2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-0353 | MEDIUM | 4.4 | 0.2% | Oct 25, 2023 | A denial of service vulnerability was reported in the Lenovo HardwareScanPlugin versions prior to 1.3.1.2 and Len... |
| CVE-2022-22466 | CRITICAL | 9.8 | 0.6% | Oct 23, 2023 | IBM Security Verify Governance 10.0 contains hard-coded credentials, such as a password or cryptographic key, which it u... |
| CVE-2022-4943 | MEDIUM | 5.3 | 0.5% | Oct 20, 2023 | The miniOrange's Google Authenticator plugin for WordPress is vulnerable to authorization bypass due to a missing capabi... |
| CVE-2022-4290 | HIGH | 8.8 | 0.8% | Oct 20, 2023 | The Cyr to Lat plugin for WordPress is vulnerable to authenticated SQL Injection via the 'ctl_sanitize_title' function i... |
| CVE-2022-3622 | MEDIUM | 4.1 | 0.6% | Oct 20, 2023 | The Blog2Social plugin for WordPress is vulnerable to authorization bypass due to missing capability checks in versions... |
| CVE-2022-3342 | HIGH | 8.8 | 1.0% | Oct 20, 2023 | The Jetpack CRM plugin for WordPress is vulnerable to PHAR deserialization via the ‘zbscrmcsvimpf’ parameter in the 'zer... |
| CVE-2022-2441 | HIGH | 8.8 | 1.1% | Oct 20, 2023 | The ImageMagick Engine plugin for WordPress is vulnerable to remote code execution via the 'cli_path' parameter in versi... |
| CVE-2022-4954 | MEDIUM | 4.8 | 0.3% | Oct 20, 2023 | The Waiting: One-click countdowns plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Countdown na... |
| CVE-2022-4712 | MEDIUM | 6.1 | 0.5% | Oct 20, 2023 | The WP Cerber Security plugin for WordPress is vulnerable to stored cross-site scripting via the log parameter when logg... |
| CVE-2022-4531 | — | — | — | Oct 20, 2023 | Rejected reason: Not a valid vulnerability. |
| CVE-2022-42150 | CRITICAL | 10 | 0.9% | Oct 19, 2023 | TinyLab linux-lab v1.1-rc1 and cloud-labv0.8-rc2, v1.1-rc1 are vulnerable to insecure permissions. The default configura... |
| CVE-2022-47583 | CRITICAL | 9.8 | 1.1% | Oct 19, 2023 | Terminal character injection in Mintty before 3.6.3 allows code execution via unescaped output to the terminal. |
| CVE-2022-37830 | CRITICAL | 9.6 | 0.7% | Oct 19, 2023 | Interway a.s WebJET CMS 8.6.896 is vulnerable to Cross Site Scripting (XSS). |
| CVE-2022-27813 | HIGH | 8.2 | 0.2% | Oct 19, 2023 | Motorola MTM5000 series firmwares lack properly configured memory protection of pages shared between the OMAP-L138 ARM a... |
| CVE-2022-26943 | HIGH | 8.8 | 0.3% | Oct 19, 2023 | The Motorola MTM5000 series firmwares generate TETRA authentication challenges using a PRNG using a tick count register ... |
| CVE-2022-26942 | HIGH | 8.2 | 0.2% | Oct 19, 2023 | The Motorola MTM5000 series firmwares lack pointer validation on arguments passed to trusted execution environment (TEE)... |
| CVE-2022-26941 | HIGH | 8.8 | 0.3% | Oct 19, 2023 | A format string vulnerability exists in Motorola MTM5000 series firmware AT command handler for the AT+CTGL command. An ... |
| CVE-2022-25334 | HIGH | 8.8 | 0.2% | Oct 19, 2023 | The Texas Instruments OMAP L138 (secure variants) trusted execution environment (TEE) lacks a bounds check on the signat... |
| CVE-2022-25333 | HIGH | 8.8 | 0.1% | Oct 19, 2023 | The Texas Instruments OMAP L138 (secure variants) trusted execution environment (TEE) performs an RSA check implemented ... |
| CVE-2022-25332 | MEDIUM | 4.1 | 0.1% | Oct 19, 2023 | The AES implementation in the Texas Instruments OMAP L138 (secure variants), present in mask ROM, suffers from a timing ... |
| CVE-2022-24404 | HIGH | 7.5 | 0.2% | Oct 19, 2023 | Lack of cryptographic integrity check on TETRA air-interface encrypted traffic. Since a stream cipher is employed, this ... |
| CVE-2022-24402 | HIGH | 7.5 | 0.6% | Oct 19, 2023 | The TETRA TEA1 keystream generator implements a key register initialization function that compresses the 80-bit key to o... |
| CVE-2022-24401 | HIGH | 8.1 | 0.3% | Oct 19, 2023 | Adversary-induced keystream re-use on TETRA air-interface encrypted traffic using any TEA keystream generator. IV genera... |
| CVE-2022-24400 | MEDIUM | 5.9 | 0.3% | Oct 19, 2023 | A flaw in the TETRA authentication procecure allows a MITM adversary that can predict the MS challenge RAND2 to set sess... |
| CVE-2022-3761 | MEDIUM | 5.9 | 0.7% | Oct 17, 2023 | OpenVPN Connect versions before 3.4.0.4506 (macOS) and OpenVPN Connect before 3.4.0.3100 (Windows) allows man-in-the-mid... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now