2022 CVE Vulnerabilities
27,525 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-43455 | MEDIUM | 6.5 | 0.6% | Jan 18, 2023 | Sewio’s Real-Time Location System (RTLS) Studio version 2.0.0 up to and including version 2.6.2 is vulnerable to imprope... |
| CVE-2022-46660 | MEDIUM | 6.5 | 0.6% | Jan 18, 2023 | An unauthorized user could alter or write files with full control over the path and content of the file. |
| CVE-2022-43494 | MEDIUM | 6.5 | 0.5% | Jan 18, 2023 | An unauthorized user could be able to read any file on the system, potentially exposing sensitive information. ... |
| CVE-2022-39429 | MEDIUM | 4.3 | 0.6% | Jan 18, 2023 | Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 19c and 21c... |
| CVE-2022-47929 | MEDIUM | 5.5 | 1.0% | Jan 17, 2023 | In the Linux kernel before 6.1.6, a NULL pointer dereference bug in the traffic control subsystem allows an unprivileged... |
| CVE-2022-39195 | MEDIUM | 6.1 | 6.3% | Jan 17, 2023 | A cross-site scripting (XSS) vulnerability in the LISTSERV 17 web interface allows remote attackers to inject arbitrary ... |
| CVE-2022-2907 | MEDIUM | 6.5 | 0.9% | Jan 17, 2023 | An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.9 before 15.1.6, all versions start... |
| CVE-2022-37436 | MEDIUM | 5.3 | 57.9% | Jan 17, 2023 | Prior to Apache HTTP Server 2.4.55, a malicious backend can cause the response headers to be truncated early, resulting ... |
| CVE-2022-40704 | MEDIUM | 6.1 | 0.6% | Jan 17, 2023 | A XSS vulnerability was found in phoromatic_r_add_test_details.php in phoronix-test-suite. |
| CVE-2022-4121 | MEDIUM | 5.5 | 0.5% | Jan 17, 2023 | In libetpan a null pointer dereference in mailimap_mailbox_data_status_free in low-level/imap/mailimap_types.c was found... |
| CVE-2022-41861 | MEDIUM | 6.5 | 1.1% | Jan 17, 2023 | A flaw was found in freeradius. A malicious RADIUS client or home server can send a malformed abinary attribute which ca... |
| CVE-2022-2893 | MEDIUM | 6.5 | 0.7% | Jan 17, 2023 | RONDS EPM version 1.19.5 does not properly validate the filename parameter, which could allow an unauthorized user to s... |
| CVE-2022-42462 | MEDIUM | 4.8 | 0.4% | Jan 17, 2023 | Auth. Stored Cross-Site Scripting (XSS) vulnerability in Adeel Ahmed's IP Blacklist Cloud plugin <= 5.00 versions. |
| CVE-2022-45440 | MEDIUM | 4.4 | 0.2% | Jan 17, 2023 | A vulnerability exists in the FTP server of the Zyxel AX7501-B0 firmware prior to V5.17(ABPC.3)C0, which processes symbo... |
| CVE-2022-45439 | MEDIUM | 6.5 | 0.2% | Jan 17, 2023 | A pair of spare WiFi credentials is stored in the configuration file of the Zyxel AX7501-B0 firmware prior to V5.17(ABPC... |
| CVE-2022-4658 | MEDIUM | 5.4 | 0.5% | Jan 16, 2023 | The RSSImport WordPress plugin through 4.6.1 does not validate and escape one of its shortcode attributes, which could a... |
| CVE-2022-4655 | MEDIUM | 5.4 | 0.5% | Jan 16, 2023 | The Welcart e-Commerce WordPress plugin before 2.8.9 does not validate and escapes one of its shortcode attributes, whic... |
| CVE-2022-4653 | MEDIUM | 5.4 | 0.4% | Jan 16, 2023 | The Greenshift WordPress plugin before 4.8.9 does not validate and escape one of its shortcode attributes, which could a... |
| CVE-2022-4648 | MEDIUM | 5.4 | 0.5% | Jan 16, 2023 | The Real Testimonials WordPress plugin before 2.6.0 does not validate and escape some of its shortcode attributes before... |
| CVE-2022-4578 | MEDIUM | 5.4 | 0.5% | Jan 16, 2023 | The Video Conferencing with Zoom WordPress plugin before 4.0.10 does not validate and escape some of its shortcode attri... |
| CVE-2022-4571 | MEDIUM | 5.4 | 0.5% | Jan 16, 2023 | The Seriously Simple Podcasting WordPress plugin before 2.19.1 does not validate and escape some of its shortcode attrib... |
| CVE-2022-4549 | MEDIUM | 4.3 | 0.3% | Jan 16, 2023 | The Tickera WordPress plugin before 3.5.1.0 does not have CSRF check in place when updating its settings, which could al... |
| CVE-2022-4544 | MEDIUM | 5.4 | 0.5% | Jan 16, 2023 | The MashShare WordPress plugin before 3.8.7 does not validate and escape some of its shortcode attributes before outputt... |
| CVE-2022-4508 | MEDIUM | 5.4 | 0.5% | Jan 16, 2023 | The ConvertKit WordPress plugin before 2.0.5 does not validate and escapes some of its shortcode attributes before outpu... |
| CVE-2022-4507 | MEDIUM | 5.4 | 0.5% | Jan 16, 2023 | The Real Cookie Banner WordPress plugin before 3.4.10 does not validate and escapes some of its shortcode attributes bef... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now