2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-0353MEDIUM4.4 A denial of service vulnerability was reported in the Lenovo HardwareScanPlugin versions prior to 1.3.1.2 and  Len...
CVE-2022-22466CRITICAL9.8IBM Security Verify Governance 10.0 contains hard-coded credentials, such as a password or cryptographic key, which it u...
CVE-2022-4943MEDIUM5.3The miniOrange's Google Authenticator plugin for WordPress is vulnerable to authorization bypass due to a missing capabi...
CVE-2022-4290HIGH8.8The Cyr to Lat plugin for WordPress is vulnerable to authenticated SQL Injection via the 'ctl_sanitize_title' function i...
CVE-2022-3622MEDIUM4.1The Blog2Social plugin for WordPress is vulnerable to authorization bypass due to missing capability checks in versions...
CVE-2022-3342HIGH8.8The Jetpack CRM plugin for WordPress is vulnerable to PHAR deserialization via the ‘zbscrmcsvimpf’ parameter in the 'zer...
CVE-2022-2441HIGH8.8The ImageMagick Engine plugin for WordPress is vulnerable to remote code execution via the 'cli_path' parameter in versi...
CVE-2022-4954MEDIUM4.8The Waiting: One-click countdowns plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Countdown na...
CVE-2022-4712MEDIUM6.1The WP Cerber Security plugin for WordPress is vulnerable to stored cross-site scripting via the log parameter when logg...
CVE-2022-4531Rejected reason: Not a valid vulnerability.
CVE-2022-42150CRITICAL10TinyLab linux-lab v1.1-rc1 and cloud-labv0.8-rc2, v1.1-rc1 are vulnerable to insecure permissions. The default configura...
CVE-2022-47583CRITICAL9.8Terminal character injection in Mintty before 3.6.3 allows code execution via unescaped output to the terminal.
CVE-2022-37830CRITICAL9.6Interway a.s WebJET CMS 8.6.896 is vulnerable to Cross Site Scripting (XSS).
CVE-2022-27813HIGH8.2Motorola MTM5000 series firmwares lack properly configured memory protection of pages shared between the OMAP-L138 ARM a...
CVE-2022-26943HIGH8.8The Motorola MTM5000 series firmwares generate TETRA authentication challenges using a PRNG using a tick count register ...
CVE-2022-26942HIGH8.2The Motorola MTM5000 series firmwares lack pointer validation on arguments passed to trusted execution environment (TEE)...
CVE-2022-26941HIGH8.8A format string vulnerability exists in Motorola MTM5000 series firmware AT command handler for the AT+CTGL command. An ...
CVE-2022-25334HIGH8.8The Texas Instruments OMAP L138 (secure variants) trusted execution environment (TEE) lacks a bounds check on the signat...
CVE-2022-25333HIGH8.8The Texas Instruments OMAP L138 (secure variants) trusted execution environment (TEE) performs an RSA check implemented ...
CVE-2022-25332MEDIUM4.1The AES implementation in the Texas Instruments OMAP L138 (secure variants), present in mask ROM, suffers from a timing ...
CVE-2022-24404HIGH7.5Lack of cryptographic integrity check on TETRA air-interface encrypted traffic. Since a stream cipher is employed, this ...
CVE-2022-24402HIGH7.5The TETRA TEA1 keystream generator implements a key register initialization function that compresses the 80-bit key to o...
CVE-2022-24401HIGH8.1Adversary-induced keystream re-use on TETRA air-interface encrypted traffic using any TEA keystream generator. IV genera...
CVE-2022-24400MEDIUM5.9A flaw in the TETRA authentication procecure allows a MITM adversary that can predict the MS challenge RAND2 to set sess...
CVE-2022-3761MEDIUM5.9OpenVPN Connect versions before 3.4.0.4506 (macOS) and OpenVPN Connect before 3.4.0.3100 (Windows) allows man-in-the-mid...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now