signature validation. A tampered update package could cause the IED... |
| CVE-2022-2081 | HIGH | 7.5 | 0.6% | Jan 4, 2024 | A vulnerability exists in the HCI Modbus TCP function included in the product versions listed above. If the HCI Modbus T... |
| CVE-2022-43375 | — | — | — | Jan 4, 2024 | Rejected reason: This CVE ID was unused by the CNA. |
| CVE-2022-3010 | HIGH | 7.5 | 0.5% | Jan 2, 2024 | The Priva TopControl Suite contains predictable credentials for the SSH service, based on the Serial number. Which makes... |
| CVE-2022-46487 | HIGH | 7.8 | 0.6% | Dec 30, 2023 | Improper initialization of x87 and SSE floating-point configuration registers in the __scone_entry component of SCONE be... |
| CVE-2022-46486 | MEDIUM | 5.5 | 0.3% | Dec 30, 2023 | A lack of pointer-validation logic in the __scone_dispatch component of SCONE before v5.8.0 for Intel SGX allows attacke... |
| CVE-2022-44589 | HIGH | 7.5 | 0.7% | Dec 29, 2023 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in miniOrange miniOrange's Google Authenticator... |
| CVE-2022-36399 | HIGH | 7.5 | 0.4% | Dec 28, 2023 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in BoxyStudio Booked - Appointment Booking for ... |
| CVE-2022-34268 | CRITICAL | 9.8 | 1.5% | Dec 25, 2023 | An issue was discovered in RWS WorldServer before 11.7.3. /clientLogin deserializes Java objects without authentication,... |
| CVE-2022-34267 | CRITICAL | 9.8 | 42.2% | Dec 25, 2023 | An issue was discovered in RWS WorldServer before 11.7.3. Adding a token parameter with the value of 02 bypasses all aut... |
| CVE-2022-43675 | MEDIUM | 6.1 | 0.4% | Dec 25, 2023 | An issue was discovered in NOKIA NFM-T R19.9. Reflected XSS in the Network Element Manager exists via /oms1350/pages/otn... |
| CVE-2022-41762 | MEDIUM | 6.1 | 0.4% | Dec 25, 2023 | An issue was discovered in NOKIA NFM-T R19.9. Multiple Reflected XSS vulnerabilities exist in the Network Element Manage... |
| CVE-2022-41761 | MEDIUM | 6.5 | 0.8% | Dec 25, 2023 | An issue was discovered in NOKIA NFM-T R19.9. An Absolute Path Traversal vulnerability exists under /cgi-bin/R19.9/viewl... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now