2022 CVE Vulnerabilities
27,525 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-2658 | MEDIUM | 4.8 | 0.5% | Jan 16, 2023 | The WP Spell Check WordPress plugin before 9.13 does not escape ignored words, which could allow high privilege users su... |
| CVE-2022-45438 | MEDIUM | 5.3 | 1.2% | Jan 16, 2023 | When explicitly enabling the feature flag DASHBOARD_CACHE (disabled by default), the system allowed for an unauthenticat... |
| CVE-2022-43721 | MEDIUM | 5.4 | 1.0% | Jan 16, 2023 | An authenticated attacker with update datasets permission could change a dataset link to an untrusted site, users could ... |
| CVE-2022-43720 | MEDIUM | 5.4 | 1.2% | Jan 16, 2023 | An authenticated attacker with write CSS template permissions can create a record with specific HTML tags that will not ... |
| CVE-2022-43718 | MEDIUM | 5.4 | 1.3% | Jan 16, 2023 | Upload data forms do not correctly render user input leading to possible XSS attack vectors that can be performed by aut... |
| CVE-2022-43717 | MEDIUM | 5.4 | 1.2% | Jan 16, 2023 | Dashboard rendering does not sufficiently sanitize the content of markdown components leading to possible XSS attack vec... |
| CVE-2022-41703 | MEDIUM | 5.4 | 1.2% | Jan 16, 2023 | A vulnerability in the SQL Alchemy connector of Apache Superset allows an authenticated user with read access to a speci... |
| CVE-2022-2815 | MEDIUM | 6.5 | 0.6% | Jan 14, 2023 | Insecure Storage of Sensitive Information in GitHub repository publify/publify prior to 9.2.10. |
| CVE-2022-38467 | MEDIUM | 6.1 | 0.8% | Jan 14, 2023 | Reflected Cross-Site Scripting (XSS) vulnerability in CRM Perks Forms – WordPress Form Builder <= 1.1.0 ver. |
| CVE-2022-41956 | MEDIUM | 6.5 | 1.8% | Jan 14, 2023 | Autolab is a course management service, initially developed by a team of students at Carnegie Mellon University, that en... |
| CVE-2022-23532 | MEDIUM | 6.5 | 0.7% | Jan 14, 2023 | APOC (Awesome Procedures on Cypher) is an add-on library for Neo4j that provides hundreds of procedures and functions. A... |
| CVE-2022-48091 | MEDIUM | 5.4 | 0.4% | Jan 13, 2023 | Tramyardg hotel-mgmt-system version 2022.4 is vulnerable to Cross Site Scripting (XSS) via process_update_profile.php. |
| CVE-2022-48090 | MEDIUM | 6.5 | 0.7% | Jan 13, 2023 | Tramyardg hotel-mgmt-system version 2022.4 is vulnerable to SQL Injection via /app/dao/CustomerDAO.php. |
| CVE-2022-42288 | MEDIUM | 5.3 | 0.5% | Jan 13, 2023 | NVIDIA BMC contains a vulnerability in IPMI handler, where an unauthorized attacker can use certain oracles to guess a v... |
| CVE-2022-42284 | MEDIUM | 5.5 | 0.1% | Jan 13, 2023 | NVIDIA BMC stores user passwords in an obfuscated form in a database accessible by the host. This may lead to a credenti... |
| CVE-2022-42282 | MEDIUM | 5.5 | 0.5% | Jan 13, 2023 | NVIDIA BMC contains a vulnerability in SPX REST API, where an authorized attacker can access arbitrary files, which may ... |
| CVE-2022-42281 | MEDIUM | 6.7 | 0.2% | Jan 13, 2023 | NVIDIA DGX A100 contains a vulnerability in SBIOS in the FsRecovery, which may allow a highly privileged local attacker ... |
| CVE-2022-48258 | MEDIUM | 5.3 | 1.1% | Jan 13, 2023 | In Eternal Terminal 6.2.1, etserver and etclient have world-readable logfiles. |
| CVE-2022-48257 | MEDIUM | 5.3 | 0.9% | Jan 13, 2023 | In Eternal Terminal 6.2.1, etserver and etclient have predictable logfile names in /tmp. |
| CVE-2022-46438 | MEDIUM | 5.4 | 0.4% | Jan 13, 2023 | A cross-site scripting (XSS) vulnerability in the /admin/article_category.php component of DouPHP v1.7 20221118 allows a... |
| CVE-2022-42704 | MEDIUM | 5.4 | 0.4% | Jan 13, 2023 | A cross-site scripting (XSS) vulnerability in Employee Service Center (esc) and Service Portal (sp) in ServiceNow Quebec... |
| CVE-2022-47102 | MEDIUM | 5.4 | 0.5% | Jan 12, 2023 | A cross-site scripting (XSS) vulnerability in Student Study Center Management System V 1.0 allows attackers to execute a... |
| CVE-2022-46622 | MEDIUM | 6.1 | 0.5% | Jan 12, 2023 | A cross-site scripting (XSS) vulnerability in Judging Management System v1.0 allows attackers to execute arbitrary web s... |
| CVE-2022-45729 | MEDIUM | 6.1 | 0.5% | Jan 12, 2023 | A cross-site scripting (XSS) vulnerability in Doctor Appointment Management System v1.0.0 allows attackers to execute ar... |
| CVE-2022-45728 | MEDIUM | 6.1 | 0.5% | Jan 12, 2023 | Doctor Appointment Management System v1.0.0 was discovered to contain a cross-site scripting (XSS) vulnerability. |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now