2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-30122 | HIGH | 7.5 | 2.1% | Dec 5, 2022 | A possible denial of service vulnerability exists in Rack <2.0.9.1, <2.1.4.1 and <2.2.3.1 in the multipart parsing compo... |
| CVE-2022-2827 | HIGH | 7.5 | 1.7% | Dec 5, 2022 | AMI MegaRAC User Enumeration Vulnerability |
| CVE-2022-37783 | HIGH | 7.5 | 1.0% | Dec 5, 2022 | All Craft CMS versions between 3.0.0 and 3.7.32 disclose password hashes of users who authenticate using their E-Mail ad... |
| CVE-2022-37325 | HIGH | 7.5 | 1.0% | Dec 5, 2022 | In Sangoma Asterisk through 16.28.0, 17.x and 18.x through 18.14.0, and 19.x through 19.6.0, an incoming Setup message t... |
| CVE-2022-45771 | HIGH | 8.8 | 1.8% | Dec 5, 2022 | An issue in the /api/audits component of Pwndoc v0.5.3 allows attackers to escalate privileges and execute arbitrary cod... |
| CVE-2022-4292 | HIGH | 7.8 | 0.7% | Dec 5, 2022 | Use After Free in GitHub repository vim/vim prior to 9.0.0882. |
| CVE-2022-3907 | HIGH | 7.5 | 0.9% | Dec 5, 2022 | The Clerk WordPress plugin before 4.0.0 is affected by time-based attacks in the validation function for all API request... |
| CVE-2022-3858 | HIGH | 7.2 | 1.0% | Dec 5, 2022 | The Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line, WeChat, Email, SMS, Call Button WordPress plugin befo... |
| CVE-2022-3856 | HIGH | 7.2 | 1.0% | Dec 5, 2022 | The Comic Book Management System WordPress plugin before 2.2.0 does not sanitize and escape a parameter before using it ... |
| CVE-2022-3846 | HIGH | 7.5 | 0.8% | Dec 5, 2022 | The Workreap WordPress theme before 2.6.3 has a vulnerability with the notifications feature as it's possible to read an... |
| CVE-2022-3694 | HIGH | 7.5 | 0.8% | Dec 5, 2022 | The Syncee WordPress plugin before 1.0.10 leaks the administrator token that can be used to take over the administrator'... |
| CVE-2022-3249 | HIGH | 7.2 | 1.0% | Dec 5, 2022 | The WP CSV Exporter WordPress plugin before 1.3.7 does not properly sanitise and escape some parameters before using the... |
| CVE-2022-1540 | HIGH | 7.2 | 1.0% | Dec 5, 2022 | The PostmagThemes Demo Import WordPress plugin through 1.0.7 does not validate the imported file, allowing high-privileg... |
| CVE-2022-45313 | HIGH | 8.8 | 1.4% | Dec 5, 2022 | Mikrotik RouterOs before stable v7.5 was discovered to contain an out-of-bounds read in the hotspot process. This vulner... |
| CVE-2022-4282 | HIGH | 7.2 | 0.7% | Dec 5, 2022 | A vulnerability was found in SpringBootCMS and classified as critical. Affected by this issue is some unknown functional... |
| CVE-2022-4281 | HIGH | 8.8 | 0.4% | Dec 5, 2022 | A vulnerability has been found in Facepay 1.0 and classified as critical. Affected by this vulnerability is an unknown f... |
| CVE-2022-43484 | HIGH | 7.8 | 0.4% | Dec 5, 2022 | TERASOLUNA Global Framework 1.0.0 (Public review version) and TERASOLUNA Server Framework for Java (Rich) 2.0.0.2 to 2.0... |
| CVE-2022-43470 | HIGH | 7.3 | 0.2% | Dec 5, 2022 | Cross-site request forgery (CSRF) vulnerability in +F FS040U software versions v2.3.4 and earlier, +F FS020W software ve... |
| CVE-2022-41777 | HIGH | 7.5 | 1.5% | Dec 5, 2022 | Improper check or handling of exceptional conditions vulnerability in Nako3edit, editor component of nadesiko3 (PC Versi... |
| CVE-2022-35507 | HIGH | 7.1 | 1.4% | Dec 4, 2022 | A response-header CRLF injection vulnerability in the Proxmox Virtual Environment (PVE) and Proxmox Mail Gateway (PMG) w... |
| CVE-2022-46413 | HIGH | 8.8 | 1.4% | Dec 4, 2022 | An issue was discovered in Veritas NetBackup Flex Scale through 3.0 and Access Appliance through 8.0.100. Authenticated ... |
| CVE-2022-46412 | HIGH | 8.8 | 0.7% | Dec 4, 2022 | An issue was discovered in Veritas NetBackup Flex Scale through 3.0. A non-privileged user may escape a restricted shell... |
| CVE-2022-46411 | HIGH | 8.8 | 0.6% | Dec 4, 2022 | An issue was discovered in Veritas NetBackup Flex Scale through 3.0 and Access Appliance through 8.0.100. A default pass... |
| CVE-2022-46410 | HIGH | 8.8 | 0.6% | Dec 4, 2022 | An issue was discovered in Veritas NetBackup Flex Scale through 3.0. An attacker with non-root privileges may escalate p... |
| CVE-2022-46405 | HIGH | 7.5 | 0.9% | Dec 4, 2022 | Mastodon through 4.0.2 allows attackers to cause a denial of service (large Sidekiq pull queue) by creating bot accounts... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now