2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-28975MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in Infoblox NIOS v8.5.2-409296 allows attackers to execute arbitrary w...
CVE-2022-40696HIGH7.5Exposure of Sensitive Information to an Unauthorized Actor vulnerability in WP Engine Advanced Custom Fields (ACF).This ...
CVE-2022-36352HIGH8.8Missing Authorization vulnerability in Profilegrid ProfileGrid – User Profiles, Memberships, Groups and Communities.This...
CVE-2022-34344HIGH8.8Missing Authorization vulnerability in Rymera Web Co Wholesale Suite – WooCommerce Wholesale Prices, B2B, Catalog Mode, ...
CVE-2022-29409Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2022-45354HIGH7.5Exposure of Sensitive Information to an Unauthorized Actor vulnerability in WPChill Download Monitor.This issue affects ...
CVE-2022-3328HIGH7Race condition in snap-confine's must_mkdir_and_open_with_perms()
CVE-2022-2602HIGH7io_uring UAF, Unix SCM garbage collection
CVE-2022-2588HIGH7.8It was discovered that the cls_route filter implementation in the Linux kernel would not remove an old filter from the h...
CVE-2022-2586HIGH7.8It was discovered that a nft object or expression could reference a nft set on a different nft table, leading to a use-a...
CVE-2022-2585HIGH7.8It was discovered that when exec'ing from a non-leader thread, armed POSIX CPU timers would be left on a list but freed,...
CVE-2022-46839CRITICAL9.8Unrestricted Upload of File with Dangerous Type vulnerability in JS Help Desk JS Help Desk – Best Help Desk & Support Pl...
CVE-2022-3864MEDIUM4.5 A vulnerability exists in the Relion update package signature validation. A tampered update package could cause the IED...
CVE-2022-2081HIGH7.5A vulnerability exists in the HCI Modbus TCP function included in the product versions listed above. If the HCI Modbus T...
CVE-2022-43375Rejected reason: This CVE ID was unused by the CNA.
CVE-2022-3010HIGH7.5The Priva TopControl Suite contains predictable credentials for the SSH service, based on the Serial number. Which makes...
CVE-2022-46487HIGH7.8Improper initialization of x87 and SSE floating-point configuration registers in the __scone_entry component of SCONE be...
CVE-2022-46486MEDIUM5.5A lack of pointer-validation logic in the __scone_dispatch component of SCONE before v5.8.0 for Intel SGX allows attacke...
CVE-2022-44589HIGH7.5Exposure of Sensitive Information to an Unauthorized Actor vulnerability in miniOrange miniOrange's Google Authenticator...
CVE-2022-36399HIGH7.5Exposure of Sensitive Information to an Unauthorized Actor vulnerability in BoxyStudio Booked - Appointment Booking for ...
CVE-2022-34268CRITICAL9.8An issue was discovered in RWS WorldServer before 11.7.3. /clientLogin deserializes Java objects without authentication,...
CVE-2022-34267CRITICAL9.8An issue was discovered in RWS WorldServer before 11.7.3. Adding a token parameter with the value of 02 bypasses all aut...
CVE-2022-43675MEDIUM6.1An issue was discovered in NOKIA NFM-T R19.9. Reflected XSS in the Network Element Manager exists via /oms1350/pages/otn...
CVE-2022-41762MEDIUM6.1An issue was discovered in NOKIA NFM-T R19.9. Multiple Reflected XSS vulnerabilities exist in the Network Element Manage...
CVE-2022-41761MEDIUM6.5An issue was discovered in NOKIA NFM-T R19.9. An Absolute Path Traversal vulnerability exists under /cgi-bin/R19.9/viewl...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now